Essential Eight

The ASD Essential Eight,
strategy by strategy and level by level.

What the eight mitigation strategies are, what each maturity level asks, who has to implement them and how they line up with ISO 27001 and SOC 2. A guide for Australian technology companies. Not legal advice, and not a substitute for ASD's own maturity model and assessment guidance.

ASDMaturity Model Nov 2023ML0 to ML3PSPFISM

Last updated Published by TryTrustableNot legal advice

Short answer

The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Signals Directorate (ASD): patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. The Essential Eight Maturity Model (current version November 2023) grades each strategy from Maturity Level Zero to Three. Non-corporate Commonwealth entities must reach Maturity Level Two under the Protective Security Policy Framework. For private companies it is voluntary, but government buyers, insurers and enterprise customers increasingly ask for it.

01

What is the Essential Eight?

The Essential Eight is the shortlist of the most effective strategies from ASD's wider Strategies to mitigate cyber security incidents. ASD's Australian Cyber Security Centre first published the maturity model in June 2017 and updates it regularly; the version current at the time of writing is the November 2023 maturity model. It was designed to protect internet-connected information technology networks. ASD says its principles can be applied to enterprise mobility and operational technology networks, but it was not designed for them and other mitigations may suit those environments better.

ASD describes it as a minimum set of preventative measures: it mitigates the majority of cyber threats, not all of them, so you still need other controls where your environment warrants them.

02

The eight mitigation strategies

StrategyWhat it stopsMaturity Level One, in brief
Patch applicationsExploits of known vulnerabilities in internet-facing services and common softwareAsset discovery at least fortnightly; vulnerability scans daily for online services and weekly for office suites, browsers, email clients, PDF software and security products; critical or exploited flaws in online services patched within 48 hours, others within two weeks; unsupported software removed
Patch operating systemsExploits of operating system vulnerabilitiesInternet-facing servers and network devices patched within 48 hours for critical or exploited flaws and two weeks otherwise; workstations and internal servers within one month; unsupported operating systems replaced
Multi-factor authenticationUse of stolen, reused or guessed credentialsMFA for users of your online services and third-party online services that handle your sensitive data, and for customers of online services that hold sensitive customer data
Restrict administrative privilegesAttackers using privileged accounts to spread and persistPrivileged access validated when first requested; dedicated privileged accounts that (unless explicitly authorised) cannot reach the internet, email or web services; separate privileged and unprivileged operating environments
Application controlExecution of malicious programs and scriptsOn workstations, only an approved set of executables, libraries, scripts and installers can run, including in user profiles and temporary folders
Restrict Microsoft Office macrosMalicious macros delivered in documentsMacros disabled for users without a business need, blocked in files from the internet, scanned by antivirus, and settings locked
User application hardeningAttacks through web browsers and other user softwareInternet Explorer 11 disabled or removed; browsers do not process Java or web advertisements from the internet; browser security settings cannot be changed by users
Regular backupsPermanent loss of data after ransomware or destructionBackups of data, applications and settings made and kept by business criticality, restorable to a common point in time, tested in disaster recovery exercises, and protected from unprivileged accounts

Summarised from Appendix A of the Essential Eight Maturity Model (November 2023). Levels Two and Three add tighter timeframes, phishing-resistant MFA, logging and broader coverage. Read the model itself before an assessment.

03

Essential Eight maturity levels explained

The maturity model has four levels. Each level is defined by the tradecraft and targeting of the attackers it is meant to resist, not by how much paperwork you have.

LevelAdversary it is designed to stop
Maturity Level ZeroNot a target: it signals weaknesses in the overall cyber security posture
Maturity Level OneOpportunistic attackers using commodity tradecraft: public exploits for unpatched services, stolen or guessed credentials, common social engineering
Maturity Level TwoAttackers with a modest step up in capability who invest more time, target credentials with phishing and try to get around weak MFA
Maturity Level ThreeAdaptive attackers less reliant on public tools, who exploit older software and weak logging, move quickly on new exploits and can steal authentication tokens

ASD notes that Maturity Level Three will not stop an attacker willing to invest enough time, money and effort.

ASD's implementation advice is to pick a target level that suits your risk, then reach the same level across all eight strategies before moving up, because the strategies are designed to cover each other's gaps. Use a risk-based approach, keep exceptions few and small, document and approve them, and back them with compensating controls that you review regularly.

04

Who must comply with the Essential Eight?

  • Australian Government entities. Under the Protective Security Policy Framework (PSPF), non-corporate Commonwealth entities have been required since 1 July 2022 to implement all eight strategies to Maturity Level Two, and to consider whether their threat environment warrants Level Three. They report on their maturity each year. The PSPF is re-issued annually, so check the current release for the exact wording.
  • Suppliers to government. Agencies often pass Essential Eight expectations down to the software and service providers that hold their data, through tenders and contracts.
  • Private companies. There is no law requiring a private business to implement the Essential Eight. It is still the baseline Australian enterprise customers, cyber insurers and boards tend to ask about, and ASD publishes it for small and medium businesses and large organisations as well as government.

Regulated financial entities answer to APRA's prudential standards (such as CPS 234 on information security) rather than the Essential Eight, though many use it as a practical baseline. If you handle personal information, the Australian Privacy Act also requires reasonable security steps under APP 11, and the Essential Eight is a common way to show what "reasonable" means.

05

How is an Essential Eight assessment done?

ASD publishes assessment guidance alongside the maturity model. In short, an assessor checks each strategy against the requirements of the target level and the levels below it, and reports a level for each strategy rather than a single score. Documented and approved exceptions with compensating controls do not, by themselves, stop you being assessed as meeting a level.

For a SaaS company the practical questions are scope (corporate laptops and identity provider, production cloud, or both) and evidence: patch and scan reports, MFA and admin role exports, application control policies, macro settings, and restore test records.

06

Essential Eight vs ISO 27001 and SOC 2

They answer different questions. SOC 2 is an independent auditor's report on whether your controls meet the Trust Services Criteria. ISO 27001 certifies a management system for information security. The Essential Eight is a technical baseline with prescribed settings and timeframes. Having one does not give you the others, but the controls overlap, so evidence collected once can support all three. See SOC 2 vs ISO 27001 for how those two differ.

Essential Eight strategyOverlapping ISO 27001:2022 Annex A controlOverlapping SOC 2 criteria
Patch applications and operating systems8.8 Management of technical vulnerabilitiesCC7.1
Multi-factor authentication8.5 Secure authenticationCC6.1
Restrict administrative privileges8.2 Privileged access rightsCC6.1 to CC6.3
Application control8.19 Installation of software on operational systemsCC6.8
Restrict Office macros, user application hardening8.9 Configuration managementCC6.8, CC7.1
Regular backups8.13 Information backupA1.2 (availability, if in scope)

Overlap, not equivalence. ISO 27001 and SOC 2 let you choose how to meet a control; the Essential Eight prescribes specific settings and timeframes at each level.

07

Does TryTrustable support the Essential Eight?

Not as a framework. TryTrustable does not model the Essential Eight or assess maturity levels, and it does not collect endpoint data such as application control or Microsoft Office macro settings. What it does do is run the SOC 2 and ISO 27001 controls that overlap with several strategies: MFA and access reviews, admin privilege checks, vulnerability scanning in your CI pipeline and cloud configuration checks, with evidence collected from GitHub, AWS and GCP into a tamper-evident ledger. If you are building toward SOC 2 or ISO 27001 and an Australian customer asks about the Essential Eight, that shared evidence is a useful starting point, not a maturity rating.

Questions

The things people ask us

What are the Essential Eight strategies?

Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups.

What is the latest version of the Essential Eight Maturity Model?

The November 2023 version, which ASD's maturity model page still listed as current in 2026. ASD updates the model from time to time, so check cyber.gov.au before an assessment.

Is the Essential Eight mandatory?

For non-corporate Commonwealth entities, yes: the PSPF has required Maturity Level Two since 1 July 2022. For private companies it is voluntary unless a contract or tender requires it.

What maturity level should a private company aim for?

ASD suggests choosing a target based on how attractive you are to attackers and the impact of an incident. Many organisations start with Maturity Level One across all eight strategies, then move to Level Two, which is the government benchmark.

Is the Essential Eight the same as ISO 27001?

No. ISO 27001 is a certifiable management system standard; the Essential Eight is a set of technical mitigation strategies with maturity levels. Several controls overlap, such as vulnerability management, MFA, privileged access and backups.

Does TryTrustable assess Essential Eight maturity?

No. The platform models SOC 2, ISO 27001 and other frameworks, and some of those controls overlap with Essential Eight strategies. It does not rate Essential Eight maturity levels.

Book a walkthrough

Build the controls that overlap, once.

Thirty minutes on SOC 2 and ISO 27001 readiness, with evidence from your GitHub, AWS and GCP accounts landing in the ledger.