The latest published Essential Eight Maturity Model covered by official ASD material is the November 2023 version. ASD’s June 2026 announcement proposed developing an “Essentials” series, with the evolution of Essential Eight guidance as its first chapter, but the consultation notice does not establish that a replacement has since been finalised or set a transition date. For now, organisations should distinguish the published model from the proposed change.
What applies under the current published model?
The Essential Eight are eight prioritised mitigation strategies developed by the Australian Signals Directorate (ASD) to help organisations defend against cyber threats. The maturity model describes how thoroughly an organisation implements them against increasing levels of malicious actors’ tradecraft and targeting. The levels are not labels for particular adversary groups, and a higher level is not a guarantee that an organisation cannot be compromised.
Scope: internet-connected enterprise IT
ASD designed the model for internet-connected information technology networks. Its principles may also be applied to enterprise mobility and operational technology, but those environments were not the model’s design target; their distinct threats may call for other or additional mitigations. Treat an Essential Eight assessment in those areas as one part of a broader risk assessment, not proof that the environment is comprehensively protected.
How the maturity levels work
Level Zero records weaknesses where the organisation does not meet Level One requirements. Levels One, Two and Three represent progressively greater resistance to malicious actors’ tradecraft and targeting. ASD recommends setting a target appropriate to the organisation and implementing the levels progressively. Its model advises reaching the same maturity level across all eight strategies before moving to a higher level, because the strategies are designed to complement one another.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
Assessment is not automatically certification
ASD’s October 2024 Essential Eight Assessment Process Guide covers assessment of both control implementation and effectiveness against the November 2023 model. It says independent certification is not generally required, although a government directive or policy, regulator or contract may require an independent assessment. An assessor can consider whether compensating controls provide equivalent protection. Products mentioned in ASD’s guide are illustrative examples, not endorsements.
What changed in the November 2023 update?
ASD’s November 2023 changes focused on patching, stronger multi-factor authentication (MFA), management of privileged access and cloud services, and improved detection and response for internet-facing infrastructure. The changes also clarified or added requirements across application control, logging, hardening and backups.
Patching vulnerabilities and applications
The update emphasised prompt action on vulnerabilities vendors assess as critical, including specified cases enabling privileged authentication bypass or unauthenticated remote code execution. ASD’s change publication sets a 48-hour mitigation timeframe for specified critical or exploited cases; that is not a universal deadline for every vulnerability.
For high-risk applications that routinely interact with untrusted internet content, the Level One patching timeframe changed from one month to two weeks, and the minimum scan frequency increased from at least fortnightly to at least weekly. Some lower-priority operating-system patching and scanning timeframes were rebalanced. At Level Three, the model added patching or mitigation for driver and firmware vulnerabilities.
Multi-factor authentication
At Level One, MFA must include “something users have” as well as “something users know,” or something users have that is unlocked using something users know or are. The update tightened customer MFA requirements for online services handling sensitive data and introduced phishing-resistant MFA at a lower maturity level. It also requires phishing-resistant MFA for workstations at Levels Two and Three. ASD gives FIDO2 and WebAuthn as examples of standards associated with phishing-resistant MFA; organisations should apply the model’s specific requirements rather than treating any MFA method as interchangeable.
Privileged access and application control
The update added governance for granting, controlling and rescinding privileged access to data repositories. It also restricts internet access by privileged accounts: access must be explicitly authorised and limited to duties, supporting safer cloud-service management. Higher maturity levels address break-glass credentials; Level Three adds secure administrative workstations and Windows hardening requirements.
Rank #3
At Level Two, organisations must implement Microsoft’s recommended application blocklist and validate application-control rulesets at least annually.
Logging, incident response and other changes
At Level Two, requirements for centralised collection, protection and analysis of event logs, incident reporting and response apply across the strategies. ASD says logging analysis at this level should focus on internet-facing infrastructure, consistent with that level’s threat model.
Free tools Windows power users keep installed
One-click scans. No signup required.
The update removed a requirement to collect and analyse Microsoft Office macro execution events, while adding a Level Three requirement to use newer V3 digital signatures for macros. It also requires disabling or uninstalling Internet Explorer 11 and implementing ASD and vendor hardening guidance where available. Backup prioritisation should account for business criticality, not only whether data is labelled “important.”
Rank #4
How should an organisation choose a target level?
ASD’s FAQ offers broad examples: Level One may suit small and medium enterprises, Level Two large enterprises, and Level Three critical infrastructure providers and other high-threat organisations. These are starting points, not a rule that assigns a level by organisation size or sector.
Use the risk the organisation needs to address to make the decision. In particular, consider:
- the tradecraft and degree of targeting the organisation intends to mitigate;
- how attractive it may be as a target;
- the possible consequences for confidentiality, integrity and availability if systems or information are compromised; and
- whether all eight strategies can reach the selected level together, rather than leaving a weak strategy behind.
ASD cautions that even Level Three will not stop actors willing and able to invest enough time, money and effort. A maturity target is a way to prioritise and measure risk reduction, not a promise of immunity.
Recommended Free Tools
Best Value
Is ASD replacing the Essential Eight?
On 15 June 2026, ASD announced consultation on a proposed “Essentials” series grounded in the Information Security Manual. ASD described the planned series as prioritised, threat-informed mitigations for contemporary technology environments, supported by practical tools and implementation guidance. It proposed that the evolution of current Essential Eight guidance form the first chapter, “Essentials for enterprise IT,” with further chapters to follow. ASD said existing Essential Eight users could expect strong alignment with their current controls and investments.
The consultation notice set 12 July 2026 as the consultation deadline. That notice establishes a proposal and consultation period; it does not itself confirm a final publication, a decision to replace the Essential Eight, or a migration timetable. An organisation should not treat the proposed chapter as a changed requirement unless ASD publishes further official guidance establishing its status and effective date.
What does the latest published adoption evidence show?
ASD’s 2026 The Commonwealth Cyber Security Posture in 2025 reports on surveyed entities, not every Australian organisation. It found that 22 per cent of entities achieved Level Two or higher across all eight strategies in 2025, compared with 15 per cent in 2024. The report also says 59 per cent of entities reported that legacy technology affected their ability to implement the Essential Eight in 2025, down from 71 per cent in 2024. It records no Essential Eight Maturity Model updates in 2024–25.
For FY 2024–25, ASD reported these entity rates at Level Two or higher by strategy:
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →| Strategy | Entities at Level Two or higher |
|---|---|
| Patch applications | 56% |
| Patch operating systems | 62% |
| Multi-factor authentication | 34% |
| Restrict administrative privileges | 46% |
| Application control | 48% |
| Restrict Microsoft Office macros | 81% |
| User application hardening | 49% |
| Regular backups | 67% |
These strategy-level figures are not interchangeable with the whole-of-eight result: an entity can be at Level Two or higher for an individual strategy without reaching that level across all eight.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

