Cyber Security

What Is the Essential Eight? A Practical Compliance Guide for Australian SMBs

Cybercrime isn’t slowing down, and for Australian small and medium businesses, the question isn’t whether you’ll be targeted; it’s whether your defences will hold when you are. That’s exactly the gap the Essential Eight was built to close.

If you’ve been asked to demonstrate cyber maturity by a client, an insurer, or a government tender, chances are the ACSC Essential Eight is the benchmark they’re measuring you against. This guide breaks down what it is, how the maturity levels work, who actually has to comply, and how your business can start closing gaps today.

What Is the Essential Eight?

The Essential Eight is a set of eight prioritised cybersecurity mitigation strategies published by the Australian Cyber Security Centre (ACSC), which sits within the Australian Signals Directorate (ASD). Rather than trying to cover every possible cyber risk, the ASD Essential Eight narrows the focus to the controls that stop the most common and damaging attack techniques: ransomware, phishing, credential theft, and malicious code execution.

The essential eight framework was first published in 2017 and has been updated regularly since to keep pace with evolving threats. It was originally designed to protect internet-connected government networks, but it has since become the de facto baseline for private-sector organisations across Australia, including SMBs.

Importantly, the eight strategies are designed to work together. Implementing six or seven well and leaving one weak (say, strong patching but no multi-factor authentication) still leaves a door open for attackers. The framework only delivers its full protective value when all eight are addressed as a set.

A Note on What’s Changing

In June 2026, the ASD confirmed that the Essential Eight will eventually be retired and replaced by a broader framework called the “Essentials series,” starting with a chapter on enterprise IT.

However, the transition is deliberately slow: the Essential Eight remains the live, active standard today, with ASD indicating it won’t begin deprecating it for roughly 12 months, and won’t retire it fully for around 24.

The eight controls themselves are unchanged, and ASD has signalled that existing Essential Eight work will map across to the new framework rather than being wasted. For any SMB working on compliance now, the practical guidance is the same: keep building against the Essential Eight, because it’s still exactly what insurers, tenders, and clients are assessing you against.

The Eight Essential Eight Controls

The essential eight controls fall into three broad objectives: preventing malware delivery and execution, limiting the extent of incidents, and enabling data recovery. Here’s what each one covers.

  1. Application Control: Only approved, trusted applications are allowed to run on your systems, blocking unauthorised or malicious software before it can execute.
  2. Patch Applications: Vulnerabilities in software like browsers, PDF readers, and office suites are identified and fixed quickly, with extreme-risk flaws remediated within 48 hours at the higher maturity levels.
  3.  Configure Microsoft Office Macro Settings: Macros are a common vector for malware delivery. This control restricts macros to only those users who genuinely need them, and blocks macros sourced from the internet.
  4. User Application Hardening: Web browsers, Office applications, and PDF software are configured to reduce their attack surface, blocking risky features like Flash, ads, and untrusted Java code.
  5. Restrict Administrative Privileges: Admin access is limited to those who need it, regularly reviewed, and separated from everyday user accounts to stop attackers escalating access if they get in.
  6. Patch Operating Systems: Similar to application patching, but for operating systems and network devices, including retiring unsupported OS versions that no longer receive security updates.
  7. Multi-Factor Authentication: A second verification step (beyond just a password) is required for logins, especially for privileged accounts and remote access, making stolen credentials far less useful to attackers.
  8. Regular Backups: Important data, software, and configurations are backed up regularly, stored securely, tested for recoverability, and protected from being altered or deleted by an attacker.

The first seven strategies are about prevention: stopping attackers getting in or moving further once they’re inside. The eighth (backups) is your recovery safety net if something still gets through.

The Essential Eight Maturity Model: Levels 0 to 3

To help organisations measure and plan their implementation, the ACSC created the Essential Eight Maturity Model, which scores each of the eight strategies against four maturity levels (not three, as some guides suggest). Getting this right matters for accurate self-assessment.

  • Maturity Level Zero: There are weaknesses in an organisation’s overall security posture that an adversary could exploit. This isn’t a “starting” level to aim for; it means meaningful gaps exist across one or more of the eight strategies.
  • Maturity Level One: Controls are partly aligned with the intent of each strategy, offering some protection against opportunistic attackers using common, widely available tools and techniques.
  • Maturity Level Two: Controls are mostly aligned with the intent of each strategy, providing protection against more capable adversaries who are willing to invest additional time and effort to bypass basic defences.
  • Maturity Level Three: Controls are fully aligned with the intent of each strategy, providing protection against highly capable, well-resourced adversaries, though even Level Three won’t stop every determined attacker indefinitely.

Your target maturity level should be based on two things: how sensitive the data and systems you’re protecting are, and the sophistication of the attackers likely to target your business, not simply the highest number available.

Who Must Comply with the Essential Eight?

Compliance obligations differ significantly depending on the type of organisation.

  • Non-corporate Commonwealth entities (federal government departments and most Commonwealth agencies) are mandated under the Protective Security Policy Framework (Policy 10) to implement all eight strategies to at least Maturity Level Two, with Level Three directed for entities handling higher-sensitivity information.
  • Corporate Commonwealth entities and government business enterprises are encouraged, but not strictly bound, to meet the same standard.
  • State and territory government agencies typically operate under their own separate frameworks, though many reference the Essential Eight directly.
  • Private businesses, including SMBs, are not legally required to comply in most cases. In practice, though, “voluntary” carries real weight: cyber insurers, government procurement processes, and enterprise clients increasingly expect Essential Eight alignment as a baseline before they’ll do business with you.

For SMBs supplying government, handling sensitive client data, or seeking cyber insurance, treating essential eight compliance as a genuine business requirement, not an optional extra, is now standard practice.

Essential Eight Assessment and Audit

An essential eight assessment measures how well your current controls align with each of the eight strategies against your target maturity level. Assessments can be:

  • Self-assessed, using ACSC’s published guidance to review your own environment, or
  • Independently assessed, typically by an IRAP-assessed cybersecurity provider, which carries more weight for tenders, insurance, and regulatory reporting.

An assessor (or self-assessment) will look for evidence, not just intent: configuration records, patch deployment logs, MFA enrolment reports, and privileged access reviews, for example.

A common pitfall is inconsistent maturity across strategies: an organisation strong on backups but weak on admin privilege restriction is generally assessed at its lowest common level, not an average. For an essential eight assessment for SMEs, the practical starting point is usually Maturity Level One across all eight strategies, then progressing evenly rather than maxing out one or two controls while neglecting others.

Small Business Essential Eight Checklist

Use this essential eight checklist as a starting point for a Maturity Level One uplift:

  • Restrict which applications are allowed to run on business devices
  • Apply application patches promptly, prioritising known critical vulnerabilities
  • Disable Microsoft Office macros by default; only enable for users with a clear business need
  • Harden browsers and Office applications (disable risky plug-ins and content types)
  • Review admin accounts and remove unnecessary privileged access
  • Patch operating systems regularly and retire unsupported versions
  • Enable multi-factor authentication, starting with email, remote access, and admin accounts
  • Set up regular, tested, offline or immutable backups of critical data and systems

Working through this checklist methodically (rather than tackling one control in depth while ignoring the rest) is the fastest way to lift your overall maturity in a way that will hold up to assessment.

Why Continuous Uplift Matters

The Essential Eight isn’t a set-and-forget project. Threats evolve, new vulnerabilities are disclosed constantly, and attackers adapt their tactics faster than static defences can keep up. A business that reached Maturity Level One two years ago and hasn’t revisited its controls since is likely to have drifted below that level without realising it. New software introduces new attack surfaces, staff turnover changes who holds admin access, and unpatched systems accumulate risk daily.

Continuous uplift means regularly reassessing your posture against the Essential Eight, retesting backups, reviewing privileged access, and keeping pace with ACSC’s periodic updates to the framework. For SMBs, this doesn’t require an enterprise-sized security team; it requires a consistent cadence of review, supported by the right managed tools and expertise.

Ready to find out where your business stands? A structured Essential Eight assessment is the clearest way to see your current maturity level and build a practical roadmap for uplift. Contact us for assistance today.

Frequently Asked Questions

What is the Essential Eight in simple terms?

The Essential Eight is a set of eight cybersecurity controls published by the ACSC, within the ASD, designed to help organisations block common cyberattacks and recover quickly if one succeeds.

Is the Essential Eight mandatory for small businesses?

No. It’s mandatory for non-corporate Commonwealth entities under the PSPF, but voluntary for private businesses, though clients, insurers, and government tenders increasingly expect it.

How many maturity levels does the Essential Eight have?

Four: Maturity Level Zero, One, Two, and Three, with Level Three representing full alignment against highly capable adversaries.

What maturity level should an SMB target?

Most SMBs should start by targeting Maturity Level One consistently across all eight strategies before progressing further, based on their actual risk profile.

What are the eight Essential Eight controls?

Application control, patch applications, restrict Microsoft Office macros, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.

How is Essential Eight compliance assessed?

Through self-assessment against ACSC guidance, or independent assessment by a qualified cybersecurity provider, evaluated using documented evidence for each of the eight strategies.

Is the Essential Eight being replaced?

Not immediately. The ASD has announced a future transition to a broader “Essentials series,” but the Essential Eight remains the current, active standard, with full retirement expected roughly two years away.

More Blogs

Book your free consultation today.

Lay the foundations for smarter, safer IT.

MENU