Free resource · Australian ACSC framework

Essential Eight Maturity Assessment Template

A worksheet covering all eight ACSC mitigation strategies across Maturity Levels 1–3 — with status, evidence and owner columns. Work through it below, or download the CSV and start now.

StrategyMaturity Level 1Maturity Level 2Maturity Level 3
1
Application control
Control execution in user-writable paths (temp, downloads) on workstations.Extend to internet-facing servers and all execution locations.Everywhere, with Microsoft block rules; ruleset validated annually.
2
Patch applications
Internet-facing apps within 2 weeks (48h if exploited); scan fortnightly.Internet-facing within 48h when exploited; others within 2 weeks; scan weekly.Patch/mitigate within 48h of exploit for all classes; remove unsupported apps.
3
Configure MS Office macro settings
Block macros for users without a need; block macros from the internet.Log macro executions; only vetted macros in trusted locations or signed.Blocked from internet; run only sandboxed/trusted; all executions monitored.
4
User application hardening
Browsers block Flash, ads, Java from internet; IE 11 disabled/removed.Browser/Office/PDF hardened to ACSC guidance; users can’t change blocked settings.Full hardening incl. PowerShell + command-line logging, centrally monitored.
5
Restrict administrative privileges
Validate privileged access on request; admins can’t browse web/email.Just-in-time/time-limited admin; separate privileged/unprivileged environments.Re-validate annually and on change; full privileged-activity logging.
6
Patch operating systems
Internet-facing OS within 2 weeks (48h if exploited); scan fortnightly.Internet-facing OS within 48h when exploited; workstations/servers within 2 weeks.Within 48h of exploit across all systems; latest/N-1 releases; remove unsupported OS.
7
Multi-factor authentication
MFA for internet-facing services and access to sensitive data.MFA for all users on internet-facing/important systems; events logged.Phishing-resistant MFA (FIDO2/passkeys) for users and admins.
8
Regular backups
Backups aligned to continuity needs; restoration tested at least once.Immutable backups; unprivileged accounts can’t modify/delete; restoration tested.Restoration tested in DR exercises; only backup admins access others’ backups.

Your overall maturity is the lowest level achieved across all eight strategies — set a target level and lift every strategy to it. Summarised from the ACSC Essential Eight Maturity Model; see acsc.gov.au for the authoritative version.

Essential Eight template FAQ

What is an Essential Eight maturity assessment template?
It is a worksheet that lists each of the eight ACSC mitigation strategies against the requirements for Maturity Levels 1, 2 and 3, with columns to record your current status, the evidence, an owner and a target date. It turns the Essential Eight Maturity Model into a practical tracker you can work through and report against.
Is this Essential Eight template free to download?
Yes — the full worksheet is free and needs no signup. The whole matrix is laid out on this page, and you can download it as a CSV to open in Excel or Google Sheets and start filling in immediately. If you would rather not maintain it by hand, CATAAM proves the automatable strategies (MFA, patching, admin restriction, backups) continuously.
How do I calculate my overall Essential Eight maturity?
Your overall maturity is the lowest level you have achieved across all eight strategies — the ACSC assesses the Essential Eight as a set, so a single strategy at Level 1 caps your whole organisation at Level 1 regardless of the others. Set a target level, then lift every strategy to it. The template’s final row captures this.
Can CATAAM automate the Essential Eight?
CATAAM automates and continuously verifies the strategies that are technical controls — multi-factor authentication, patching of applications and operating systems, restricting administrative privileges, and regular backups — by connecting to your cloud, identity and endpoint tooling. The remaining strategies are supported with guided manual evidence. See Essential Eight automation.

Stop tracking the Essential Eight in a spreadsheet

CATAAM proves MFA, patching, admin restriction and backups automatically — continuous, timestamped, mapped to each strategy.