Skip to content
Nexcentric
Guide

What is the Essential Eight, and does my business need it?

Updated 31 July 2026 · 8 minute read

Short answer

The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Signals Directorate, assessed against four maturity levels from Level 0 to Level 3. It's mandatory for non-corporate Commonwealth entities and, while not legally required for private businesses, has become the benchmark cyber insurers, government tenders and enterprise clients ask about by name. Most Australian small and medium businesses should target Maturity Level 1 as a baseline.

The eight strategies

Published by the Australian Signals Directorate, the eight are designed to complement each other. ASD's guidance is to reach the same maturity level across all eight before progressing to a higher one — which is why your real maturity is your weakest strategy, not your average.

StrategyWhat it does
Patch applicationsCloses known vulnerabilities in software before they're exploited
Patch operating systemsSame, for the OS underneath everything else
Multi-factor authenticationStops stolen passwords being enough to get in
Restrict administrative privilegesLimits what a compromised account can do
Application controlPrevents unapproved programs — including ransomware — from running
Restrict Microsoft Office macrosBlocks a long-standing delivery method for malware
User application hardeningTurns off risky features in browsers and document readers
Regular backupsDetermines whether you recover or pay

The four maturity levels

Maturity Level Zero exists to describe organisations that don't yet meet Level One. It's more common than most business owners expect, and usually fixable quickly.

LevelWhat it's designed to withstand
Level 0Weaknesses a low-effort, opportunistic attacker could exploit
Level 1Opportunistic attackers using widely available tooling
Level 2More capable attackers investing time in a specific target
Level 3Adaptive, highly capable attackers who adjust to defences

Your overall maturity is your lowest-scoring strategy, not an average. One untested backup or one gap in MFA coverage defines your real exposure.

Is it mandatory?

For non-corporate Commonwealth entities, yes — the Essential Eight is required under the Protective Security Policy Framework.

For private Australian businesses it isn't a legal requirement. But it's become the common language for security expectations, which means it reaches you anyway through three routes: cyber insurance questionnaires at renewal, government and enterprise tender requirements, and larger customers pushing security obligations down their supply chain.

Businesses most often discover the Essential Eight when they're asked to evidence it — usually with a deadline attached.

What level should a small business aim for?

For most Australian SMEs, Maturity Level 1 is the sensible baseline and achievable without a large budget. Level 2 is realistic if you handle sensitive client data or are regularly asked about your posture.

Level 3 is aimed at organisations facing determined, well-resourced attackers. It's rarely proportionate for a small business, and pursuing it before Level 1 is solid across all eight is effort spent in the wrong order.

Where most businesses actually fail

Across assessments, the same gaps come up repeatedly — and they're rarely the exotic ones:

  • Backups that have never been restore-tested, so recoverability is assumed rather than proven
  • Backups a compromised administrator account could delete, which is exactly what ransomware targets first
  • MFA covering most staff but not all — attackers only need the account that isn't protected
  • Local administrator rights left on everyday user accounts
  • Macros enabled by default because turning them off once broke something years ago
  • Patching that happens when someone remembers rather than on a schedule

What it costs to get to Level 1

Less than most owners expect, because several of the eight are configuration changes rather than purchases. MFA, macro restrictions, removing local admin rights and application control are largely a matter of doing the work.

The costs that do arise are usually backup tooling capable of immutable copies, and the time to document and test. If you're on a managed IT service with security included, much of the Level 1 work should already be in scope — worth asking your provider to evidence rather than assume.

Common questions

Quick answers

What are the eight strategies in the Essential Eight?

Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups.

Is the Essential Eight mandatory in Australia?

It's mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework. It isn't legally required for private businesses, but cyber insurers, government tenders and enterprise clients increasingly ask about Essential Eight maturity specifically.

What Essential Eight maturity level should we target?

Maturity Level 1 is the sensible baseline for most Australian small and medium businesses. Level 2 is appropriate if you handle sensitive data or are regularly asked to evidence your security. Level 3 is aimed at organisations facing highly capable, adaptive attackers.

How is Essential Eight maturity calculated?

Each of the eight strategies is assessed independently against Levels 0 to 3. Your overall maturity is your lowest strategy score, because ASD's guidance is to reach the same level across all eight before progressing.

How long does it take to reach Maturity Level 1?

For a typical small business with a managed IT provider, a few weeks to a few months depending on the starting point. Several of the eight are configuration changes rather than purchases; backup improvements and documentation usually take longest.

Find out where you actually stand

Our free assessment takes three minutes and gives you a maturity level across all eight strategies, plus a ranked list of what to fix first. No signup.