Essential Eight Maturity in Australia: what boards need to approve, not just read

September 21, 2026

Essential Eight Maturity in Australia: what boards need to approve, not just read

8 Min Read

The Essential Eight only delivers value when it is tied to a decision the board is willing to sign. Treated as an IT project, it produces a maturity score that no one funds. Treated as a governance question, it puts Australian cyber risk in front of the people who allocate capital against it.

The Australian Signals Directorate's Essential Eight covers eight controls: application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. It has become the baseline that regulators, auditors, insurers and Commonwealth buyers expect to see first. The question is not whether to adopt it. The question is what maturity level each of your critical systems needs to reach, by when, and what business risk the organisation carries in the meantime.

Why "we have Essential Eight" is not the same as "we are protected"

Most Australian organisations we meet in Melbourne can point to some form of Essential Eight coverage: MFA at the perimeter, a patching cadence, endpoint backups. Very few can show an auditor a single, current, evidenced view that maps each control to its ASD maturity criteria, to the systems in scope, and to the residual risk the board has accepted.

That gap matters for three reasons.

First, ASD's Essential Eight Maturity Model is prescriptive. Maturity Level One (ML1), Two (ML2) and Three (ML3) are defined by specific technical implementations, not by intent. Partial MFA is not ML1. Weekly patching where ASD requires 48 hours is not ML2. A control sits at the level of its weakest implementation, not the average.

Second, Australian regulators are increasingly asking Essential Eight questions in language that assumes a boardroom answer. APRA-regulated entities are examined against CPS 234; critical infrastructure operators against the SOCI Act and their Critical Infrastructure Risk Management Programme (CIRMP), which now references the Essential Eight. Commonwealth suppliers are expected to align with the Protective Security Policy Framework (PSPF) and the Information Security Manual (ISM), both of which lean on Essential Eight controls.

Third, cyber insurers now underwrite off maturity evidence, not intent. A refreshed policy or a lower excess routinely turns on producing an Essential Eight report an underwriter can read.

What the maturity levels actually mean for the business

Maturity levels describe the kind of attacker your controls can defeat. They are not scores on an abstract scale.

  • ML1.Defends against attackers using widely available, off-the-shelf tooling. Enough for lower-risk business functions; rarely enough for regulated data, critical infrastructure, or Commonwealth work.
  • ML2.Defends against attackers who invest time and modest tradecraft against your organisation specifically. This is the working baseline for most APRA-regulated entities and for critical infrastructure of moderate criticality.
  • ML3.Defends against well-resourced attackers who adapt their tradecraft to your environment. Appropriate for systems of national significance, high-value financial services, and Commonwealth-sensitive workloads.

The board decision is not "what maturity level is best". It is: which systems must sit at which level, by when, and what business risk the organisation accepts until each one gets there. Once the question is put in those terms, the Essential Eight becomes a funding decision, not an IT ticket.

The five gaps that fail an Essential Eight assessment

Across the Essential Eight assessments the NCG Melbourne team runs, the same five gaps recur.

  1. Application control is documented but not enforced.Allow-listing runs in audit mode on production endpoints, or excludes servers altogether. ASD's assessment methodology treats this as not met.
  2. Patching is measured by cadence rather than exposure.A monthly patch window looks disciplined until an internet-facing vulnerability sits open for 20 days. ML2 requires 48 hours for internet-facing services and 14 days for the rest, timed from vendor release, not from ticket creation.
  3. MFA is applied inconsistently.Perimeter MFA is common. MFA on privileged accounts, service accounts, remote access into OT environments, and legacy authentication paths often is not. Attackers use the gaps, not the coverage.
  4. Administrative privileges are standing, not time-bound.ML2 expects segregation of duties and just-in-time elevation for privileged accounts. Standing domain admin, however few the accounts, will fail the level.
  5. Backups exist, but tested recovery does not.Documented recovery of the top ten business services within business-defined RTOs, from immutable copies, in a segregated environment, is rare.

None of these gaps are exotic. All five determine whether an Essential Eight report will hold up in front of APRA, ASIC, a cyber insurer or a Commonwealth buyer, or whether it will stall the conversation.

How the Essential Eight fits with SOCI, APRA CPS 234, ISO 27001 and the ISM

The Essential Eight sits inside Australia's broader regulatory framework. It does not replace any of the obligations it interacts with.

  • SOCI Act and CIRMP.Critical infrastructure entities must maintain a Critical Infrastructure Risk Management Programme and attest annually. The Essential Eight is one of the recognised cyber standards a CIRMP can be aligned to. The board attestation obligation makes the maturity level a governance number, not a technical one.
  • APRA CPS 234 and CPS 230.CPS 234 requires proportional information security capability tied to the sensitivity and criticality of information assets. CPS 230, in force from July 2025, adds operational risk management, business continuity, and third-party service provider obligations. Essential Eight maturity is a defensible way to demonstrate control adequacy under both.
  • ISO 27001.Essential Eight controls map cleanly to Annex A of ISO 27001:2022. Running both in parallel is common: ISO 27001 provides the management system, the Essential Eight provides the technical baseline.
  • PSPF and ISM.For Commonwealth-facing work and IRAP assessments, Essential Eight controls are expected as a floor. Alignment reduces the effort of PSPF and ISM control mapping later.
  • Privacy Act 1988 and the APPs.The Essential Eight does not satisfy APP 11 on its own, but strong maturity substantially strengthens the "reasonable steps" defence in the event of a notifiable data breach.

Organisations that run these frameworks together, rather than as five separate projects, spend less on audit and end up with better coverage. The goal is a single control, evidenced once, that answers several obligations at the same time.

How to run an Essential Eight uplift that survives an audit

An uplift that produces a defensible ML2 or ML3 outcome has five characteristics.

  1. Scope by system, not by organisation.Declare the systems in scope, their business owners, and the maturity level target for each. A single organisation-wide maturity number is neither accurate nor useful.
  2. Baseline against ASD's assessment methodology.Use ASD's own assessment guidance as the yardstick, not a vendor's interpretation of it. Discrepancies caught early are cheaper than discrepancies raised by an assessor.
  3. Fix by control, not by tool.Each of the eight controls has a defined technical outcome. Buying a platform is not the same as achieving that outcome. Evidence packs should show the outcome, not the licence.
  4. Bring identity and privileged access into scope from day one.MFA and administrative privileges are the two controls that most often decide the level. Both are identity problems, not endpoint problems.
  5. Rehearse the board conversation.Every uplift should end with a one-page view a director can read: systems, target level, current level, gap, cost, timeline, residual risk accepted.

How to start this quarter

If the Essential Eight is on your risk register but not yet on the board's decision list, three actions will move it inside one quarter.

  • Commission an Essential Eight maturity assessment against ASD's current methodology, scoped by system, with an evidence pack per control.
  • Convert the assessment into a board paper that names the target maturity level per system, the funding required, and the residual risk accepted until the target is met.
  • Align the uplift roadmap with the other frameworks your organisation already answers to (SOCI, APRA, ISO 27001, PSPF and ISM) so a single set of controls services several obligations.

The organisations that get the Essential Eight right in Australia are not the ones with the highest maturity score. They are the ones whose boards have made a deliberate, funded, minuted decision about which systems sit at which level, and why.

Frequently asked questions

Is the Essential Eight mandatory in Australia?

For non-corporate Commonwealth entities the Essential Eight is mandatory under the PSPF. For private-sector organisations it is not universally mandatory, but it is expected in practice under the SOCI Act, APRA CPS 234, ISM alignment for Commonwealth suppliers, and by most cyber insurers.

What is the difference between ML1, ML2 and ML3?

ML1, ML2 and ML3 describe the kind of attacker each level of control is designed to defeat. ML1 addresses attackers using off-the-shelf tooling. ML2 addresses attackers who invest time and modest tradecraft against your organisation. ML3 addresses well-resourced attackers who adapt their tradecraft to your environment.

How long does an Essential Eight uplift take?

Typical ML1 to ML2 uplifts run 6 to 12 months, depending on the identity, patching and application-control estate. ML2 to ML3 is usually 12 to 18 months and requires design changes, not just configuration changes.

Does the Essential Eight replace ISO 27001?

No. The Essential Eight is a technical control baseline. ISO 27001 is a management system. Most Australian organisations run both.

Who signs off on Essential Eight maturity?

Technically the CISO or equivalent. Commercially the board or its risk committee, because the maturity level chosen for each system is a risk-acceptance decision.

NCG's Melbourne practice runs Essential Eight assessments and uplift programmes for Australian organisations regulated under the SOCI Act, APRA CPS 234 and CPS 230, and for Commonwealth suppliers preparing for PSPF and IRAP. Talk to our Australian team.

Thank you!