Skip to content
arrow_back

Essential Eight Maturity Model.

Three levels of implementation maturity for each Essential 8 strategy. Your overall maturity equals the lowest level across all eight.

Last updated: March 2026

The four levels.

ML0
Not aligned
The strategy is not implemented or only partially in place.
ML1
Partly aligned
Basic implementation targeting commodity threats and opportunistic adversaries.
ML2
Mostly aligned
Standard implementation that extends coverage to more capable adversaries.
ML3
Fully aligned
Advanced implementation targeting sophisticated adversaries including nation-state actors.

Requirements by strategy.

Each strategy has specific requirements at each maturity level. For full control-level detail, use theEssential 8 control library.

1Application Controlexpand_more
ML1

Block unapproved executables on workstations

ML2

Extend to internet-facing servers; implement Microsoft's recommended blocklist

ML3

Cover all servers and workstations; restrict drivers; validate rulesets annually

2Patch Applicationsexpand_more
ML1

Patch internet-facing apps within two weeks; use vulnerability scanner

ML2

Apply critical patches within 48 hours for exploited vulnerabilities

ML3

Patch all applications within 48 hours for critical vulnerabilities; remove unsupported software

3Configure Office Macro Settingsexpand_more
ML1

Disable macros for users who do not need them; block macros from the internet

ML2

Block macros from making Win32 API calls; enforce AV scanning of macros

ML3

Only allow vetted, trusted macros with valid digital signatures from trusted publishers

4User Application Hardeningexpand_more
ML1

Block web ads, Java from the internet, and IE11; lock down browser settings

ML2

Harden Office and PDF software using ASD guidance; log PowerShell events

ML3

Disable .NET 3.5; constrain PowerShell language mode; remove legacy runtimes

5Restrict Administrative Privilegesexpand_more
ML1

Separate privileged and unprivileged accounts; block privileged accounts from internet access

ML2

Use jump servers; enforce strong passphrases; disable inactive accounts after 45 days

ML3

Just-in-time administration; secure admin workstations; enable Credential Guard

6Patch Operating Systemsexpand_more
ML1

Patch internet-facing OS within two weeks; replace unsupported operating systems

ML2

Apply critical patches within 48 hours for exploited vulnerabilities

ML3

Patch all operating systems within 48 hours for critical vulnerabilities; use latest or previous release

7Multi-Factor Authenticationexpand_more
ML1

Require MFA for internet-facing services and third-party providers

ML2

MFA for all users including privileged accounts; log MFA events centrally

ML3

Phishing-resistant MFA for all users; disable legacy authentication protocols

8Regular Backupsexpand_more
ML1

Backup important data; test restoration; prevent unprivileged modification

ML2

Prevent privileged accounts from modifying or deleting backups

ML3

Prevent all accounts (including backup admins) from modifying backups during retention period

How to determine your maturity level

Start by self-assessing against ML1 for all eight strategies. Use theEssential 8 control libraryto review each control's requirements - filter by ML1, ML2, or ML3.

For formal reporting, engage an IRAP-certified professional. Most organisations should target ML2 minimum. Government agencies handling sensitive data should aim for ML3.

Refer to ASD'sofficial Essential Eight Maturity Model documentation.

Maturity model vs certification

Unlike ISO 27001, the Essential 8 Maturity Model is a self-assessment and reporting tool - there is no formal "Essential 8 certification" issued by ASD.

Government agencies report maturity levels through internal assessments. Private sector organisations may have maturity assessed by IRAP assessors as part of broader security reviews.

Check your Essential 8 controls.

Review every control at your target maturity level with plain-English guidance and cross-framework mappings.

Mindset Cyber offers PECB-accreditedISO 27001 training.