Update (June 2026): ASD has confirmed it will retire the Essential Eight within two years, replacing it with a broader, outcomes-based “Essentials” series. The Essential Eight remains the active framework today and your investment carries over. Read our full explainer on what’s changing and when.
The Essential Eight is the Australian Cyber Security Centre’s baseline set of strategies to protect organisations against common cyber threats. With more government and enterprise tenders specifying a target maturity level, here’s what the eight strategies are and how the maturity scale works.
What is the Essential Eight?
Developed by the Australian Cyber Security Centre (ACSC), the Essential Eight is a prioritised set of eight mitigation strategies that, implemented together, make it much harder for adversaries to compromise your systems. It is widely referenced across Australian government and is increasingly required in tenders and supplier assessments.
The eight strategies
- Application control
- Patch applications
- Configure Microsoft Office macro settings
- User application hardening
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
- Regular backups
Maturity levels 0 to 3
The ACSC defines maturity on a scale from Level 0 to Level 3. Level 0 indicates weaknesses in an organisation’s overall posture; Level 1 provides a baseline against common, opportunistic attacks; Level 2 addresses more capable adversaries; and Level 3 targets sophisticated, targeted threats. Your required level depends on your risk and what your customers or tenders specify.

Essential Eight vs ISO 27001
The Essential Eight is a focused set of technical controls; ISO 27001 is a complete information security management system. They complement each other: the Essential Eight strengthens key technical controls within the broader governance framework of ISO 27001.
How Streamline helps
Streamline assesses your current Essential Eight maturity, identifies the gaps and gives you a prioritised roadmap to your target level, aligning it with ISO 27001 where you have it, so your security investment does double duty.
Frequently asked questions
What Essential Eight maturity level do I need?
It depends on your risk profile and what your customers or tenders require: commonly Maturity Level 1 or 2 for general business, with higher levels for handling sensitive government data.
Is the Essential Eight mandatory?
It is mandatory for many Australian government entities and is increasingly required of their suppliers through tenders and contracts, even where it is not legally mandated for your organisation directly.
Related reading
- Essential Eight assessment & maturity uplift: what an assessment involves, what you get, and how long it takes.
- Essential Eight vs ISO 27001: which does your business need?
- ASD to retire the Essential Eight: what the new Essentials series means
Speak with an experienced ISO auditor
Need to meet an Essential Eight target for a tender? Email hello@streamline.business or call us:
- Brisbane 07 3667 8280
- Sydney 02 8315 7780
- Melbourne 03 9034 3990
Stay in the Loop
Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.
We handle your details in line with our privacy policy.











