Guide
The ACSC Essential Eight, Explained: The 8 Strategies, Maturity Levels 0–3, and How to Prove Them
August 30, 2026 · 9 min read
The Essential Eight is Australia’s cyber-security baseline — mandatory for federal government and the de-facto standard everyone else is measured against. Here’s what the eight strategies actually require, how the Maturity Model works, and why proving them beats claiming them.
Quick answer: the Essential Eight is a set of eight prioritised mitigation strategies published by the Australian Cyber Security Centre (ACSC) to protect organisations against the most common cyber threats. Each strategy is assessed against a Maturity Model with four levels (0–3). Maturity Level 2 is the common target for most commercial organisations. Federal (non-corporate Commonwealth) entities are mandated to implement it; in the private sector it has become the baseline that boards, insurers and customers benchmark against.
Who needs the Essential Eight?
Australian federal government entities are mandated to reach a target maturity level. Beyond that, the Essential Eight is used voluntarily but very widely: state agencies, critical-infrastructure operators, and private companies adopt it because it’s the clearest, most recognised measure of baseline cyber hygiene in Australia — and increasingly a requirement in contracts, cyber-insurance questionnaires and enterprise vendor reviews.
The eight mitigation strategies
- Application control — allow only approved executables, scripts, installers and libraries to run.
- Patch applications — patch or mitigate vulnerabilities in internet-facing apps within 48 hours when exploited.
- Configure Microsoft Office macro settings — block macros from the internet; allow only vetted/signed macros.
- User application hardening — block Java, web ads and unneeded browser/PDF features; disable legacy components.
- Restrict administrative privileges — validate, revalidate and isolate privileged access from internet, email and web.
- Patch operating systems — patch OS and network-device vulnerabilities on a strict SLA; retire unsupported OSes.
- Multi-factor authentication — MFA for internet-facing services, sensitive-data services and all privileged users.
- Regular backups — perform, retain and test restoration of important data, software and configuration.
How the Maturity Model works
Each strategy is assessed at Maturity Level 0 (not implemented), 1 (partly, against basic threats), 2 (against more capable adversaries), or 3 (against adaptive, targeted attackers). You target one maturity level across all eight strategies rather than mixing levels. Most commercial organisations aim for Maturity Level 1 or 2; ML3 is for high-value targets facing sophisticated threats.
Prove the Essential Eight — don’t just claim it
Four of the eight strategies — patching, MFA, restrict admin and backups — are highly technical and measurable, which is exactly where a screenshot-based checklist falls short. CATAAM validates each with an evidence-gated test against your live environment (patch status from your asset discovery, MFA from your identity provider, privileged access from your cloud IAM), and — because it’s also an attack-surface and breach-simulation platform — it can attack your own environment to prove the controls actually hold.
Already have ISO 27001 or SOC 2? You’re part-way there
The Essential Eight overlaps heavily with ISO 27001 and SOC 2 on patching, access control, MFA and backups. CATAAM cross-maps a single evidence set across all of them, so an ISO- or SOC 2-certified organisation auto-satisfies much of the Essential Eight and only builds the genuinely E8-specific controls (application control, macro hardening, user-application hardening).
Automate the Essential Eight with CATAAM
→