Essential 8··14 min read

The Essential 8 Maturity Model Explained (ML0 to ML3)

The Essential 8 Maturity Model is the ACSC's framework for scoring how well you've implemented the eight strategies. Here's how ML0 to ML3 works.

By Vikram Kukreja

TL;DR: The Essential 8 Maturity Model is the ACSC's scale for measuring how well an organisation has implemented the eight mitigation strategies, running from Maturity Level Zero to Maturity Level Three. Each level is cumulative and defends against a more capable adversary than the last, and your overall maturity level is always the lowest level achieved across all eight strategies.


What is the Essential 8 Maturity Model?

The Essential 8 Maturity Model is a scoring framework published by the Australian Cyber Security Centre (ACSC) that measures how well an organisation has implemented the eight mitigation strategies known as the Essential Eight. It is not the strategies themselves. It is the ruler used to measure how well you have applied them.

The model runs across four levels: Maturity Level Zero, One, Two, and Three. Each level corresponds to a category of adversary the controls are designed to resist, from opportunistic attackers at the lower levels through to sophisticated, well-resourced adversaries at Maturity Level Three. The ACSC's Essential Eight Maturity Model page is the authoritative published version.

A government contract or cyber insurance policy asking for "Essential 8 ML2" is referring to this model. It is the mechanism that turns eight abstract strategies into a specific, verifiable target.


Who publishes the Essential 8 Maturity Model?

The Australian Signals Directorate's Australian Cyber Security Centre owns and maintains the model. The ACSC originally published a longer list called the Strategies to Mitigate Cyber Security Incidents, then identified the eight strategies with the highest baseline effectiveness and packaged them as the Essential Eight, with the Maturity Model as the companion scoring system.

The ACSC updates the model periodically as attacker techniques change. A control that satisfied ML1 several years ago may no longer meet the current published criteria, which is why organisations preparing for procurement or audit should always check the live version on cyber.gov.au instead of relying on cached guidance.


The two dimensions of the model

The Essential 8 Maturity Model works across two axes at once, and confusing them is the most common mistake organisations make when first reading the ACSC guidance.

The first axis is the eight strategies themselves: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups.

The second axis is the maturity level, applied separately to each of those eight strategies. A 40-person Melbourne law firm might have MFA implemented at ML2 standard, patching at ML1, and backups not yet meeting ML1 restoration testing requirements. That firm's overall maturity level is ML0, because the model scores the organisation at its weakest strategy, not its average.


What Maturity Level Zero means

Maturity Level Zero is the starting point, not a fourth target level to aim for. The ACSC defines ML0 as having weaknesses in overall cyber security posture that, if exploited, could compromise the confidentiality, integrity, or availability of an organisation's data and systems.

Most organisations begin at ML0 by default, before any of the eight strategies have been deliberately implemented against the ACSC's specific criteria. Having antivirus software or a firewall in place does not move an organisation past ML0. The model only counts controls that meet its specific, published technical requirements.


How the levels build on each other

The four levels are cumulative, and this is the single most important structural fact about the model. Maturity Level Two includes every requirement of Maturity Level One. Maturity Level Three includes every requirement of both levels below it.

This means an organisation cannot claim ML2 for a strategy while skipping an ML1 requirement within that same strategy. For patch applications, ML1 requires patching internet-facing services within 48 hours of a critical vulnerability being disclosed. ML2 keeps that same 48-hour window and extends the patching requirement to a wider scope of software. You cannot meet ML2's wider scope while missing the ML1 timing requirement underneath it.

The same weakest-link rule applies across the eight strategies. If seven strategies are assessed at ML2 and one strategy is still at ML1, the ACSC records the organisation's overall maturity level as ML1. For a full breakdown of what changes at each level, see the Essential 8 maturity levels guide.


Why the model does not work like a certification

The Essential 8 Maturity Model is a measurement scale, not a certificate issued by a central authority. There is no single national body that stamps an organisation as "ML2 certified" the way a body might issue an ISO certificate.

Instead, an organisation self-assesses against the published criteria, or engages an independent assessor to test controls and confirm the level achieved. The result is a report stating the maturity level reached, which the organisation then presents to whoever is asking for it: a government procurement team, a prime contractor, or a cyber insurer.

This is why the assessment method matters as much as the result. A self-assessment run through an automated scanning platform is useful for tracking internal progress. A formal audit is what most contracts and insurance applications require. For a full explanation of that distinction, see the Essential 8 audit guide.


The Essential 8 Maturity Model vs SMB1001

The Essential 8 Maturity Model and SMB1001 are both Australian frameworks, but they measure different things. The Essential 8 model scores eight specific technical strategies across four levels, ML0 to ML3. SMB1001 is a broader standard purpose-built for small and medium businesses, with five tiers from Bronze to Diamond that layer governance and process controls, such as documented incident response and vendor risk management, on top of technical controls.

The technical overlap between the two frameworks is significant. An organisation that has reached Essential 8 ML1 has already satisfied a meaningful share of the technical controls SMB1001's Bronze and Silver tiers require. Many Australian SMBs pursue both frameworks together for that reason, instead of treating them as competing standards.


How organisations use the model in practice

A target maturity level usually comes from an external requirement, not internal preference. Australian Government contracts commonly specify ML2 as a condition of supply. Cyber insurers increasingly ask applicants to state their Essential 8 maturity level as part of underwriting. Managed service providers use the model as a shared vocabulary with clients who have no cyber security background.

A practical example: a 25-person accounting firm bidding for a state government contract is told the contract requires "Essential 8 Maturity Level One." That single phrase now defines exactly which of the eight strategies need work, and to what specific technical standard, because the model translates a vague requirement into eight measurable targets.

Once the target level is set, the standard approach is a gap assessment against each of the eight strategies, followed by remediation of whatever falls short, followed by a formal or self-assessment to confirm the level has been reached.


How CYBERWHITE maps your environment to the model

CYBERWHITE connects to your Microsoft 365 tenant and checks each of the eight strategies against the ACSC's current published criteria for ML1, ML2, and ML3. The platform reports where you sit on each strategy individually, then rolls that up into your overall maturity level using the same weakest-link rule the ACSC applies.

Where a gap exists, CYBERWHITE's AutoFix engine can deploy the underlying Microsoft 365 configuration directly, with your approval before anything changes in your tenant. See the Essential 8 compliance guide for a full walkthrough of the eight strategies, or run the free Essential 8 maturity assessment to see where your organisation currently sits on the model. For platform and pricing details, see features and pricing.


Essential 8 Maturity Model FAQ

What is the Essential 8 Maturity Model?

The Essential 8 Maturity Model is the scoring framework the Australian Cyber Security Centre uses to measure how well an organisation has implemented the eight mitigation strategies. It runs across four levels, Maturity Level Zero through Maturity Level Three, with each level defending against a more capable adversary than the one before it.


Who created the Essential 8 Maturity Model?

The Australian Signals Directorate's Australian Cyber Security Centre (ACSC) created and maintains the model. It sits alongside the broader Strategies to Mitigate Cyber Security Incidents, a longer list from which the eight highest-value strategies were selected to form the Essential Eight.


What is Maturity Level Zero (ML0)?

Maturity Level Zero means an organisation has weaknesses in its overall cyber security posture that, if exploited, could compromise the confidentiality, integrity, or availability of its data and systems. It is the starting point on the model, not a target level. Every organisation begins at ML0 before implementing any of the eight strategies to the ACSC's standard.


Are the Essential 8 maturity levels cumulative?

Yes. Maturity Level Two includes every requirement of Maturity Level One, and Maturity Level Three includes every requirement of both levels below it. You cannot skip a level or claim a higher level while a lower-level requirement remains unmet on any of the eight strategies.


Is reaching Maturity Level Three required for every organisation?

No. The ACSC designed the model so organisations select a target level based on the adversary tradecraft they are likely to face, not a universal requirement. Most Australian SMBs target ML1 or ML2. ML3 is generally reserved for organisations handling highly sensitive data or facing targeted attackers, and is the level federal government agencies typically require of key suppliers.


Does the Essential 8 Maturity Model apply to cloud environments?

Yes. The ACSC's guidance covers on-premises, cloud, and hybrid environments, and Microsoft has published mapping guidance for implementing each strategy within Microsoft 365 and Azure. Most Australian SMBs now implement the Essential 8 primarily through their Microsoft 365 tenant.


How is the Essential 8 Maturity Model different from a certification?

The model is a measurement scale, not a certificate issued by a central body. An organisation, or an assessor working with it, determines the maturity level achieved by testing each strategy against the ACSC's published criteria. There is no national registry of certified organisations, though contracts and insurers frequently require evidence of a specific assessed level.


How often does the ACSC update the Essential 8 Maturity Model?

The ACSC reviews and updates the model periodically as adversary tradecraft evolves, typically issuing revisions on cyber.gov.au instead of following a fixed annual schedule. Organisations working toward a specific level should check the current published version instead of relying on older guidance.


What is the difference between the Essential 8 Maturity Model and SMB1001?

The Essential 8 Maturity Model scores eight specific technical strategies across four levels. SMB1001 is a broader Australian standard built for small and medium businesses, with five tiers from Bronze to Diamond covering governance and process controls alongside technical ones. Many organisations pursue both, since the technical controls overlap significantly.


How does CYBERWHITE measure my Essential 8 maturity level?

CYBERWHITE connects to your Microsoft 365 tenant and checks each of the eight strategies against the ACSC's published criteria for ML1, ML2, and ML3. The platform reports your current level per strategy and your overall maturity level, which is always the lowest level achieved across all eight.

Ready to assess your compliance?

CYBERWHITE helps Australian businesses reach Essential 8 and SMB1001 audit-readiness faster. Start with our free 5-minute assessment.