Key Takeaways
- The Essential Eight maturity model includes four levels, from Maturity Level Zero to Maturity Level Three. The levels reflect increasing control strength across the eight mitigation strategies.
- The target maturity level should be based on risk. A small organization may prioritize Level One, while a larger enterprise or critical infrastructure provider may need Level Two or Level Three.
- Organizations should avoid uneven maturity. If one Essential Eight strategy lags behind the rest, it can limit the value of stronger controls elsewhere.
- A connected GRC approach makes Essential Eight maturity easier to manage because it links controls, risks, remediation, evidence, and reporting in one workflow.
- An essential eight compliance program can be managed effectively through a connected risk and compliance approach.
What Is the Essential Eight Maturity Model?
The Essential Eight Maturity Model is a framework for essential eight cyber security that helps organizations assess their implementation of the Australian Signals Directorate’s (ASD) eight mitigation strategies. It categorizes security progress into four distinct levels, providing a clear roadmap for improving cybersecurity posture.
The model is a central component of Australia’s cyber policy direction, which is increasingly focused on uplift. Horizon 2 of the 2023–2030 Australian Cyber Security Strategy reinforces the need to strengthen cyber maturity across government, critical infrastructure, industry, and the wider digital economy. The maturity model gives organizations a practical way to turn the goal of cybersecurity uplift into measurable control progress. The four levels help teams understand their current baseline, identify areas for improvement, and build stronger protection across all eight strategies.
The Essential Eight is a set of cybersecurity mitigation strategies developed by the Australian Signals Directorate. It focuses on eight practical areas:
| Essential Eight Strategy | What It Helps Reduce |
| Patch Applications | Exposure from vulnerable software |
| Patch Operating Systems | Exposure from vulnerable platforms |
| Multi-Factor Authentication | Credential misuse and unauthorized access |
| Restrict Administrative Privileges | Excessive privileged access |
| Application Control | Execution of unauthorized software |
| Restrict Microsoft Office Macros | Macro-based malware activity |
| User Application Hardening | Browser, Office, and PDF-based attack paths |
| Regular Backups | Data loss and recovery disruption |
The maturity model defines the depth of implementation for these strategies. It allows organizations to evaluate if their current controls are basic, developing, strong, or advanced enough for their environment.
The Four Maturity Levels
| Maturity Level Zero | Important Essential Eight controls are missing or inconsistently implemented. |
| Maturity Level One | Controls address common and opportunistic attack methods. |
| Maturity Level Two | Controls address attackers using more targeted methods and stronger attempts to bypass controls. |
| Maturity Level Three | Controls address more adaptive attackers that may invest effort in bypassing the organization’s defenses. |
Start Getting Value With
Centraleyes for Free
See for yourself how the Centraleyes platform exceeds anything an old GRC
system does and eliminates the need for manual processes and spreadsheets
to give you immediate value and run a full risk assessment in less than 30 days
Maturity Level Zero
Maturity Level Zero means the organization has gaps across the Essential Eight that could leave systems and data exposed. Conducting an essential eight assessment at this stage helps teams understand their current baseline, document known gaps, and identify control ownership. It does not always mean nothing has been done. It often means controls are partial, inconsistent, or difficult to prove.
For example, an organization may patch some systems quickly but lack reliable asset discovery. Another may use MFA for cloud applications but leave privileged access outside the process. A third may perform backups but rarely test restoration.
At this level, the most useful work is visibility. Teams need to understand what exists, what is missing, and where control ownership is unclear.
Useful actions:
- Identifying the systems in scope
- Mapping current controls to each Essential Eight strategy
- Documenting known gaps and exceptions
- Assigning owners for remediation
- Building a practical timeline for Level One
Maturity Level Zero is a starting point. The goal is to create enough structure to move from awareness to action.
Maturity Level One
Maturity Level One focuses on reducing exposure to common and opportunistic attacks. These are attacks that often rely on known vulnerabilities, stolen credentials, basic social engineering, or weak administrative controls.
This level is often the first meaningful target for organizations that are formalizing their cybersecurity program.
At Level One, teams begin to put the basic operating routines in place. They patch critical internet-facing systems quickly. They remove unsupported software. They apply MFA to sensitive online services. They restrict unnecessary administrative access. They manage macros, harden common applications, and maintain usable backups.
The important point is consistency. A control that works for one business unit but not another may create a false sense of maturity.
For many teams, the biggest challenge at Level One is not understanding the requirement. It is turning the requirement into recurring work. Patching needs a defined cadence. MFA needs coverage tracking. Backups need testing. Administrative access needs review.
This is where a compliance management system can help teams track requirements, control owners, evidence, and remediation in a more reliable way.
Maturity Level Two
Maturity Level Two reflects a more mature control environment. It is designed for organizations facing attackers that are more selective and willing to spend more effort on bypassing basic controls.
This is where Essential Eight implementation often becomes more operationally demanding.
At Level Two, organizations need stronger assurance across areas such as phishing-resistant MFA, privileged access management, event logging, application control, and incident response. Controls are expected to be more complete. Evidence is expected to be easier to review. Exceptions need to be documented and managed.
The shift from Level One to Level Two often reveals process issues. For example, an organization may discover that MFA coverage is not easy to report across all systems. It may find that privileged access reviews are performed, but not consistently recorded. It may have backups in place, but restoration testing is not tied to business criticality.
A Level Two program usually has three traits:
- Clear control ownership
- Repeatable evidence collection
- Remediation tracking that shows progress
This is also where compliance gap analysis becomes important. Teams need to compare the current state against the target maturity level and identify the work that will close the gap.
Maturity Level Threes
Maturity Level Three is the most advanced Essential Eight maturity level. It is designed for organizations that need to prepare for more adaptive attackers. These attackers may look for ways around technical controls, attempt to gain privileged access, move across environments, and hide activity.
At this level, security controls need to be stronger and more deeply embedded. Teams may need broader application control coverage, stronger administrative workstations, just-in-time administration, deeper logging, stricter macro controls, and stronger backup protections.
Level Three is not only a technical challenge. It requires governance discipline.
Security teams need to know which systems meet the requirements. Risk teams need to understand residual exposure. Compliance teams need evidence that can stand up to review. Leaders need reporting that explains progress in business terms.
How to Choose the Right Target Maturity Level
The right target maturity level depends on the organization’s risk profile.
A small business with limited sensitive data may begin with Level One. A large enterprise with distributed systems and sensitive customer data may need Level Two. A critical infrastructure provider or high-value target may need Level Three.
The decision should consider:
- The sensitivity of data handled by the organization
- The importance of system availability
- The organization’s exposure to targeted attacks
- Contractual or regulatory expectations
- The maturity of existing security operations
- The ability to maintain controls over time
The Information Security Manual may also be relevant for organizations that need broader control guidance beyond the Essential Eight.
Why Consistency Across All Eight Strategies Matters
One of the most important Essential Eight ideas is that the strategies are designed to work in parallel.
This is a point worth stressing because maturity is often limited by the least mature area. If seven strategies are operating at Level Two and one remains at Level One, the overall posture may still reflect that lower maturity.
It may seem ironic, but a balanced program is usually stronger than an uneven one. Teams should look for the control areas that lag behind and ask why. The issue may be technical. It may be ownership. It may be evidence. It may be a legacy system that needs a risk decision. If strategies are inconsistent, the results of an essential eight audit may not accurately reflect the organization’s true security posture.
How Centraleyes Helps
Centraleyes helps organizations manage Essential Eight implementation as part of connected risk and compliance workflows.
Teams can map Essential Eight requirements to controls, assign ownership, manage evidence, track remediation, and report maturity in one place. This helps reduce disconnected manual work and gives leaders a clearer view of progress.
Centraleyes also supports broader cyber risk and compliance programs, including framework mapping, risk register workflows, audit readiness, regulatory tracking, and executive reporting. For organizations managing Essential Eight alongside other frameworks, this connected approach helps teams avoid duplicating work across separate spreadsheets and systems.
FAQs
What Are the Four Essential Eight Maturity Levels?
The four levels are Maturity Level Zero, Maturity Level One, Maturity Level Two, and Maturity Level Three. Level Zero reflects gaps or inconsistent implementation. Levels One through Three reflect increasing control strength against more capable attacker behavior.
Does Every Organization Need to Reach Maturity Level Three?
No. The target level should reflect the organization’s risk profile, threat environment, regulatory expectations, and business impact. Level Three may be appropriate for critical infrastructure or high-threat environments, but many organizations may first focus on Level One or Level Two.
Can an Organization Be Partially Mature Across the Essential Eight?
Yes, but uneven maturity should be managed carefully. If one strategy is much weaker than the others, it may reduce the practical value of stronger controls elsewhere. Teams should identify the lowest-performing strategies and prioritize targeted uplift.
Is Essential Eight Compliance the Same as Certification?
No. The Essential Eight maturity model does not require independent certification by default. However, an independent assessment may be required by a government directive, regulator, customer, or contract.
How Often Should Essential Eight Maturity Be Reviewed?
Organizations should review maturity regularly, especially after major technology changes, new systems, audit findings, incidents, or changes in regulatory expectations. Many teams review progress quarterly and perform a deeper assessment annually.
Start Getting Value With
Centraleyes for Free
See for yourself how the Centraleyes platform exceeds anything an old GRC
system does and eliminates the need for manual processes and spreadsheets
to give you immediate value and run a full risk assessment in less than 30 days


