The Australian Cyber Security Centre's Essential Eight is the baseline cyber security framework for Australian organisations. Mandatory for Commonwealth entities, increasingly required for government suppliers, and now a common expectation in enterprise supply chains. This checklist walks through all eight mitigations and what genuine compliance looks like at each maturity level.
The Essential Eight at a glance
- 1. Application control — only approved applications run on endpoints
- 2. Patch applications — all applications patched within defined timeframes
- 3. Configure Microsoft Office macro settings — macros restricted to signed and trusted sources
- 4. User application hardening — browsers and PDF readers hardened
- 5. Restrict admin privileges — admin accounts limited to those who need them
- 6. Patch operating systems — OS patched within defined timeframes
- 7. Multi-factor authentication — MFA on all remote access and privileged accounts
- 8. Regular backups — backups tested and stored offline or immutably
Maturity Level 1 checklist
ML1 addresses opportunistic attackers — automated bots and low-skill adversaries that compromise businesses through known vulnerabilities and poor hygiene.
- Application control on workstations (allow-listing or Microsoft WDAC)
- Applications patched within 30 days of release
- Office macros blocked by default — only signed macros permitted
- Web browsers set to block web ads and untrusted Java
- Admin privileges removed from standard user accounts
- OS patches applied within 30 days (2 weeks for internet-facing systems)
- MFA enabled for all remote access (VPN, RDP, cloud portals)
- Daily backups of critical data, with one copy offline
Maturity Level 2 checklist
ML2 addresses targeted attackers — adversaries who will invest time and technique to compromise a specific organisation.
- Application control covers servers as well as workstations
- Applications patched within 14 days (48 hours for critical vulnerabilities)
- Macros permitted only from trusted locations, not from the internet
- Browser extensions controlled and limited to an approved list
- Privileged access workstations (PAWs) used for admin tasks
- Internet-facing systems patched within 48 hours of critical release
- MFA on all accounts accessing sensitive data
- Backups tested quarterly; restoration procedures documented and tested
Common gaps in Australian businesses
- Admin privileges — most common ML1 gap; many Australian businesses still give staff local admin rights
- Application patching — third-party applications (Adobe, Chrome, 7-Zip) lag behind OS patching
- MFA — often deployed for Microsoft 365 but missed for VPN, RDP and third-party SaaS
- Backup testing — backups exist but restores have never been tested
- Application control — rarely implemented outside government and large enterprise
How to assess your Essential Eight maturity
An honest Essential Eight gap assessment starts with a technical review of your current environment — not a self-assessment questionnaire. A managed IT or security provider should be able to produce a written gap report that maps each control against the ACSC's maturity requirements and identifies specific remediation steps.
Ready to take the next step?
Talk to a senior Logical Systems engineer — no sales deck, no pressure.
Get a free Essential Eight gap assessment