Essential Eight Compliance
Helping Australian businesses implement the ASD Essential Eight — and navigate the transition to the new Essentials series
What Is the Essential Eight?
The Essential Eight is a set of eight cybersecurity mitigation strategies developed by the Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC). First published in 2017, it identifies the most common methods attackers use to compromise Australian organizations and provides practical, prioritized controls to defend against them.
The eight strategies are grouped across three objectives: preventing attacks (application control, patching applications, configuring Office macro settings, and user application hardening), limiting the impact of attacks (restricting administrative privileges, patching operating systems, and multi-factor authentication), and recovering data (regular backups).
For many Australian businesses, the Essential Eight is no longer optional. It is mandatory for organisations engaging with Commonwealth agencies. It is required at Maturity Level 2 for Defence Industry Security Program (DISP) membership. And it is increasingly expected by cyber insurers, enterprise customers, and regulators as the baseline standard for cybersecurity in Australia.
At Intro Labs, we help businesses understand where they stand, close the gaps, and achieve a demonstrable Essential Eight maturity posture — backed by independent audit.
The Eight Controls
1. Application Control
Only approved software can run on your devices. Unapproved executables, scripts, and installers are blocked — stopping ransomware and malware from executing even after it lands on a machine.
2. Patch Applications
Close known vulnerabilities in software before attackers can exploit them. Critical vulnerabilities must be patched within 48 hours. All other internet-facing application patches applied within two weeks.
3. Configure Microsoft Office Macro Settings
Block malicious macros embedded in Office documents — one of the most common malware delivery methods targeting Australian businesses. Macros from the internet are blocked, and only users with a documented business need are permitted to use them.
4. User Application Hardening
Disable unnecessary features in web browsers, PDF viewers, and Office applications that attackers commonly exploit. This includes blocking Java from the internet, removing Flash, disabling web advertisements, and ensuring Internet Explorer 11 is removed.
5. Restrict Administrative Privileges
Limit the damage a compromised account can do. Admin accounts are used only for admin tasks — not for email or web browsing. Separate accounts are used for privileged and day-to-day work, and privileged access is validated before being granted.
6. Patch Operating Systems
Keep Windows and other operating systems current so known vulnerabilities cannot be exploited. Critical OS patches must be applied within 48 hours. Unsupported operating systems must be removed from the environment.
7. Multi-Factor Authentication (MFA)
A stolen password alone is not enough to access your accounts or systems. MFA is required for all users accessing internet-facing services, cloud systems, and all administrative access. At Maturity Level 2 and above, phishing-resistant MFA (passkeys, FIDO2 hardware keys) is required.
8. Regular Backups
Your data can be recovered after a ransomware attack, accidental deletion, or hardware failure. Backups must be performed daily, retained for at least three months, stored separately from production systems, and — critically — tested to confirm they actually work.
Maturity Levels
The Essential Eight uses four maturity levels (0 to 3). Your overall maturity is determined by your lowest-scoring control — partial implementation does not count. If seven controls are at Level 2 but one is at Level 0, your overall maturity is Level 0.
Level 0 — Not Aligned
ASD definition: Minimally aligned with the intent of the mitigation strategy.
Controls are absent or unreliable. The organisation is vulnerable to common, low-effort attacks. Most small businesses that have not formally addressed cybersecurity sit at Level 0 without realising it.
Level 1 — Partly Aligned
ASD definition: Partly aligned with the intent of the mitigation strategy.
Defends against opportunistic attackers using commodity tools and techniques. This is the recommended starting point for small to medium businesses and provides a solid baseline against the most common cyber threats facing Australian organisations.
Level 2 — Mostly Aligned
ASD definition: Mostly aligned with the intent of the mitigation strategy.
Defends against more capable adversaries willing to invest time targeting your specific organisation. Required for Defence Industry Security Program (DISP) membership, expected by most government procurement, and increasingly the standard cyber insurers measure against. Patch deadlines tighten to two weeks for all patches, phishing-resistant MFA is required for admin accounts, application control extends to servers, and backup restoration must be tested quarterly. Since January 2026, ML2 has been formalised as the recommended baseline for all Australian industries under the 2023–2030 Cyber Security Strategy.
Level 3 — Fully Aligned
ASD definition: Fully aligned with the intent of the mitigation strategy.
Defends against highly targeted, adaptive attackers using sophisticated tools and techniques. Applicable to critical infrastructure, defence contractors handling classified material, and high-threat environments.
How We Help
At Intro Labs, we deliver Essential Eight implementation as a structured, phased program — not a one-off checklist.
-
We conduct a detailed discovery of your current environment — Microsoft 365 tenant, Intune configuration, device compliance, backup coverage, and administrative privilege structure. We assess your current posture against every Essential Eight control and identify exactly where the gaps are.
-
We close the gaps. This includes deploying application control policies via Windows Defender Application Control (WDAC) or AppLocker, configuring macro restrictions through Intune, enforcing patch compliance with automated deadlines, hardening browsers and applications, reducing administrative privileges to least-privilege, validating MFA coverage and registration, and configuring enterprise-grade backups with Veeam — with documented test restores to prove recoverability.
-
We conduct an internal self-assessment across all eight controls, prepare a complete evidence package (policy configurations, Intune compliance reports, update logs, backup restoration records), and remediate any remaining gaps. We then coordinate an independent auditor to conduct the formal Essential Eight assessment and issue a sign-off letter confirming your maturity level.
-
Once your initial maturity level is achieved and audited, we work with you on the roadmap to the next level. For most businesses, the progression is ML1 to ML2 over 6 to 12 months. We also provide ongoing monitoring and maintenance to ensure your controls do not degrade over time — because the Essential Eight is an operational discipline, not a one-time project.
Why It Matters Now
-
Underwriters now require proof of Essential Eight maturity before issuing or renewing policies. Businesses without demonstrable ML1 alignment are facing higher premiums, policy exclusions, or outright refusal of cover.
-
The majority of government tenders now reference Essential Eight compliance, typically requiring Maturity Level 2 or higher.
-
Your clients are increasingly asking about your security posture during due diligence. If you handle their data, they want to know it is protected. The Essential Eight gives you a clear, recognised framework to demonstrate that.
-
Since November 2025, the full Essential Eight at Maturity Level 2 is mandatory for all Defence Industry Security Program (DISP) membership levels, including Entry Level. Achieving ML1 first is the recommended building block — it is not possible to jump directly to ML2 from a Level 0 baseline.
What’s Changing — The Essentials Series
On 24 June 2026, the Australian Signals Directorate confirmed that the Essential Eight will be retired over the next two years and replaced by a new framework called the Essentials series.
The transition is staged and deliberate. The Essential Eight remains the current, active standard today. Both frameworks will run side by side for approximately 12 months, after which ASD expects to begin deprecating the Essential Eight around mid-2027, with full retirement around mid-2028.
What is the Essentials series?
The Essentials series moves away from a single eight-control checklist and instead provides domain-specific cybersecurity guidance. The first chapter, Essentials for Enterprise IT, covers the same ground as the Essential Eight but takes a broader, outcomes-based approach grounded in ASD’s Information Security Manual (ISM). Future chapters will cover operational technology (OT), cloud environments, and agentic AI — reflecting the reality that modern IT environments extend well beyond traditional on-premises Windows networks.
The key shift is from prescriptive technical controls to principles-based guidance that allows organisations to apply the right controls for their specific technology environment, while still achieving the same security outcomes.
What does this mean for your business?
First, your existing Essential Eight work is not wasted. ASD has been explicit that the controls and investment you have made under the Essential Eight remain relevant under the Essentials series and will map directly into the new framework. Organisations that have achieved ML1 or ML2 are ahead of the curve for the transition — not starting over.
Second, the Essential Eight is still what you are measured against today. Insurers, government tenders, DISP assessments, and independent auditors are all still assessing against the Essential Eight right now, and will continue to do so throughout the transition period.
Third, the underlying security controls are not going away. Patching, MFA, application control, privilege restriction, and tested backups do not stop working because the framework gets a new name. What changes is how they are documented, assessed, and applied to modern environments.
At Intro Labs, we are tracking the Essentials series transition closely and will guide our clients through the changeover as the new framework is finalised. In the meantime, we continue to implement and maintain the Essential Eight — because it remains the right foundation to build on.
Not sure where your business stands?
Most Australian businesses are at Level 0 without realising it. Whether you are starting your Essential Eight journey or preparing for the transition to the Essentials series, let’s start with a conversation about your current setup and what it would take to get you to where you need to be.