AgenorIT
AgenorIT
Cybersecurity & Governance•12 min read

Essential Eight Maturity Levels Explained: From ML0 to ML3

GS
Gurinder Singh
Principal Cloud & Software Architect
Published: 2026-09-26
Last Reviewed: 2026-09-26
Understand ACSC Essential Eight maturity levels from ML0 to ML3. Practical implementation requirements, weakest-link doctrine, and compliance audit evidence.

The Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC) maintain the Essential Eight as a prioritised set of technical mitigation strategies designed to protect Microsoft Windows-based networks against internet-borne cyber threats. According to the ACSC Essential Eight Maturity Model (updated November 2023, retrieved 26 September 2026), the framework outlines four distinct maturity levels—ranging from Maturity Level 0 through to Maturity Level 3.

Achieving meaningful compliance requires navigating the technical distinctions between each maturity tier, understanding how the weakest-link doctrine governs overall ratings, and producing verifiable engineering evidence that satisfies government panels, corporate procurement boards, and cyber insurance underwriters.

Key Takeaways

  • Prescriptive Technical Focus: The Essential Eight is an operational baseline focusing on endpoints, application execution, and identity, rather than an administrative policy framework.
  • The Weakest-Link Doctrine: Overall organisational maturity is defined by the single lowest maturity level achieved across all eight strategies. A single ML0 control caps the entire enterprise at ML0.
  • November 2023 ACSC Update: Current guidance mandates phishing-resistant multi-factor authentication (MFA) and tighter patching windows across applications and operating systems.
  • Evidence Over Assertions: Compliance requires concrete technical artefacts—such as App Control for Business XML exports, tenant sign-in logs, and signed restore logs—rather than policy spreadsheets.
  • Interactive Self-Assessment: Organisations can benchmark their baseline in under four minutes using the free Essential Eight Assessment Tool or engage Gurinder Singh and vetted specialists for Essential Eight Consulting.

What is the ACSC Essential Eight?

Developed by the Australian Signals Directorate, the Essential Eight represents the most effective technical mitigations organisations can deploy to protect against adversary tradecraft. The eight strategies are categorised into three primary defence objectives:

  1. Mitigations to Prevent Malware Delivery and Execution:
    • Application Control
    • Patch Applications
    • Configure Microsoft Office Macro Settings
    • User Application Hardening
  2. Mitigations to Limit the Extent of Cyber Security Incidents:
    • Restrict Administrative Privileges
    • Patch Operating Systems
    • Multi-Factor Authentication
  3. Mitigations to Recover Data and Restore System Availability:
    • Regular Backups

While non-corporate Commonwealth entities are mandated under the Protective Security Policy Framework (PSPF) to implement Maturity Level 2, commercial businesses across Australia increasingly adopt the framework to mitigate ransomware, satisfy enterprise supply chain contracts, and qualify for cyber liability insurance cover. For primary reference documentation and technical implementation details, refer to the ACSC Essential Eight Overview (retrieved 26 September 2026).


The Four Maturity Levels Defined

The ACSC defines four distinct tiers within the maturity model. Rather than representing arbitrary milestone percentages, each tier is directly mapped to adversary tradecraft, targeting sophistication, and attacker tooling.

+-------------------------------------------------------------------------+
| Level 0: Weaknesses Exist      --> High susceptibility to opportunistic attacks
| Level 1: Basic Tradecraft      --> Commodity tools & publicly available exploits
| Level 2: Targeted Exploitation --> Moderate tradecraft & credential harvesting
| Level 3: Advanced Adversaries  --> Advanced persistent threats & zero-days
+-------------------------------------------------------------------------+

Maturity Level 0 (ML0): Weaknesses in Posture

Maturity Level 0 does not imply a total absence of security measures; rather, it indicates that one or more fatal weaknesses exist across the baseline. If an organisation satisfies seven of the eight mitigation strategies at Maturity Level 2, but leaves legacy email authentication enabled without multi-factor verification, attackers can exploit that single pathway to bypass perimeter defences. Under ASD doctrine, an enterprise in this state is classified as Maturity Level 0.

Maturity Level 1 (ML1): Defending Against Commodity Attacks

Maturity Level 1 aims to mitigate opportunistically targeted attacks. Threat actors at this level do not invest significant resources in finding bespoke flaws in your specific environment; instead, they run automated scanners to identify unpatched public software, distribute malicious macro-enabled documents, or spray common passwords.

  • Targeted Adversary: Script kiddies, automated botnets, and opportunistic cybercriminals.
  • Focus: Basic application execution whitelisting, daily patching of exploited vulnerabilities, disabling macros from the internet, and MFA for non-console administrative logins.

Maturity Level 2 (ML2): Defending Against Moderately Sophisticated Attacks

Maturity Level 2 defends against adversaries who deliberately target your organisation. These threat actors demonstrate greater technical capability, invest time tailoring phishing campaigns, attempt credential harvesting, and actively probe for administrative misconfigurations.

  • Targeted Adversary: Organized cybercrime syndicates and commercial ransomware gangs.
  • Focus: Restricting execution to approved file paths and digital signatures, 48-hour patch SLAs for critical CVEs, blocking macros unless certified, privileged access workstations, and mandatory MFA across all user logins to online business applications.

Maturity Level 3 (ML3): Defending Against Advanced Persistent Threats

Maturity Level 3 is designed to withstand advanced adversaries, including state-sponsored groups and highly capable cyber extortionists. Threat actors at this level identify zero-day vulnerabilities, develop customized in-memory malware, and exploit obscure operating system interactions.

  • Targeted Adversary: Nation-state actors and elite advanced persistent threat (APT) groups.
  • Focus: Cryptographically validated application control (blocking unsigned DLLs and scripts), immediate patching of zero-days, automated logging of blocked macro executions, ephemeral administrative credentials (Just-In-Time access), hardware-backed phishing-resistant MFA (FIDO2 keys), and air-gapped immutable backup repositories.

Strategy-by-Strategy Requirements Matrix

The following comparison table synthesises the technical requirements across all eight mitigation strategies and compares the criteria across Maturity Levels 1, 2, and 3 based on the ASD November 2023 framework release:

Mitigation StrategyMaturity Level 1 (ML1)Maturity Level 2 (ML2)Maturity Level 3 (ML3)
1. Application ControlApplied to workstations. Restricts execution of executables (.exe) in standard user profiles (AppData).Applied to workstations and servers. Enforces execution rules for executables, software libraries (.dll), scripts (.ps1, .bat, .vbs), and installers (.msi).Enforced across all endpoints and servers using cryptographic publisher certificates or file hash validation. Logging and auditing of all blocked execution events.
2. Patch ApplicationsSecurity vulnerabilities patched or mitigated within one month. Critical CVEs with working exploits patched within 48 hours.Vulnerabilities with working exploits patched within 48 hours. Online scanning used at least fortnightly to verify software currency.Vulnerabilities with working exploits patched within 48 hours. Vulnerability scanner run at least weekly. End-of-life software immediately removed.
3. Configure Office MacrosMicrosoft Office macros blocked from running in files downloaded from the internet. Antivirus scan enabled for macros.Only macros signed by trusted certificates or stored in trusted server locations are permitted to execute.Standard users cannot enable macros. Macro execution blocked entirely unless specifically approved in an isolated, monitored environment.
4. User Application HardeningWeb browsers configured to block Java and Adobe Flash runtimes. In-browser advertisement blocking deployed where practical.Web browsers block untrusted browser extensions. PDF and Office applications prevented from spawning child command-line processes.Microsoft Defender Attack Surface Reduction (ASR) rules enforced. Internet access blocked for software that has no business requirement to communicate externally.
5. Restrict Admin PrivilegesRequests for elevated administrative privileges are validated with business justification. Standard accounts do not have local admin rights.Privileged accounts are prevented from accessing internet email, web browsing, and external file sharing services.Dedicated Privileged Access Workstations (PAWs) used for administrative tasks. Privileged identity accounts use time-limited Just-In-Time (JIT) activation.
6. Patch Operating SystemsOS patches applied within one month of vendor release. Critical vulnerabilities with known exploits patched within 48 hours.OS patches for critical vulnerabilities applied within 48 hours. Latest OS build/version maintained across all fleet devices.Operating system patch compliance scanned at least weekly. Unsupported legacy OS versions retired or completely network-isolated.
7. Multi-Factor AuthenticationMFA enforced for all remote access (VPN, RDP) and cloud services that process sensitive organisational data.MFA enforced for all users accessing any online customer, staff, or business portal, including email and internal web applications.Phishing-resistant MFA (e.g. FIDO2 hardware security keys or Windows Hello for Business) enforced for all logins and administrative operations.
8. Regular BackupsBackups of critical data, software, and configuration settings performed at least weekly. Restoration tested at least annually.Backups performed at least daily. Backups stored with immutability or isolated offsite. Restoration tested at least every six months.Backup access strictly limited to dedicated backup administrators. Unalterable, air-gapped immutable storage. Restoration tested at least quarterly.

How Essential Eight Assessment Works: The Weakest-Link Principle

A foundational aspect of the ASD Essential Eight is its non-compensatory scoring methodology. Unlike enterprise frameworks that compute a percentage score (such as CIS Controls or NIST CSF scoring), the Essential Eight requires that all eight strategies achieve a target maturity level before the organisation can claim that overall rating.

+-----------------------------------------------------------------------------------+
|  Strategy 1: Application Control        [ ML2 ]                                    |
|  Strategy 2: Patch Applications         [ ML2 ]                                    |
|  Strategy 3: Configure Macros           [ ML2 ]                                    |
|  Strategy 4: User App Hardening         [ ML2 ]                                    |
|  Strategy 5: Restrict Admin Privileges  [ ML2 ]                                    |
|  Strategy 6: Patch Operating Systems    [ ML2 ]                                    |
|  Strategy 7: Multi-Factor Auth (MFA)    [ ML0 ]  <-- WEAKEST LINK IDENTIFIED       |
|  Strategy 8: Regular Backups            [ ML2 ]                                    |
+-----------------------------------------------------------------------------------+
|  OVERALL ASSESSED MATURITY RATING:      [ ML0 ]                                    |
+-----------------------------------------------------------------------------------+

Why Does the ACSC Enforce Weakest-Link Scoring?

In practical penetration testing and real-world breach response, threat actors follow the path of least resistance. Consider the following attack scenario:

  • A financial advisory firm implements automated Windows patching within 24 hours (ML2).
  • They deploy App Control for Business on all laptops (ML2).
  • They maintain daily immutable cloud backups with Microsoft 365 backup locks (ML2).
  • However, standard email mailboxes use single-factor passwords without mandatory number-matching MFA (ML0).

An adversary executes a simple credential stuffing attack using a password leaked from an unrelated third-party breach. Gaining access to an unauthenticated mailbox, the adversary executes payment redirection fraud, accesses confidential client correspondence, and establishes an internal forwarding rule. The firm's high maturity in application control and backups provided zero defence against the identity compromise.

For this reason, the ACSC insists that a business is only as secure as its single most vulnerable control. Before investing heavily in advancing one strategy to Level 3, organisations must systematically eliminate all Level 0 and Level 1 gaps across the fleet. You can check your current weakest links using our free Essential Eight Assessment.


What Does "Implemented" Mean in an Audit?

One of the most frequent misconceptions encountered during Essential Eight audits is confusing written policy documentation with operational technical control. Under ACSC audit guidelines, an auditor cannot accept an employee handbook, security policy document, or verbal statement as evidence.

Every control must be backed by reproducible technical artefacts:

1. Application Control Evidence

  • Acceptable Evidence: Active App Control for Business (WDAC) policy XML files exported from Microsoft Intune, showing enforcing mode (Enabled:UMCI), alongside Microsoft Defender for Endpoint Advanced Hunting telemetry logs proving that unauthorized .exe, .dll, and script interpreters were successfully blocked.
  • Unacceptable Evidence: A corporate policy stating "Employees must only run approved business applications."

2. Patching SLA Evidence

  • Acceptable Evidence: Automated vulnerability reports from Microsoft Defender Vulnerability Management or Tenable, showing endpoint patch installation dates cross-referenced against the National Vulnerability Database (NVD) CVE release timestamps.
  • Unacceptable Evidence: A screenshot showing Windows Update turned on with default settings.

3. Privileged Access Evidence

  • Acceptable Evidence: Microsoft Entra Privileged Identity Management (PIM) audit export logs demonstrating zero standing Global Administrator accounts, with time-bound Just-In-Time role activations requiring ticket numbers and multi-factor approval.
  • Unacceptable Evidence: An Excel spreadsheet listing named administrators.

4. Backup Immutability Evidence

  • Acceptable Evidence: Cryptographic Azure Backup vault configuration exports verifying that Immutable Vault Lock is active with multi-user authorization (MUA), accompanied by a signed disaster recovery restoration test certificate executed within the past six months.
  • Unacceptable Evidence: An invoice from an external cloud storage provider.

Practical Roadmap: Achieving Maturity Level 2

For Australian mid-market organisations with 20 to 500 endpoints, Maturity Level 2 represents the recommended baseline posture. It provides comprehensive resistance against commercial ransomware syndicates without requiring the specialized air-gapping hardware of Maturity Level 3.

Phase 1: Discovery (Weeks 1-2)
  ├── Run automated tenant security scan
  ├── Audit local admin rights across endpoints
  └── Identify all ML0 weakest-link bottlenecks

Phase 2: Identity & Access Foundation (Weeks 3-4)
  ├── Enforce Entra Conditional Access with phishing-resistant MFA
  ├── Revoke standard user local administrator rights
  └── Deploy Windows LAPS for local endpoint management

Phase 3: Endpoint Hardening & App Control (Weeks 5-8)
  ├── Deploy Microsoft Defender ASR rules
  ├── Roll out Intune App Control for Business in Audit Mode
  └── Block untrusted Microsoft Office macros via Administrative Templates

Phase 4: Patching & Backup Governance (Weeks 9-10)
  ├── Configure Windows Update for Business deployment rings (48hr critical SLA)
  ├── Deploy automated third-party application patch automation
  └── Enable Immutable Vault Locks on cloud backups and execute a live restore test

Organisations that systematically follow this staged approach achieve verified compliance quickly, without disrupting daily staff workflows or generating excessive helpdesk tickets.


Conclusion & Next Steps

The ACSC Essential Eight is not a bureaucratic checklist—it is an engineering blueprint designed to protect Australian enterprises against the specific tactics modern threat actors deploy. By focusing on weakest-link vulnerabilities, leveraging your existing Microsoft 365 licensing, and producing verifiable configuration evidence, your organization can achieve robust, audit-ready compliance.

To evaluate where your organisation stands today:

GS

Written by Gurinder Singh

Author

Principal Cloud & Software Architect at AgenorIT. Specialising in Microsoft Azure Landing Zones, Microsoft Entra identity architectures, Microsoft Fabric lakehouses, and high-performance digital products for Australian organisations.

Direct Technical Consultation

Need Senior Architecture Guidance on Your Platform?

Speak directly with an experienced engineer about cloud infrastructure, data pipelines, or software development.

Senior Azure architect & vetted specialistsStrict confidentialityDirect technical scoping