The Essential Eight is eight mitigation strategies published by the Australian Signals Directorate, and almost every conversation about it is really a conversation about maturity levels. A buyer does not ask whether you have implemented the Essential Eight. They ask what level you are at, which is a different and much harder question to answer honestly.
The model is widely misread as a scale of effort — more work, higher number. It is not. It is a scale of adversary.
What the Maturity Model Actually Measures
Each of the eight strategies is rated from maturity level zero to maturity level three, and the levels are defined by the sophistication of the adversary the implementation would withstand. Level three does not mean you tried three times harder than level one. It means the implementation holds up against a materially more capable attacker.
That framing matters because it changes what "good enough" means. The question is not how much of the control you deployed. It is which adversaries your deployment would stop, and whether those are the adversaries you expect to meet.
It also means two organisations can deploy the same product and land on different levels, because the level depends on configuration depth, coverage across the fleet and whether the control is enforced or merely observed.
The Four Levels
Maturity Level Zero
Level zero is not a starting tier so much as a finding. It signifies weaknesses in the overall posture that, when exploited, could compromise the confidentiality of data, or the integrity or availability of systems and data.
Teams are routinely surprised to be rated zero on a strategy they consider handled. The usual cause is a control deployed but not enforced — application control running in audit mode, or multi-factor authentication available but not required.
Maturity Level One
Level one targets adversaries using widely available tradecraft to gain access to, and likely control of, systems. Think commodity tooling, publicly known exploits, and opportunistic targeting of whoever happens to be reachable and unpatched.
This is the level that stops the background noise of the internet. For many organisations it is a meaningful improvement over where they actually are, and it is achievable in weeks rather than quarters for most of the eight.
Maturity Level Two
Level two targets adversaries operating with a modest step up in capability. They are willing to invest more time in a target, and more effort in evading controls and in the effectiveness of their tools — including better use of stolen credentials and more selective targeting.
This is the level most commonly named in Australian government supply chain requirements, which makes it the practical target for vendors rather than an aspirational one.
Maturity Level Three
Level three targets adversaries who are more adaptive and much less reliant on public tooling. They exploit weaknesses in configuration and monitoring — the gaps left by controls that are present but imperfectly operated — and they pursue specific targets rather than opportunities.
Reaching level three across all eight is a substantial programme. It is justified by the sensitivity of what you hold rather than by a desire to top the scale.
Why the Eight Move Together
ASD's guidance is to implement all eight strategies to the same maturity level before advancing any of them. This is the rule most often broken, and breaking it wastes money.
The reason is straightforward: an adversary does not grade you. If multi-factor authentication is at level three and application control is at level zero, the path through application control is still open, and the extra investment in authentication bought very little. An assessment reflects this by reporting the weakest strategy prominently, because that is what determines the outcome.
Uneven maturity usually happens because the easy strategies move quickly. Patching and MFA have mature tooling and obvious owners. Application control does not, so it lags — and the overall posture lags with it, no matter how good the rest looks on a dashboard.
Want an honest read on where your eight actually sit?
Share your work email and we'll walk each of the eight against the maturity model and mark where the evidence supports the level you would like to claim.
Choosing a Target Level
Pick the level your buyers ask for, not the level that sounds impressive.
If you sell into Australian government supply chains, the requirement is usually stated explicitly in the tender or the contract, and that number is your target. If you are implementing for risk reasons rather than procurement reasons, level one across all eight is a defensible first destination and a far better posture than level three on three strategies and zero on two.
Two questions settle the choice in most cases. What do our buyers actually require, in writing? And what would we be able to evidence across the whole fleet, not just the managed subset?
Where Self-Assessments Usually Overstate
Four patterns account for most of the gap between a claimed level and an assessed one.
- Audit mode counted as enforcement. Application control deployed to observe and report, with enforcement deferred, is not implemented. This is the single most common overstatement.
- Coverage gaps outside the managed fleet. Contractor laptops, servers outside the standard build, and systems inherited through acquisition are in scope and usually unrated.
- Exceptions with no expiry. A permanent exception is not an exception; it is the configuration. A register full of them lowers the real level regardless of what the policy says.
- Backups that have never been restored. A successful backup job is not evidence of recoverability. Restoration testing is what the strategy asks for.
None of these are hard to find if you look for them deliberately. All of them are easy to miss if the assessment is a questionnaire filled in by the team that owns the control.
Essential Eight Maturity Questions Teams Ask
These are the Essential Eight maturity questions teams ask most often when they first see a rating that is lower than expected.
No. The levels are defined by the sophistication of the adversary an implementation would withstand, so the right target depends on who you expect to face and what your buyers require. Level three is a substantial programme justified by the sensitivity of what you hold. For most organisations the useful target is the level stated in their procurement requirements — commonly level two in Australian government supply chains — reached evenly across all eight rather than unevenly at a higher number.
In practice yes, and most organisations are. But ASD's guidance is to implement all eight to the same level before advancing any of them, and an assessment reports the weakest strategy because that is what determines the outcome. An adversary routes around your strongest control, so investment in a strategy that is already ahead of the others buys very little until the laggards catch up.
There is no certification body and no certificate. Organisations commonly perform a self-assessment, and ASD publishes an assessment process guide describing how to do it rigorously. Independent assessors are also used, particularly where a procurement requirement expects an external view. What a buyer receives is a stated maturity level per strategy with the evidence behind it, not a logo.
At least annually, and before any major procurement that will ask for a level. Maturity decays between assessments in ways that are easy to miss: fleets drift from their baselines, exceptions accumulate, software reaches end of life, and acquisitions bring unmanaged systems into scope. A level claimed from an assessment more than a year old is a claim about a configuration that has since changed.
Turn an Essential Eight assessment into evidence you can hand over
Book a demo and we'll show how Konfirmity tracks each of the eight against a target maturity level and keeps the evidence current between assessments.
Book a demo
Start From an Honest Baseline
An honest baseline beats an optimistic one, because the gap between claimed and assessed maturity surfaces at the worst possible moment — during procurement, or during an incident. Rate each of the eight against the model with evidence rather than recollection, and treat level zero findings as information rather than embarrassment.
Then move all eight together. The application control strategy will be the one that sets your pace, and planning around that reality produces a better outcome than planning around the strategies that move easily.

