The ASD Essential Eight is Australia’s baseline for practical cyber defence. We measure your maturity honestly, then lift it to the level your customers, insurers or Defence contracts require.
Maturity Level 1–3 / Microsoft 365 & endpoints / ASD-aligned
The Essential Eight is not law. It is mandatory for non-corporate Commonwealth entities under Commonwealth policy, and it reaches most businesses through a contract, a tender or an insurer’s question. The maturity level you need is set by whoever is asking — not by the framework itself.
Who is asking about the Essential Eight?
Have they named a maturity level?
How many of the eight have you actually implemented?
Careful — partial implementation may score Maturity Level Zero.
ASD is explicit that choosing not to implement an entire mitigation strategy where it is technically feasible is generally assessed as Maturity Level Zero — regardless of how mature the others are. Strong on six of eight is not ‘mostly Level 2’. It is Level Zero.
The Essential Eight is designed to be implemented and assessed as a package.
Probably lower than you think.
Maturity is assessed as a package: the same level across all eight before moving up. Peaks and troughs assess to the trough, and a strategy left out entirely can take the whole assessment to Level Zero.
Not an obligation yet — but it is good advice.
Nobody is requiring it of you today. The Essential Eight is still the most practical baseline available, and it is what most Australian buyers will ask about first when they eventually do ask.
Level 3 — and you should not start there.
ASD advises against assessing at Level 3 without having demonstrated Level 2 first, and Level 2 without Level 1. Skipping the ladder produces an assessment that will not hold.
Yes — and the level is set by whoever asked.
The framework does not choose your maturity level; the contract, tender or insurer does. If nobody has named one, that is itself worth clarifying before you spend, because the gap between Level 1 and Level 2 is substantial.
The Essential Eight are eight mitigation strategies from the Australian Signals Directorate that, implemented well, stop the majority of common cyber attacks. Maturity is measured from Level 0 to 3 — and increasingly, customers, cyber insurers and Defence buyers ask you to prove a specific level.
Measure your current maturity across all eight strategies — honestly, against the ASD model.
A practical, sequenced plan to reach your target level without breaking the business.
Apply the controls in Microsoft 365 and across endpoints — done properly, not just toggled on.
Capture the evidence that proves your maturity to customers, insurers and auditors.
Patching, configuration and review cadence so the maturity holds, not slips.
Book a call and we’ll scope an honest gap assessment and a realistic path to the maturity you need.