The ASD Essential Eight,
strategy by strategy and level by level.
What the eight mitigation strategies are, what each maturity level asks, who has to implement them and how they line up with ISO 27001 and SOC 2. A guide for Australian technology companies. Not legal advice, and not a substitute for ASD's own maturity model and assessment guidance.
Last updated Published by TryTrustableNot legal advice
The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Signals Directorate (ASD): patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. The Essential Eight Maturity Model (current version November 2023) grades each strategy from Maturity Level Zero to Three. Non-corporate Commonwealth entities must reach Maturity Level Two under the Protective Security Policy Framework. For private companies it is voluntary, but government buyers, insurers and enterprise customers increasingly ask for it.
What is the Essential Eight?
The Essential Eight is the shortlist of the most effective strategies from ASD's wider Strategies to mitigate cyber security incidents. ASD's Australian Cyber Security Centre first published the maturity model in June 2017 and updates it regularly; the version current at the time of writing is the November 2023 maturity model. It was designed to protect internet-connected information technology networks. ASD says its principles can be applied to enterprise mobility and operational technology networks, but it was not designed for them and other mitigations may suit those environments better.
ASD describes it as a minimum set of preventative measures: it mitigates the majority of cyber threats, not all of them, so you still need other controls where your environment warrants them.
The eight mitigation strategies
| Strategy | What it stops | Maturity Level One, in brief |
|---|---|---|
| Patch applications | Exploits of known vulnerabilities in internet-facing services and common software | Asset discovery at least fortnightly; vulnerability scans daily for online services and weekly for office suites, browsers, email clients, PDF software and security products; critical or exploited flaws in online services patched within 48 hours, others within two weeks; unsupported software removed |
| Patch operating systems | Exploits of operating system vulnerabilities | Internet-facing servers and network devices patched within 48 hours for critical or exploited flaws and two weeks otherwise; workstations and internal servers within one month; unsupported operating systems replaced |
| Multi-factor authentication | Use of stolen, reused or guessed credentials | MFA for users of your online services and third-party online services that handle your sensitive data, and for customers of online services that hold sensitive customer data |
| Restrict administrative privileges | Attackers using privileged accounts to spread and persist | Privileged access validated when first requested; dedicated privileged accounts that (unless explicitly authorised) cannot reach the internet, email or web services; separate privileged and unprivileged operating environments |
| Application control | Execution of malicious programs and scripts | On workstations, only an approved set of executables, libraries, scripts and installers can run, including in user profiles and temporary folders |
| Restrict Microsoft Office macros | Malicious macros delivered in documents | Macros disabled for users without a business need, blocked in files from the internet, scanned by antivirus, and settings locked |
| User application hardening | Attacks through web browsers and other user software | Internet Explorer 11 disabled or removed; browsers do not process Java or web advertisements from the internet; browser security settings cannot be changed by users |
| Regular backups | Permanent loss of data after ransomware or destruction | Backups of data, applications and settings made and kept by business criticality, restorable to a common point in time, tested in disaster recovery exercises, and protected from unprivileged accounts |
Summarised from Appendix A of the Essential Eight Maturity Model (November 2023). Levels Two and Three add tighter timeframes, phishing-resistant MFA, logging and broader coverage. Read the model itself before an assessment.
Essential Eight maturity levels explained
The maturity model has four levels. Each level is defined by the tradecraft and targeting of the attackers it is meant to resist, not by how much paperwork you have.
| Level | Adversary it is designed to stop |
|---|---|
| Maturity Level Zero | Not a target: it signals weaknesses in the overall cyber security posture |
| Maturity Level One | Opportunistic attackers using commodity tradecraft: public exploits for unpatched services, stolen or guessed credentials, common social engineering |
| Maturity Level Two | Attackers with a modest step up in capability who invest more time, target credentials with phishing and try to get around weak MFA |
| Maturity Level Three | Adaptive attackers less reliant on public tools, who exploit older software and weak logging, move quickly on new exploits and can steal authentication tokens |
ASD notes that Maturity Level Three will not stop an attacker willing to invest enough time, money and effort.
ASD's implementation advice is to pick a target level that suits your risk, then reach the same level across all eight strategies before moving up, because the strategies are designed to cover each other's gaps. Use a risk-based approach, keep exceptions few and small, document and approve them, and back them with compensating controls that you review regularly.
Who must comply with the Essential Eight?
- Australian Government entities. Under the Protective Security Policy Framework (PSPF), non-corporate Commonwealth entities have been required since 1 July 2022 to implement all eight strategies to Maturity Level Two, and to consider whether their threat environment warrants Level Three. They report on their maturity each year. The PSPF is re-issued annually, so check the current release for the exact wording.
- Suppliers to government. Agencies often pass Essential Eight expectations down to the software and service providers that hold their data, through tenders and contracts.
- Private companies. There is no law requiring a private business to implement the Essential Eight. It is still the baseline Australian enterprise customers, cyber insurers and boards tend to ask about, and ASD publishes it for small and medium businesses and large organisations as well as government.
Regulated financial entities answer to APRA's prudential standards (such as CPS 234 on information security) rather than the Essential Eight, though many use it as a practical baseline. If you handle personal information, the Australian Privacy Act also requires reasonable security steps under APP 11, and the Essential Eight is a common way to show what "reasonable" means.
How is an Essential Eight assessment done?
ASD publishes assessment guidance alongside the maturity model. In short, an assessor checks each strategy against the requirements of the target level and the levels below it, and reports a level for each strategy rather than a single score. Documented and approved exceptions with compensating controls do not, by themselves, stop you being assessed as meeting a level.
For a SaaS company the practical questions are scope (corporate laptops and identity provider, production cloud, or both) and evidence: patch and scan reports, MFA and admin role exports, application control policies, macro settings, and restore test records.
Essential Eight vs ISO 27001 and SOC 2
They answer different questions. SOC 2 is an independent auditor's report on whether your controls meet the Trust Services Criteria. ISO 27001 certifies a management system for information security. The Essential Eight is a technical baseline with prescribed settings and timeframes. Having one does not give you the others, but the controls overlap, so evidence collected once can support all three. See SOC 2 vs ISO 27001 for how those two differ.
| Essential Eight strategy | Overlapping ISO 27001:2022 Annex A control | Overlapping SOC 2 criteria |
|---|---|---|
| Patch applications and operating systems | 8.8 Management of technical vulnerabilities | CC7.1 |
| Multi-factor authentication | 8.5 Secure authentication | CC6.1 |
| Restrict administrative privileges | 8.2 Privileged access rights | CC6.1 to CC6.3 |
| Application control | 8.19 Installation of software on operational systems | CC6.8 |
| Restrict Office macros, user application hardening | 8.9 Configuration management | CC6.8, CC7.1 |
| Regular backups | 8.13 Information backup | A1.2 (availability, if in scope) |
Overlap, not equivalence. ISO 27001 and SOC 2 let you choose how to meet a control; the Essential Eight prescribes specific settings and timeframes at each level.
Does TryTrustable support the Essential Eight?
Not as a framework. TryTrustable does not model the Essential Eight or assess maturity levels, and it does not collect endpoint data such as application control or Microsoft Office macro settings. What it does do is run the SOC 2 and ISO 27001 controls that overlap with several strategies: MFA and access reviews, admin privilege checks, vulnerability scanning in your CI pipeline and cloud configuration checks, with evidence collected from GitHub, AWS and GCP into a tamper-evident ledger. If you are building toward SOC 2 or ISO 27001 and an Australian customer asks about the Essential Eight, that shared evidence is a useful starting point, not a maturity rating.
The things people ask us
What are the Essential Eight strategies?
Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups.
What is the latest version of the Essential Eight Maturity Model?
The November 2023 version, which ASD's maturity model page still listed as current in 2026. ASD updates the model from time to time, so check cyber.gov.au before an assessment.
Is the Essential Eight mandatory?
For non-corporate Commonwealth entities, yes: the PSPF has required Maturity Level Two since 1 July 2022. For private companies it is voluntary unless a contract or tender requires it.
What maturity level should a private company aim for?
ASD suggests choosing a target based on how attractive you are to attackers and the impact of an incident. Many organisations start with Maturity Level One across all eight strategies, then move to Level Two, which is the government benchmark.
Is the Essential Eight the same as ISO 27001?
No. ISO 27001 is a certifiable management system standard; the Essential Eight is a set of technical mitigation strategies with maturity levels. Several controls overlap, such as vulnerability management, MFA, privileged access and backups.
Does TryTrustable assess Essential Eight maturity?
No. The platform models SOC 2, ISO 27001 and other frameworks, and some of those controls overlap with Essential Eight strategies. It does not rate Essential Eight maturity levels.
Build the controls that overlap, once.
Thirty minutes on SOC 2 and ISO 27001 readiness, with evidence from your GitHub, AWS and GCP accounts landing in the ledger.