Published 20 July 2026
Multi-factor authentication for Australian small business
You've told a broker, an insurer's renewal form, or a bigger customer's security questionnaire that your business "has MFA." Fair enough — someone set up an authenticator app at some point. But the question behind the question is usually more specific than that: MFA on what, for whom, and using which kind of factor? A yes/no answer can hide a setup that meets none of those specifics.
Update, 18 July 2026: ASD has announced the Essential Eight will evolve into a new Essentials series over roughly two years. The MFA criteria below come from the current model, which remains in force throughout the transition.
What multi-factor authentication actually is
Multi-factor authentication means signing in needs more than a password — typically something you have (a code from an app, a security key) or something you are (a fingerprint), on top of something you know. The point is simple: a stolen or guessed password on its own is no longer enough to get into an account. Since most break-ins start with compromised credentials, this is one of the cheapest, highest-impact controls a small business can put in place — no new hardware required for most setups, just turning on a feature most business software already includes.
What the Essential Eight expects, level by level
MFA is one of the Essential Eight's eight controls, and like the others it's scored at maturity Level 0 to Level 3. Here's what actually changes between levels, based on the ASD's Essential Eight Maturity Model — see the full MFA control page for the plain-English rundown of why each requirement matters:
Level 1 — partly aligned. MFA is used for the organisation's own online services that handle sensitive data, and for any third-party services (like a cloud accounting platform) that do the same. The factor itself can be something you have and something you know, or something you have that's unlocked by something you know or are — a reasonably broad definition that covers most authenticator apps and hardware tokens.
Level 2 — mostly aligned. Coverage widens and gets more rigorous. MFA now applies to both privileged users (admins) and unprivileged users (everyday staff) — not admins only. Successful and unsuccessful MFA attempts are logged centrally, so unusual sign-in activity is visible rather than invisible. And the method itself needs to be phishing-resistant — a meaningful step up from "any second factor will do."
Level 3 — fully aligned. The scope extends one step further, to data repositories themselves, not just the systems that sit in front of them.
The pattern across all three levels is the same one that runs through the whole framework: each level adds either broader coverage (more systems, more people) or greater rigour (a stronger, harder-to-phish factor) — never an unrelated new requirement.
Why insurers ask about this specifically
MFA is commonly the single most-asked-about control on an Australian cyber insurance application or renewal form, and often the one most likely to cause problems if the honest answer is no. That's not arbitrary. Insurers price risk based on what actually turns into claims, and stolen credentials remain one of the most common ways small businesses are compromised — an attacker doesn't need to breach a firewall if they can just log in with a password bought off a leak list.
That doesn't mean MFA guarantees anything. Insurers make their own underwriting decisions, weighing MFA alongside backups, patching, and admin-access controls together — and no single control is a promise of cover, a specific premium, or protection from every incident. What MFA reliably does is remove one of the easiest doors into your business, which is exactly why it comes up first.
How to check where your business actually stands
Reading the criteria is one thing; knowing whether your business meets them is another. It's common to discover a gap only once someone checks properly — MFA turned on for admins but not the rest of the team, or a factor type that technically works but wouldn't survive a determined phishing attempt.
Our free Essential Eight self-assessment walks through plain-English questions covering MFA and the other seven controls, and calculates an indicative Level 0–3 for each — including where your MFA setup specifically falls short of Level 1, 2, or 3. For the questions we ask and why, see the MFA control guide. It takes about 20 minutes, no account required to see your result. This is a self-assessment based on your own answers, not an independent audit or certification — but it's a genuinely faster way to find out than guessing, or waiting for a renewal questionnaire to ask.
FAQ
Is SMS-based MFA good enough for the Essential Eight? At Level 1, the Essential Eight accepts a broad range of factor types, and an SMS code can qualify as "something you have." At Level 2 and above, ACSC pushes towards phishing-resistant methods (like passkeys or hardware security keys), because SMS codes can be intercepted or socially engineered. If you're starting from nothing, SMS-based MFA is a legitimate first step — just don't treat it as the finish line.
Do all staff need MFA, or just admins? Level 1 requires MFA on the organisation's online services and any third-party services holding sensitive data — that's staff logins generally, not only admins. Level 2 explicitly separates privileged (admin) and unprivileged (everyday staff) users and expects MFA on both. Admin-only MFA, on its own, does not meet the baseline.
What is phishing-resistant MFA? It's an MFA method that can't be defeated by tricking a user into approving a fraudulent prompt or handing over a one-time code — think hardware security keys or passkeys, rather than SMS codes or basic push approvals. The Essential Eight expects it at Level 2 for authenticating users of systems.
Does Microsoft 365 or Google Workspace MFA count? Generally yes — both platforms offer built-in MFA (authenticator apps, security keys) that can meet the Essential Eight's factor-type requirements, provided it's actually turned on for the accounts and services that matter and not left optional.
Will MFA alone get my business cyber insurance? No single control guarantees cover — insurers make their own underwriting decisions and typically look at MFA alongside backups, patching, and admin access together. MFA is commonly the first question asked and the one most likely to cause a decline if missing, but it's one piece of the picture, not the whole application.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).