Summary
I’ve come to think of the Essential Eight less as a checklist and more as a journey. What counted as mature a year or two ago doesn’t always hold up now, evidence matters as much as the controls themselves. Here’s what each maturity level actually asks of your business in 2026, why Level 1 has to come first, and what a real cyber security strategy looks like once you get past the self-assessment stage.
In This Article
- Why Was the Essential Eight Created for Businesses Like Mine?
- Which Eight Controls Do I Need to Know About?
- What Do the Essential 8 Maturity Levels Mean for My Business?
- What’s My Best Strategy for Reaching Cyber Security Maturity?
- What Are My Practical Next Steps Toward Essential Eight Maturity?
- The Bottom Line
Reflecting on how many conversations I have where someone tells me they’re “covered” under the Essential Eight, I keep coming back to one question. Covered, or just claiming it? The four maturity levels themselves haven’t changed, but what businesses are expected to show for meeting them has sharpened considerably.
I still think about cyber security the way I think about home security. Moving from one Essential Eight maturity level to the next was never just about adding another lock. It’s layering different kinds of protection, cameras, alarms, fences, so each one reinforces the last rather than standing alone.
That layered approach makes attackers work harder and limits the damage when something gets through. What’s changed is that businesses aren’t just judged on adding the layers anymore, they’re asked to prove those layers actually hold, and that’s worth sitting with before you assume you’re covered.
Why Was the Essential Eight Created for Businesses Like Mine?
The Australian Cyber Security Centre introduced the Essential Eight in February 2017, distilling a broader international framework into eight practical controls Australian businesses could act on.
The ACSC believed most cyber attacks could be prevented if businesses got the basics right, so it introduced the Essential Eight, evolved from an earlier document called Strategies to Mitigate Cyber Security Incidents. The framework drew on the NIST cyber security framework, which I think of as a vast library of cyber security knowledge.
Which Eight Controls Do I Need to Know About?
Each control sits under one of three goals, preventing attacks, limiting their impact, or aiding recovery, chosen from ACSC’s direct experience responding to real incidents.
The Essential Eight protects internet-connected Microsoft Windows systems, and every control maps to one of three goals, to prevent, limit, or recover.
The Essential Eight strategies are:
- Patching applications
- Patching operating systems
- Multi-factor authentication
- Restricting administrative privileges
- Application control
- Restricting Microsoft Office macros
- User application hardening
- Regular backups
These weren’t picked arbitrarily, ACSC drew on its own experience with threat intelligence and real incidents to land on this set from dozens of possible cyber security mitigation strategies. For deeper detail on each one, our cyber security services page goes further.
What Do the Essential 8 Maturity Levels Mean for My Business?
The four maturity levels run from Level 0, no real strategy, to Level 3, full alignment across all eight controls, but in 2026 what separates them isn’t only what you’ve implemented. It’s whether you can show it.
I’ve never seen the Essential Eight as something you tick off once and forget. It calls for a cyber security strategy that keeps improving, mostly because the goalposts keep moving with it.
| MATURITY LEVEL | WHAT YOUR SECURITY AND STRATEGY LOOK LIKE |
|---|---|
| Level 0 | Weaknesses across your security posture, with no real alignment to a mitigation strategy |
| Level 1 | Solid resilience against common, opportunistic attacks |
| Level 2 | Protection against more capable adversaries, backed by early detection and forensic follow-up |
| Level 3 | Full alignment across all eight controls, built for sophisticated, targeted threats |
A couple of years ago, describing your own maturity level was usually enough. Assessors and insurers now want documented proof, patch records, access review logs, monitoring outputs.
It’s sharpened in one specific way too. Businesses often sit comfortably at one maturity level overall while a single control, often application control or privilege management, lags well behind. That’s papering over the cracks rather than closing them, and it’s the exact gap assessors are trained to look for now.
Insurers are leaning more heavily on Essential Eight maturity, and your ability to prove it, when setting policy eligibility and premiums. Only government agencies or heavily regulated organisations genuinely need Level 3. But with government or enterprise clients, insurance requirements, or supply chain obligations, Level 2 is fast becoming the expected floor.
What’s My Best Strategy for Reaching Cyber Security Maturity?
Build every control to Level 1 before chasing higher levels anywhere else. One advanced control can’t make up for weak basics sitting underneath it.
When you’re building a house, you wouldn’t add a fancy roof over a shaky foundation. Push one control ahead while the others sit unfinished at Level 1, and what you’ve created is a gap, not an achievement.
Multi-factor authentication is a good example. Implement it well but skip regular patching, and hackers can still exploit those holes, MFA included. Authentication itself faces more scrutiny too, with passkeys and hardware-based MFA increasingly preferred over SMS or app codes in higher-risk sectors.
The path to take looks like this. At Level 1, you implement the core control, patching applications, enforcing strong passwords. At Level 2, you refine it, automating patching, running password audits. At Level 3, you go further again, vulnerability scanning, privileged access controls.
What Are My Practical Next Steps Toward Essential Eight Maturity?
Start with an honest, evidenced assessment of where you actually sit, then speak with a cyber security consultant if you’d like guidance tailored beyond ACSC’s general resources.
None of this needs to feel overwhelming. The ACSC website has useful resources and tools to start with. But for advice shaped around your business specifically, a cyber security consultant can help you work out what actually fits where you sit, not where you assume you do.
I’d think of an assessment the way I’d think of a proper building inspection. You want someone who gets under the floorboards, not someone who eyeballs the roofline from the street and calls it sound. That’s the distinction that matters most.
The Bottom Line
I’ve come to see cyber security less as a destination and more as an ongoing conversation between where you are and where you need to be. The Essential Eight hasn’t changed, but what it means to genuinely meet a level has moved on, and I think that’s a good thing. It asks more of businesses, but it protects more of what they’ve built too.
If you’re not sure where your business actually sits, my team can run a free human risk report, scanning your domain for compromised credentials and testing your people with a real phishing campaign. It’s a useful starting point either way.
