ISMS Copilot

Learn

Essential Eight maturity levels

What ML1, ML2, and ML3 actually require, who is expected to reach ML2, and why averaging the eight scores is how teams lie to themselves.

Last reviewed 2026-08-13. Vendor-neutral. Not an IRAP assessment and not a substitute for the ACSC text.

1. Treat Essential Eight as eight strategies, not a vibe called cyber hygiene

The Essential Eight is the Australian Signals Directorate / Australian Cyber Security Centre baseline of eight mitigation strategies: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. The November 2023 maturity model is the current public version this guide is aligned to. It is not ISO 27001, it is not a certificate, and it is not a synonym for “we take security seriously.” It is eight scored strategies.

2. Score the level you are at, not the level on the slide

ML0 is not a starting badge. It means the strategy does not yet meet ML1. ML1 addresses opportunistic adversaries. ML2 addresses adversaries who put in more time and tradecraft. ML3addresses adaptive adversaries. The ACSC is explicit that an organisation's overall maturity is the lowest of the eight strategy scores. Seven strategies at ML3 and backups at ML1 is ML1. Teams that publish an average are describing a slide, not the model.

3. Know who is actually expected to reach ML2

The Protective Security Policy Framework expects non-corporate Commonwealth entities to reach Essential Eight Maturity Level Two. That is a government obligation, not a marketing slogan. State agencies, defence primes, and critical-infrastructure operators often copy ML2 into supplier contracts. A private Australian SaaS company is not a Commonwealth entity. It still loses deals when the RFP says “demonstrate Essential Eight ML2.” Score against the published ML2 requirements for each strategy, not against a consultant's vibe of “pretty good for a startup.”

4. Do not confuse Essential Eight with ISO 27001 or with IRAP

ISO 27001 asks whether you run an information-security management system. Essential Eight asks whether eight specific mitigations meet a published maturity level. Overlap exists (patching, access, backups, malware). The artefacts do not. An ISO certificate does not prove ML2. An ML2 self-assessment does not prove clause 4 to 10. IRAP is a different thing again: an independent assessor evaluates a system against the ASD Information Security Manual. ISMS Copilot can draft IRAP-oriented documentation. It is not an IRAP assessor and it does not host the system being assessed.

5. Walk each strategy with evidence, then plan the upgrade one level at a time

For each strategy, write four things in your own words: the control you operate today, the evidence it produces (config export, patch report, MFA coverage, backup test), the owner, and the maturity level that evidence actually supports. Then raise the loweststrategies first. A programme that pushes MFA to ML3 while application control sits at ML0 has not moved the organisation's maturity. The model punishes theatre.

How this sits next to ISO 27001

QuestionEssential EightISO 27001
What is scoredEight technical strategies at ML0 to ML3A management system (clauses 4 to 10 plus Annex A)
Who asks for itAustralian government, primes, PSPF-aligned tendersExport customers, enterprise, certifying bodies
What you walk away withA maturity score and a strategy-by-strategy gap listA certificate from an accredited body, if you complete the audit

For the Australian product hub, see ISMS Copilot for Australia. For SaaS-shaped buying, see Australian SaaS companies. For the framework page, see Essential Eight Copilot.

Frequently asked questions

Is Essential Eight mandatory for every Australian company?

No. The ACSC recommends it as a baseline for all organisations. The PSPF obligation to reach ML2 applies to non-corporate Commonwealth entities. Private companies meet Essential Eight when a contract, a prime, or a board says they must. The model is still the right scoring language even when it is not a legal duty.

Can we claim ML2 if most strategies are at ML2 and one is at ML1?

No. The ACSC treats overall maturity as the lowest strategy score. One strategy at ML1 makes the organisation ML1. Fix the lagging strategy. Do not average.

Does ISO 27001 certification satisfy Essential Eight?

Not by itself. ISO 27001 demonstrates a management system. Essential Eight scores eight technical strategies. A mapped ISMS can produce both, but the assessor or buyer who asked for ML2 wants the eight-strategy evidence, not only the certificate. See /frameworks/essential-eight and /frameworks/iso-27001.

Is ISMS Copilot an IRAP assessor?

No. IRAP assessments are performed by ASD-endorsed IRAP assessors. ISMS Copilot drafts policies, control descriptions, and evidence lists. It does not issue an IRAP assessment and it must not host the system that holds IRAP-assessed data.

Which version of the maturity model is this guide using?

The ACSC Essential Eight Maturity Model update published November 2023, which is the public version still in force as of the last review date on this page. If ASD publishes a later model, this page should be refreshed against that text, not against secondary blogs.

Primary sources

  • Australian Cyber Security Centre, Essential Eight (strategies and intent). www.cyber.gov.au (checked 2026-08-13).
  • Australian Cyber Security Centre, Essential Eight Maturity Model (November 2023). www.cyber.gov.au (checked 2026-08-13).
  • Protective Security Policy Framework, Australian Government (Commonwealth entity obligations). www.protectivesecurity.gov.au (checked 2026-08-13).

Written and maintained by the ISMS Copilot team. Last reviewed 2026-08-13.

Essential Eight and the Information Security Manual are Commonwealth of Australia publications. This guide paraphrases in original wording and does not reproduce official control text. It is educational content, not an IRAP assessment, not legal advice, and not a certification.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.