Framework · Last verified

Essential Eight

The Essential Eight is an ASD mitigation-strategy set with four maturity levels (ML0-ML3); ML2 is a mandatory baseline for PSPF-covered federal entities. The ACSC names the eight strategies: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, regular backups.

Class
Framework
Owner
Australian Signals Directorate (ASD), via the Australian Cyber Security Centre (ACSC)
Last verified

What it is

The ACSC names the strategies verbatim: "The mitigation strategies that constitute the Essential Eight are: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, regular backups."

The Essential Eight is the most effective subset of a broader ASD list, "Strategies to mitigate cyber security incidents"; the maturity model was first published in June 2017 and is updated periodically (most recently November 2023, per the ACSC's own change log).

The ACSC defines four maturity levels: "four maturity levels have been defined (Maturity Level Zero through to Maturity Level Three) ... based on mitigating increasing levels of tradecraft."

Who owns it

The Essential Eight is developed by the Australian Signals Directorate and published through the Australian Cyber Security Centre.

Maturity levels

  • Maturity Level Zero
  • Maturity Level One
  • Maturity Level Two
  • Maturity Level Three

Who asks for it

Statutory (scoped). Verified mandatory status applies only to non-corporate Commonwealth entities subject to the Department of Home Affairs' Protective Security Policy Framework (PSPF) — not to Australian businesses or state-level bodies in general.

The ACSC's FAQ states the mandatory scope precisely: "For non-corporate Commonwealth entities subject to the Department of Home Affairs' Protective Security Policy Framework (PSPF), this means that while Maturity Level Two is considered a mandatory baseline, controls mapped to Maturity Level Three within the ISM are still applicable for their systems, however, their implementation may be risk managed."

The same page notes contractual pass-through is possible but gives no named scheme: "an organisation contractually required to implement Maturity Level Two from the E8MM should not assume that controls within the ISM that are mapped to Maturity Level Three are out of scope..."

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"Essential Eight." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/essential-eight

All frameworks & audits →