What is the Essential Eight, and does my business need it?
Updated 31 July 2026 · 8 minute read
Short answer
The Essential Eight is a set of eight cyber security mitigation strategies published by the Australian Signals Directorate, assessed against four maturity levels from Level 0 to Level 3. It's mandatory for non-corporate Commonwealth entities and, while not legally required for private businesses, has become the benchmark cyber insurers, government tenders and enterprise clients ask about by name. Most Australian small and medium businesses should target Maturity Level 1 as a baseline.
The eight strategies
Published by the Australian Signals Directorate, the eight are designed to complement each other. ASD's guidance is to reach the same maturity level across all eight before progressing to a higher one — which is why your real maturity is your weakest strategy, not your average.
| Strategy | What it does |
|---|---|
| Patch applications | Closes known vulnerabilities in software before they're exploited |
| Patch operating systems | Same, for the OS underneath everything else |
| Multi-factor authentication | Stops stolen passwords being enough to get in |
| Restrict administrative privileges | Limits what a compromised account can do |
| Application control | Prevents unapproved programs — including ransomware — from running |
| Restrict Microsoft Office macros | Blocks a long-standing delivery method for malware |
| User application hardening | Turns off risky features in browsers and document readers |
| Regular backups | Determines whether you recover or pay |
The four maturity levels
Maturity Level Zero exists to describe organisations that don't yet meet Level One. It's more common than most business owners expect, and usually fixable quickly.
| Level | What it's designed to withstand |
|---|---|
| Level 0 | Weaknesses a low-effort, opportunistic attacker could exploit |
| Level 1 | Opportunistic attackers using widely available tooling |
| Level 2 | More capable attackers investing time in a specific target |
| Level 3 | Adaptive, highly capable attackers who adjust to defences |
Your overall maturity is your lowest-scoring strategy, not an average. One untested backup or one gap in MFA coverage defines your real exposure.
Is it mandatory?
For non-corporate Commonwealth entities, yes — the Essential Eight is required under the Protective Security Policy Framework.
For private Australian businesses it isn't a legal requirement. But it's become the common language for security expectations, which means it reaches you anyway through three routes: cyber insurance questionnaires at renewal, government and enterprise tender requirements, and larger customers pushing security obligations down their supply chain.
Businesses most often discover the Essential Eight when they're asked to evidence it — usually with a deadline attached.
What level should a small business aim for?
For most Australian SMEs, Maturity Level 1 is the sensible baseline and achievable without a large budget. Level 2 is realistic if you handle sensitive client data or are regularly asked about your posture.
Level 3 is aimed at organisations facing determined, well-resourced attackers. It's rarely proportionate for a small business, and pursuing it before Level 1 is solid across all eight is effort spent in the wrong order.
Where most businesses actually fail
Across assessments, the same gaps come up repeatedly — and they're rarely the exotic ones:
- Backups that have never been restore-tested, so recoverability is assumed rather than proven
- Backups a compromised administrator account could delete, which is exactly what ransomware targets first
- MFA covering most staff but not all — attackers only need the account that isn't protected
- Local administrator rights left on everyday user accounts
- Macros enabled by default because turning them off once broke something years ago
- Patching that happens when someone remembers rather than on a schedule
What it costs to get to Level 1
Less than most owners expect, because several of the eight are configuration changes rather than purchases. MFA, macro restrictions, removing local admin rights and application control are largely a matter of doing the work.
The costs that do arise are usually backup tooling capable of immutable copies, and the time to document and test. If you're on a managed IT service with security included, much of the Level 1 work should already be in scope — worth asking your provider to evidence rather than assume.
Quick answers
What are the eight strategies in the Essential Eight?
Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups.
Is the Essential Eight mandatory in Australia?
It's mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework. It isn't legally required for private businesses, but cyber insurers, government tenders and enterprise clients increasingly ask about Essential Eight maturity specifically.
What Essential Eight maturity level should we target?
Maturity Level 1 is the sensible baseline for most Australian small and medium businesses. Level 2 is appropriate if you handle sensitive data or are regularly asked to evidence your security. Level 3 is aimed at organisations facing highly capable, adaptive attackers.
How is Essential Eight maturity calculated?
Each of the eight strategies is assessed independently against Levels 0 to 3. Your overall maturity is your lowest strategy score, because ASD's guidance is to reach the same level across all eight before progressing.
How long does it take to reach Maturity Level 1?
For a typical small business with a managed IT provider, a few weeks to a few months depending on the starting point. Several of the eight are configuration changes rather than purchases; backup improvements and documentation usually take longest.
Find out where you actually stand
Our free assessment takes three minutes and gives you a maturity level across all eight strategies, plus a ranked list of what to fix first. No signup.
