Framework · Last verified
Essential Eight
The Essential Eight is an ASD mitigation-strategy set with four maturity levels (ML0-ML3); ML2 is a mandatory baseline for PSPF-covered federal entities. The ACSC names the eight strategies: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, regular backups.
- Class
- Framework
- Owner
- Australian Signals Directorate (ASD), via the Australian Cyber Security Centre (ACSC)
- Last verified
What it is
The ACSC names the strategies verbatim: "The mitigation strategies that constitute the Essential Eight are: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, regular backups."
The Essential Eight is the most effective subset of a broader ASD list, "Strategies to mitigate cyber security incidents"; the maturity model was first published in June 2017 and is updated periodically (most recently November 2023, per the ACSC's own change log).
The ACSC defines four maturity levels: "four maturity levels have been defined (Maturity Level Zero through to Maturity Level Three) ... based on mitigating increasing levels of tradecraft."
Who owns it
The Essential Eight is developed by the Australian Signals Directorate and published through the Australian Cyber Security Centre.
Maturity levels
- Maturity Level Zero
- Maturity Level One
- Maturity Level Two
- Maturity Level Three
Who asks for it
Statutory (scoped). Verified mandatory status applies only to non-corporate Commonwealth entities subject to the Department of Home Affairs' Protective Security Policy Framework (PSPF) — not to Australian businesses or state-level bodies in general.
The ACSC's FAQ states the mandatory scope precisely: "For non-corporate Commonwealth entities subject to the Department of Home Affairs' Protective Security Policy Framework (PSPF), this means that while Maturity Level Two is considered a mandatory baseline, controls mapped to Maturity Level Three within the ISM are still applicable for their systems, however, their implementation may be risk managed."
The same page notes contractual pass-through is possible but gives no named scheme: "an organisation contractually required to implement Maturity Level Two from the E8MM should not assume that controls within the ISM that are mapped to Maturity Level Three are out of scope..."
Sources
- Australian Cyber Security Centre (ACSC) — Essential Eight Maturity Model ↗ — accessed
- ACSC — Essential Eight Maturity Model FAQ ↗ — accessed
- ACSC — Essential Eight (explained) ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.