IronSights
←All insights

essential eight

Essential Eight Maturity Level 2 checklist: every requirement, in ASD's words

All 83 Maturity Level 2 requirements quoted from ASD's maturity model and grouped by control, with the six logging and incident lines listed once, a note on what changed from Level 1, and what an assessor will ask to see.

Ryan BallootBy Ryan Balloot, Managing Director29 September 202612 min read
ByRyan Balloot29 September 202612 min read

Every requirement for 2, in 's own words, grouped by control. There are 83 control-specific lines plus six logging and incident-response lines that ASD repeats under four of the controls. Tick each one only when you can show an assessor the evidence, because Level 2 is the level where intentions stop counting and logs start.

The wording is quoted from the Essential Eight Maturity Model as published at cyber.gov.au and read on 29 September 2026. Where our note under a control says what changed from Level 1, it is describing the difference between Appendix A and Appendix B of that model.

Your overall level is your lowest control, so a Level 2 claim needs every list below complete. If you want the eight explained rather than listed, start with the Essential Eight controls, listed; if you want to know whether Level 2 is the right target, read what Level 2 takes to reach.

The six lines that repeat

ASD lists these under , restrict administrative privileges, application control and user application hardening. They are the same six requirements each time, so they are here once. An assessor will check them four times.

  • Event logs are protected from unauthorised modification and deletion.
  • Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.
  • Cyber security events are analysed in a timely manner to identify cyber security incidents.
  • Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.
  • Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered.
  • Following the identification of a cyber security incident, the cyber security is enacted.

If nothing today collects and keeps those logs centrally, that is a platform decision to make before anything else on this page, because four of the eight controls depend on it.

1. Patch applications

  • An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent scanning activities.
  • A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
  • A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
  • A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.
  • A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.
  • Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
  • Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
  • Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release.
  • Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release.
  • Online services that are no longer supported by vendors are removed.
  • Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

Level 2 adds one thing to Level 1 here: every other application has to be scanned fortnightly and patched within a month. The catch is the word every. Businesses without a complete asset list discover that gap at this control.

2. Patch operating systems

  • An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
  • A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
  • A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.
  • A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
  • Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
  • Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
  • Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.
  • Operating systems that are no longer supported by vendors are replaced.

Identical to Level 1. If you hold Level 1 here you already hold Level 2.

3. Multi-factor authentication

  • Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.
  • Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.
  • Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation's non-sensitive data.
  • Multi-factor authentication is used to authenticate users to their organisation's online customer services that process, store or communicate their organisation's sensitive customer data.
  • Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation's sensitive customer data.
  • Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
  • Multi-factor authentication is used to authenticate privileged users of systems.
  • Multi-factor authentication is used to authenticate unprivileged users of systems.
  • Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
  • Multi-factor authentication used for authenticating users of online services is -resistant.
  • Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.
  • Multi-factor authentication used for authenticating users of systems is phishing-resistant.
  • Successful and unsuccessful multi-factor authentication events are centrally logged.

Most of the Level 2 effort lands here. Staff MFA has to be phishing-resistant, which rules out SMS codes and simple push approvals for online services and for logging on to systems. In practice that means or hardware security keys for everyone, and a change-management job as much as a technical one. Plus the logging and incident lines below.

4. Restrict administrative privileges

  • Requests for privileged access to systems, applications and data repositories are validated when first requested.
  • Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated.
  • Privileged access to systems and applications is disabled after 45 days of inactivity.
  • Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.
  • Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.
  • Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.
  • Privileged users use separate privileged and unprivileged operating environments.
  • Privileged operating environments are not virtualised within unprivileged operating environments.
  • Unprivileged user accounts cannot logon to privileged operating environments.
  • Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
  • Administrative activities are conducted through jump servers.
  • Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.
  • Privileged access events are centrally logged.
  • Privileged user account and security group management events are centrally logged.

The 12-month revalidation, the 45-day inactivity cut-off and the jump server are the new lines. This is the control set that most reliably annoys senior technical staff, and most reliably stops a compromise becoming a takeover. Plus the logging and incident lines below.

5. Application control

  • Application control is implemented on workstations.
  • Application control is implemented on internet-facing servers.
  • Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.
  • Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients.
  • Application control restricts the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.
  • Microsoft's recommended application blocklist is implemented.
  • Application control rulesets are validated on an annual or more frequent basis.
  • Allowed and blocked application control events are centrally logged.

Level 2 extends the control from workstations to internet-facing servers and from user-writable folders to everywhere, adds Microsoft's blocklist, and expects someone to review the rules at least once a year. Plus the logging and incident lines below.

6. Restrict Microsoft Office macros

  • Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.
  • Microsoft Office macros in files originating from the internet are blocked.
  • Microsoft Office macro antivirus scanning is enabled.
  • Microsoft Office macros are blocked from making Win32 API calls.
  • Microsoft Office macro security settings cannot be changed by users.

One addition over Level 1: macros are blocked from Win32 API calls. That is a single rule, and it surfaces every macro that was quietly calling out of Office.

7. User application hardening

  • Internet Explorer 11 is disabled or removed.
  • Web browsers do not process Java from the internet.
  • Web browsers do not process web advertisements from the internet.
  • Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
  • Web browser security settings cannot be changed by users.
  • Microsoft Office is blocked from creating child processes.
  • Microsoft Office is blocked from creating executable content.
  • Microsoft Office is blocked from injecting code into other processes.
  • Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.
  • Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
  • Office productivity suite security settings cannot be changed by users.
  • PDF software is blocked from creating child processes.
  • PDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
  • PDF software security settings cannot be changed by users.
  • PowerShell module logging, script block logging and transcription events are centrally logged.
  • Command line process creation events are centrally logged.

The longest list at Level 2. Most of it maps to Microsoft's attack surface reduction rules and the ASD hardening guides for Edge, Office and Acrobat, applied by policy so users cannot undo them. Plus the logging and incident lines below.

8. Regular backups

  • Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
  • Backups of data, applications and settings are synchronised to enable restoration to a common point in time.
  • Backups of data, applications and settings are retained in a secure and resilient manner.
  • Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
  • Unprivileged user accounts cannot access backups belonging to other user accounts.
  • Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.
  • Unprivileged user accounts are prevented from modifying and deleting backups.
  • Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.

Level 2 extends the protection to privileged accounts: a domain admin should not be able to read or delete backups, because a domain admin is exactly what a operator becomes before they encrypt.

What an assessor will ask to see

A tick on this list is a claim until there is evidence behind it. For most of the lines above that means the policy or configuration that enforces the requirement, and a sample showing it working: vulnerability scan reports with dates, the patch records for a recent critical, MFA method settings from your identity provider, the privileged account list with its last revalidation date, application control event logs, the group policies for Office and browser hardening, and the log of the last restore test. The gap between having a control and being able to evidence it is where most Level 2 assessments find the work.

Frequently asked questions

How many requirements are there at Maturity Level 2?

83 control-specific requirements across the eight controls, plus six logging and incident-response requirements that ASD repeats under four of them. Counted the way ASD lists them, with the repeats, the total is higher; counted as distinct things to implement, it is 89.

What is the difference between Level 1 and Level 2?

Phishing-resistant MFA for staff, application control extended to servers and all locations, privileged access that expires and runs through jump servers, Office and PDF attack surface rules, backups protected from privileged accounts, and central logging with incident reporting to ASD. Patching operating systems does not change at all.

Who needs Maturity Level 2?

Commonwealth entities under PSPF Policy 14, and anyone whose contract, panel deed, insurer or enterprise customer names it. If nobody who matters to your revenue or risk is asking for it, a well-evidenced Level 1 with real detection behind it is usually the better use of the budget.

Does Level 2 require reporting incidents to ASD?

Yes. Reporting cyber security incidents to ASD as soon as possible after they occur or are discovered is a Level 2 requirement under four of the controls. That is separate from, and in addition to, any legal obligation under the Privacy Act or the Cyber Security Act 2024.

Where to start

An assessment rates every control at Level 0 to 3 against exactly these lines, with evidence, and gives you the gap list in priority order. That is what our Essential Eight assessment does. With the framework deprecating around mid-2027, an assessment completed now is evidence against the standard your contracts name; the retirement timeline has the dates.

Essential Eight

Find out which maturity level you actually hold.

We assess your environment against each of the eight controls, show you where you sit today, and set out what closing the gap involves. You get the findings whether or not you engage us for the uplift.