IronSights
←All insights

essential eight

Essential Eight Maturity Level 1 checklist: every requirement, in ASD's words

All 48 Maturity Level 1 requirements quoted from ASD's maturity model and grouped by control, with a note under each on what most often stops a business ticking it, and what an assessor will ask to see.

Ryan BallootBy Ryan Balloot, Managing Director29 September 20269 min read
ByRyan Balloot29 September 20269 min read

Every requirement for 1, in 's own words, grouped by control. There are 48 lines. Level 1 is the level insurers, tenders and supply-chain questionnaires most often ask for, and it is calibrated against attackers using commodity tools who are looking for any victim rather than you in particular. It is also the level many businesses assume they already hold.

The wording is quoted from the Essential Eight Maturity Model as published at cyber.gov.au and read on 29 September 2026. The note under each control says what most often stops a business from ticking the lines above it.

Your overall level is your lowest control, so seven controls at Level 1 and one at Level 0 is Level 0. The companion Level 2 checklist has the next tier in the same format, and the Essential Eight controls, listed explains each control before you tick anything.

1. Patch applications

  • An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent scanning activities.
  • A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
  • A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
  • A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.
  • Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
  • Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
  • Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release.
  • Online services that are no longer supported by vendors are removed.
  • Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

Two things surprise people here. The first is that Level 1 already asks for automated asset discovery and a vulnerability scanner, not a spreadsheet. The second is the 48-hour window: an exploited vulnerability in anything internet-facing has to be patched within two days at the lowest level, not the lowest priority.

2. Patch operating systems

  • An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
  • A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
  • A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.
  • A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
  • Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
  • Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
  • Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.
  • Operating systems that are no longer supported by vendors are replaced.

Network devices count as operating systems here. The firewall and the switch have to be in the scanner and inside the 48-hour window, which is where a lot of Level 1 claims fall over.

3. Multi-factor authentication

  • is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.
  • Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.
  • Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation's non-sensitive data.
  • Multi-factor authentication is used to authenticate users to their organisation's online customer services that process, store or communicate their organisation's sensitive customer data.
  • Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation's sensitive customer data.
  • Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
  • Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.

Level 1 does not require -resistant MFA and does not require MFA to log on to workstations or servers; that arrives at Level 2. What it does require is MFA on every online service holding sensitive data, including the third-party ones, and on customer-facing services for the customers themselves. The cloud storage and collaboration tools are the ones most often missed.

4. Restrict administrative privileges

  • Requests for privileged access to systems, applications and data repositories are validated when first requested.
  • Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.
  • Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.
  • Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.
  • Privileged users use separate privileged and unprivileged operating environments.
  • Unprivileged user accounts cannot logon to privileged operating environments.
  • Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.

The IT team reading email from the domain admin account is one of the most common Level 1 failures. Separate accounts, and admin accounts that cannot browse or open mail, are the whole control at this level.

5. Application control

  • Application control is implemented on workstations.
  • Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.
  • Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.

Three lines, and usually the longest project. Workstations only at this level, and only the folders a user or a download can write to, but the allowlist has to exist before enforcement can, and building it surfaces every unapproved tool the business quietly depends on.

6. Restrict Microsoft Office macros

  • Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.
  • Microsoft Office macros in files originating from the internet are blocked.
  • Microsoft Office macro antivirus scanning is enabled.
  • Microsoft Office macro security settings cannot be changed by users.

Demonstrated business requirement means a documented one. A list of who needs macros and why, with the setting enforced by policy rather than left to the user, is what an assessor will ask for.

7. User application hardening

  • Internet Explorer 11 is disabled or removed.
  • Web browsers do not process Java from the internet.
  • Web browsers do not process web advertisements from the internet.
  • Web browser security settings cannot be changed by users.

Four browser settings, all of them policy-enforced. The Office and PDF hardening rules and PowerShell logging that people associate with this control are Level 2.

8. Regular backups

  • Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
  • Backups of data, applications and settings are synchronised to enable restoration to a common point in time.
  • Backups of data, applications and settings are retained in a secure and resilient manner.
  • Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
  • Unprivileged user accounts cannot access backups belonging to other user accounts.
  • Unprivileged user accounts are prevented from modifying and deleting backups.

Applications and settings, not just data, and a restore test as part of a disaster recovery exercise. A backup that has never been restored from does not meet the fourth line, however complete it is.

What an assessor will ask to see

For each line, the configuration or policy that enforces it and a sample showing it working. In practice that is a vulnerability scan report with dates, the patch records for a recent critical, the MFA settings from your identity provider showing which services are covered, the list of privileged accounts and their separate unprivileged ones, the application control policy and a sample of blocked executions, the group policy for macros and browser settings, and the log of the last restore test. Where a control is only partly in place, ASD allows documented and approved exceptions, but an exception that nobody wrote down is a Level 0 finding.

Frequently asked questions

How many requirements are there at Maturity Level 1?

48, across the eight controls, in the current maturity model. Unlike Level 2, none of them are about logging or incident reporting; those requirements begin at Level 2.

What does Maturity Level 1 protect against?

ASD describes the Level 1 adversary as one who uses commodity tradecraft that is widely available, opportunistically exploiting unpatched online services or stolen, reused, brute-forced or guessed credentials, and looking for any victim rather than a specific one.

Is Maturity Level 1 enough?

For most businesses whose contracts, insurer and sector expectations are satisfied at Level 1, yes, provided it is evidenced rather than assumed. If someone who matters to your revenue names Level 2, or you face attackers willing to target you specifically, the Level 2 checklist is the next step.

How long does it take to reach Maturity Level 1?

A focused program with a named owner typically takes three to six months. Application control and macro restrictions are the slow ones, because the allowlist and the macro-requirement list have to be built before either can be enforced.

Does Level 1 require phishing-resistant MFA?

No. Level 1 accepts any combination of something you have and something you know, or something you have unlocked by something you know or are. Phishing-resistant MFA is a Level 2 requirement.

Where to start

An assessment rates every control at Level 0 to 3 against exactly these lines, with evidence, and gives you the gap list in priority order. That is what our Essential Eight assessment does. If you want a rough sense first, the free self-assessment takes five minutes.

Essential Eight

Find out which maturity level you actually hold.

We assess your environment against each of the eight controls, show you where you sit today, and set out what closing the gap involves. You get the findings whether or not you engage us for the uplift.