The is eight mitigation strategies published by the (ASD), each assessed at one of four maturity levels, from 0 (not implemented in a way that meets the intent) to Maturity Level 3. This page lists the eight, in ASD's current order, with what each one requires at Levels 1, 2 and 3. Every line is condensed from the maturity model as published at cyber.gov.au and read on 29 September 2026.
Two rules shape everything below. ASD expects an organisation to reach the same level across all eight before moving to the next, so your overall level is your lowest-scoring control, not your average. And the model is a minimum: exceptions are allowed if they are documented, approved and reviewed, and the levels are minimums.
The framework is being retired on a mid-2027 deprecation and mid-2028 retirement track. The controls carry across to its successor, so the list below stays useful. The dates are in our Essential Eight retirement timeline.
The eight, in one list
1. Patch applications. 2. Patch operating systems. 3. . 4. Restrict administrative privileges. 5. Application control. 6. Restrict Microsoft Office macros. 7. User application hardening. 8. Regular backups.
The first four are ASD's current priority order for most organisations, because they close the two entry points attackers use most, unpatched internet-facing software and , and limit what a stolen account can do. The rest limit what an attacker can do once inside, and the last one is what you fall back on when everything else has failed.
1. Patch applications
Find every application you run, scan it for missing patches on a schedule, and apply patches within a fixed window that shortens as the risk rises. Unsupported software is removed.
| Level | What the control requires |
|---|---|
| Maturity Level 1 | Automated asset discovery at least fortnightly. Vulnerability scanning daily for online services and weekly for office suites, web browsers and extensions, email clients, PDF software and security products. Online services patched within 48 hours when a vulnerability is rated critical or has a working exploit, otherwise within two weeks. Those application types patched within two weeks. Unsupported online services and unsupported applications of those types removed. |
| Maturity Level 2 | Everything at Level 1, plus every other application scanned at least fortnightly and patched within one month. |
| Maturity Level 3 | Everything at Level 2, plus the office, browser, email, PDF and security set patched within 48 hours when critical or exploited (two weeks otherwise), and unsupported applications of any kind removed. |
Deep dive: a patching strategy for Australian businesses.
2. Patch operating systems
The same discipline applied to Windows, macOS, Linux and the firmware on network devices, with the tightest windows on anything that faces the internet.
| Level | What the control requires |
|---|---|
| Maturity Level 1 | Automated asset discovery at least fortnightly. Internet-facing servers and network devices scanned daily; workstations and internal servers and devices scanned fortnightly. Internet-facing operating systems patched within 48 hours when critical or exploited, otherwise within two weeks. Workstations and internal systems patched within one month. Unsupported operating systems replaced. |
| Maturity Level 2 | No change from Level 1. The requirements are identical. |
| Maturity Level 3 | Everything at Level 2, plus drivers and firmware scanned fortnightly; workstations and internal systems, drivers and firmware patched within 48 hours when critical or exploited (one month otherwise); and only the latest or previous release of each operating system in use. |
3. Multi-factor authentication
A second factor on every sign-in that matters, with the method itself hardening as the level rises: at Level 1 any two factors will do, at Level 2 staff MFA has to be -resistant.
| Level | What the control requires |
|---|---|
| Maturity Level 1 | MFA for users of the organisation's own online services and third-party online services that hold sensitive data (and where available, non-sensitive data), for users of online customer services holding sensitive customer data, and for the customers of those services. The method is something you have plus something you know, or something you have that is unlocked by something you know or are. |
| Maturity Level 2 | Everything at Level 1, plus MFA for privileged and unprivileged users of systems. MFA for users of online services and of systems must be phishing-resistant, and customers must be offered a phishing-resistant option. Successful and unsuccessful MFA events centrally logged, logs protected from modification and deletion, logs from internet-facing servers analysed, incidents reported to the CISO and to ASD, and the incident response plan enacted. |
| Maturity Level 3 | Everything at Level 2, plus MFA for users of data repositories, phishing-resistant MFA for customers and data repository users too, and logs from internal servers and workstations analysed as well. |
Deep dive: implementing MFA under the Essential Eight, and what counts as phishing-resistant.
4. Restrict administrative privileges
Admin rights are granted on request, used from dedicated accounts in a separate environment, and kept away from email and the web. The higher levels add expiry, jump servers and .
| Level | What the control requires |
|---|---|
| Maturity Level 1 | Requests for privileged access validated when first made. Privileged users get a dedicated privileged account used only for privileged duties. Privileged accounts blocked from the internet, email and web services unless explicitly authorised, and then strictly limited. Separate privileged and unprivileged operating environments, with no logging on across them. |
| Maturity Level 2 | Everything at Level 1, plus privileged access revalidated every 12 months and disabled after 45 days of inactivity. Privileged environments not virtualised inside unprivileged ones. Administration through jump servers. Break-glass, local administrator and service account credentials long, unique, unpredictable and managed. Privileged access events and account and group management events centrally logged, with the same log protection, analysis and incident reporting as MFA. |
| Maturity Level 3 | Everything at Level 2, plus privileged access limited to what each user and service needs, Secure Admin Workstations, just-in-time administration, and memory integrity, Local Security Authority protection, Credential Guard and Remote Credential Guard enabled. Logs from internal servers and workstations analysed as well. |
Deep dive: restricting administrative privileges.
5. Application control
Only approved software runs. The scope widens from workstations to servers as the level rises, and Microsoft's own blocklists are layered on top.
| Level | What the control requires |
|---|---|
| Maturity Level 1 | Application control on workstations, applied to user profiles and the temporary folders used by operating systems, browsers and email clients. It restricts executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set. |
| Maturity Level 2 | Everything at Level 1, plus application control on internet-facing servers and in all locations, Microsoft's recommended application blocklist, rulesets validated at least annually, and allowed and blocked events centrally logged with the same log protection, analysis and incident reporting as MFA. |
| Maturity Level 3 | Everything at Level 2, plus application control on internal servers, drivers restricted to an approved set, Microsoft's vulnerable driver blocklist, and logs from internal servers and workstations analysed. |
Deep dive: application control explained.
6. Restrict Microsoft Office macros
Macros off for everyone without a demonstrated need, blocked outright from internet-sourced files, and at the top level allowed only when sandboxed, in a Trusted Location or signed by a trusted publisher.
| Level | What the control requires |
|---|---|
| Maturity Level 1 | Macros disabled for users without a demonstrated business requirement. Macros in files from the internet blocked. Macro antivirus scanning enabled. Macro security settings locked so users cannot change them. |
| Maturity Level 2 | Everything at Level 1, plus macros blocked from making Win32 API calls. |
| Maturity Level 3 | Everything at Level 2, plus only macros running in a sandbox, from a Trusted Location or signed by a trusted publisher may execute. Macros are checked for malicious code before being signed or placed in a Trusted Location, only the privileged users who do that checking can write to Trusted Locations, macros signed by untrusted publishers or with non-V3 signatures cannot be enabled from the Message Bar or Backstage View, and the trusted publisher list is validated at least annually. |
Deep dive: the 2025 macro settings update.
7. User application hardening
Browsers, Office and PDF readers configured so the features attackers abuse are switched off and stay off. Level 2 adds the Office and PDF attack-surface rules and PowerShell logging.
| Level | What the control requires |
|---|---|
| Maturity Level 1 | Internet Explorer 11 disabled or removed. Browsers do not process Java or web advertisements from the internet. Browser security settings locked so users cannot change them. |
| Maturity Level 2 | Everything at Level 1, plus browsers, office suites and PDF software hardened to ASD and vendor guidance with the stricter rule winning, and their settings locked. Microsoft Office blocked from creating child processes, creating executable content and injecting code into other processes, and prevented from activating OLE packages. PDF software blocked from creating child processes. PowerShell module, script block and transcription logging and command line process creation events centrally logged, with the same log protection, analysis and incident reporting as MFA. |
| Maturity Level 3 | Everything at Level 2, plus .NET Framework 3.5 and Windows PowerShell 2.0 disabled or removed, PowerShell in Constrained Language Mode, and logs from internal servers and workstations analysed. |
Deep dive: user application hardening.
8. Regular backups
Backups that match business criticality, restore to a single point in time, are tested in disaster recovery exercises, and cannot be read or destroyed by the accounts an attacker is most likely to steal.
| Level | What the control requires |
|---|---|
| Maturity Level 1 | Backups of data, applications and settings performed and retained according to business criticality and continuity requirements, synchronised to a common point in time, and retained securely and resiliently. Restoration to a common point in time tested in disaster recovery exercises. Unprivileged accounts cannot access other accounts' backups and cannot modify or delete backups. |
| Maturity Level 2 | Everything at Level 1, plus privileged accounts (other than backup administrators) also cannot access other accounts' backups or modify or delete backups. |
| Maturity Level 3 | Everything at Level 2, plus no unprivileged or privileged account (other than backup administrators) can access even its own backups, and backup administrators cannot modify or delete backups during the retention period. |
Deep dive: backup and recovery under the Essential Eight, and what a backup has to survive in are backups safe to restore after ransomware.
What the levels are calibrated against
Level 1 is aimed at attackers using commodity tools who are looking for any victim rather than you in particular. Level 2 is aimed at attackers willing to spend more time on a target and on their tooling, including phishing for credentials and working around weak MFA. Level 3 is aimed at adaptive attackers who make swift use of new exploits, steal authentication tokens to bypass stronger MFA and work to evade detection. ASD is explicit that Level 3 will not stop an attacker willing to invest enough time, money and effort.
Which level you need is set by whoever is asking. Government suppliers under PSPF Policy 14 need Level 2. Most insurers and supply-chain questionnaires ask for Level 1. Our maturity levels explainer covers how to pick a target, and the Level 2 checklist has every Level 2 requirement as a tick list.
Frequently asked questions
What are the Essential Eight controls?
Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups. ASD publishes them with a maturity model that sets requirements at Levels 1, 2 and 3.
How is the overall maturity level worked out?
By the lowest control. ASD expects the same level across all eight before moving up, so seven controls at Level 2 and one at Level 1 is an overall Level 1.
Does the Essential Eight require certification?
No. ASD says there is no requirement to have an implementation certified by an independent party, but a government directive, a regulator or a contract may require an independent assessment.
Is the Essential Eight still current?
Yes, until deprecation begins around mid-2027. The replaces it, and the controls carry across.
Where to start
An assessment rates each of the eight at Level 0 to 3 with evidence and gives you the gap list in priority order. If you want a rough sense first, our free Essential Eight self-assessment takes five minutes, and the assessment service does it properly.



