ESSENTIAL EIGHT · 24 AUGUST 2026 · 2 MIN READ
The Essential Eight, explained for Australian businesses
Eight mitigation strategies, three maturity levels, 152 requirements: what the ACSC actually asks, who is asking you for it, and how to evidence it without a spreadsheet.
The Essential Eight is the Australian Signals Directorate's baseline of eight mitigation strategies for Windows-based networks. It is not a certification (there is no ASD certificate), but it is the most-requested cyber benchmark in Australian procurement, and it is increasingly written into contracts with a maturity level attached.
The eight
- Patch applications: known vulnerabilities in internet-facing services and office software closed within defined windows (48 hours for exploited critical ones at higher levels).
- Patch operating systems: the same discipline for Windows, macOS, Linux and firmware.
- Multi-factor authentication: for remote access, privileged users, internet-facing services and, at higher levels, for everyone, using phishing-resistant methods.
- Restrict administrative privileges: separate admin accounts, no email or web from privileged accounts, regular revalidation.
- Application control: only approved executables, scripts and installers run.
- Restrict Microsoft Office macros: blocked from the internet, signed or trusted-location only, logged.
- User application hardening: browsers and productivity apps configured to remove the attack surface (no Java from the internet, no ads, PowerShell constrained).
- Regular backups: of data, applications and settings; tested restores; access to backups restricted.
Maturity levels
Each strategy is assessed at Maturity Level 0 to 3. ML1 defends against commodity, opportunistic attackers. ML2 against adversaries who invest some effort in a specific target, and it is the level most defence primes and government buyers name. ML3 targets adaptive, well-resourced adversaries.
The ACSC's maturity model breaks the eight strategies into around 150 specific requirements across the three levels. Assessing at the strategy level ("we do MFA") is not an assessment. Assessing at the requirement level ("phishing-resistant MFA is enforced for all privileged users; here is the export") is.
Who asks
Defence Industry Security Program (DISP) members and their supply chains. Commonwealth entities and their suppliers under the PSPF. State governments. Insurers, increasingly. And MSPs, on behalf of all of the above.
How to evidence it without losing your mind
The failure mode is a spreadsheet: eight rows, a colour, a date. It cannot be audited and it is out of date the week after it is finished.
On ISO Assist, the Essential Eight is modelled at the ACSC's own resolution, every requirement is a row with an owner, a status, linked evidence and an exceptions register for compensating controls. Maturity rolls up from the requirements; nobody declares a level. Evidence you already hold for ISO 27001 (access reviews, patch reports, backup restore tests) is credited where it satisfies an E8 requirement.