Skip to content

Published 16 July 2026

Essential Eight maturity levels explained (0 to 3)

Someone has probably said the word "Level" to you recently — a broker asking what Essential Eight maturity level your business is at, an insurance renewal form, or a bigger customer's security questionnaire. If you've gone looking for what that actually means and come back more confused, you're not alone. Most explanations describe the maturity levels in the abstract. Here's what they mean in practice, and how to work out where your business actually sits.

Update, 18 July 2026: ASD has announced the Essential Eight will evolve into the new Essentials series over roughly two years. The maturity levels explained below come from the current model, which remains in force throughout the transition.

The four maturity levels, in plain English

Essential Eight maturity is scored on a scale of Level 0 to Level 3, applied separately to each of the eight controls (things like MFA, backups, and patching). For a broader introduction to the framework itself, see our Essential Eight compliance guide.

  • Level 0 — one or more of the basics for that control aren't in place. This doesn't always mean nothing has been done; it often means what exists is partial, inconsistent, or nobody can point to evidence of it.
  • Level 1 — partly aligned. Progress exists but coverage is incomplete — MFA is switched on for admins but not everyone, say, or backups run but nobody has ever tested a restore.
  • Level 2 — mostly aligned. The control is applied consistently and is starting to be monitored, not just switched on. This is the level most Australian small businesses are aiming for, and the one insurers and brokers most commonly reference.
  • Level 3 — fully aligned. Advanced measures aimed at more capable attackers — phishing-resistant MFA, tighter patch timeframes, logging of admin activity. Built for organisations facing sophisticated, targeted threats.

These definitions come from the ASD's Essential Eight Maturity Model, the same public framework behind the free self-assessment.

Levels are cumulative — you can't skip Level 1

The single most common misunderstanding: people assume Level 2 is just "a bit more" than Level 1, so they check the Level 2 criteria and stop there. In the ACSC model, reaching Level 2 for a control means all of that control's Level 1 criteria are met, plus everything specific to Level 2. Miss one Level 1 requirement and the control caps at Level 0, no matter how advanced your Level 2 or 3 measures look.

A concrete example: a business enables phishing-resistant MFA for its admin team (a Level 2/3-grade measure) but hasn't turned on MFA for everyday staff logins to email. Under the cumulative rule, that control still fails Level 1 — because the baseline requirement ("MFA is used for the organisation's online services") isn't fully met — regardless of how strong the admin-side MFA is.

Your overall score is your weakest control, not an average

The second surprise: your overall Essential Eight maturity is the lowest level across all eight controls that apply to you — not an average, and not "5 out of 8 at Level 2." This is deliberate. Attackers don't attack your strongest control; they look for the weakest door.

So a business with excellent backups (Level 3), solid MFA (Level 2), and tested patching (Level 2), but no restrictions on Microsoft Office macros (Level 0), has an overall maturity of Level 0 — even though six of the seven other applicable controls are strong. That's why the fastest way to lift your overall level is almost never to polish your best control further. It's to find and fix your weakest one.

What actually changes between levels

Reading "mostly aligned" doesn't tell you much on its own. Here's what the shift looks like for three controls SMBs ask about most:

ControlLevel 1 (partly aligned)Level 2 (mostly aligned)Level 3 (fully aligned)
Multi-factor authenticationMFA is used for online services holding sensitive data, using a factor the user has (e.g. a code or app)MFA extends to all privileged and unprivileged users, and successful/failed attempts are logged centrallyMFA is phishing-resistant (e.g. passkeys/hardware keys) and extends to data repositories
Regular backupsBackups run on a schedule matching business needs; ordinary user accounts can't modify or delete themPrivileged accounts (other than the backup admin) can't access other users' backupsEven the backup administrator account can't modify or delete backups during the retention period
Patch applicationsCritical vulnerabilities in internet-facing services patched within 48 hours; everyday apps within two weeksPatches for other applications applied within one monthEven office productivity apps and browsers get critical patches within 48 hours

This is a sample, not the full criteria — the ACSC model runs to around 150 detailed requirements across all eight controls. The point is the pattern: each level adds coverage (more of the organisation, more consistently) or speed/rigour (faster patch windows, stronger authentication factors), not an unrelated new requirement.

Which level should a small business target?

For most Australian SMBs, Level 2 is the sensible target — it's mostly aligned, achievable without enterprise-grade tooling, and it's the level insurers and brokers commonly reference when they ask about your security posture. Level 1 is a reasonable baseline if you're just starting out. Level 3 is generally overkill unless you handle unusually sensitive data or face a specific reason to expect a sophisticated attacker — it's built for that threat profile, not general SMB risk.

Two honest caveats: no maturity level guarantees insurance approval, a specific premium, or that you won't have an incident — insurers make their own underwriting decisions, and the Essential Eight reduces risk rather than eliminating it. Treat "Level 2" as a sensible target to document and work towards, not a pass/fail gate.

Find out your own level

Reading about the scale is one thing; knowing where your business actually sits is another. Our free Essential Eight self-assessment walks through plain-English questions for each control — the same ones covered in how to do an Essential Eight self-assessment — and calculates your indicative Level 0–3 per control and overall, in about 20 minutes. No account required to see your result. This is a self-assessment, not an audit or certification — it reflects your own answers, not independent verification.

FAQ

Is Level 0 illegal or non-compliant? No — the Essential Eight isn't a law for most private businesses. Level 0 simply means gaps exist that attackers commonly exploit. It's a risk signal, not a legal breach.

Do I need to reach Level 3? Not usually. Level 3 targets sophisticated, adaptive attackers and typically suits organisations with unusually sensitive data or specific threat exposure. Most SMBs aim for Level 2.

Can different controls sit at different levels? Yes — each of the eight controls is scored individually. Your overall figure is the lowest of the applicable ones, which is why closing your single weakest control usually moves your overall score more than improving an already-strong one.

How often should I re-check my level? At least annually, and ideally timed to your insurance renewal — controls drift as staff, software, and exceptions change over time, so last year's result may no longer reflect reality.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).