Skip to main content

Cyber Security

Essential Eight Compliance Checklist for Australian Businesses (2026)

Logical Systems··10 min read

The Australian Cyber Security Centre's Essential Eight is the baseline cyber security framework for Australian organisations. Mandatory for Commonwealth entities, increasingly required for government suppliers, and now a common expectation in enterprise supply chains. This checklist walks through all eight mitigations and what genuine compliance looks like at each maturity level.

The Essential Eight at a glance

  • 1. Application control — only approved applications run on endpoints
  • 2. Patch applications — all applications patched within defined timeframes
  • 3. Configure Microsoft Office macro settings — macros restricted to signed and trusted sources
  • 4. User application hardening — browsers and PDF readers hardened
  • 5. Restrict admin privileges — admin accounts limited to those who need them
  • 6. Patch operating systems — OS patched within defined timeframes
  • 7. Multi-factor authentication — MFA on all remote access and privileged accounts
  • 8. Regular backups — backups tested and stored offline or immutably

Maturity Level 1 checklist

ML1 addresses opportunistic attackers — automated bots and low-skill adversaries that compromise businesses through known vulnerabilities and poor hygiene.

  • Application control on workstations (allow-listing or Microsoft WDAC)
  • Applications patched within 30 days of release
  • Office macros blocked by default — only signed macros permitted
  • Web browsers set to block web ads and untrusted Java
  • Admin privileges removed from standard user accounts
  • OS patches applied within 30 days (2 weeks for internet-facing systems)
  • MFA enabled for all remote access (VPN, RDP, cloud portals)
  • Daily backups of critical data, with one copy offline

Maturity Level 2 checklist

ML2 addresses targeted attackers — adversaries who will invest time and technique to compromise a specific organisation.

  • Application control covers servers as well as workstations
  • Applications patched within 14 days (48 hours for critical vulnerabilities)
  • Macros permitted only from trusted locations, not from the internet
  • Browser extensions controlled and limited to an approved list
  • Privileged access workstations (PAWs) used for admin tasks
  • Internet-facing systems patched within 48 hours of critical release
  • MFA on all accounts accessing sensitive data
  • Backups tested quarterly; restoration procedures documented and tested

Common gaps in Australian businesses

  • Admin privileges — most common ML1 gap; many Australian businesses still give staff local admin rights
  • Application patching — third-party applications (Adobe, Chrome, 7-Zip) lag behind OS patching
  • MFA — often deployed for Microsoft 365 but missed for VPN, RDP and third-party SaaS
  • Backup testing — backups exist but restores have never been tested
  • Application control — rarely implemented outside government and large enterprise

How to assess your Essential Eight maturity

An honest Essential Eight gap assessment starts with a technical review of your current environment — not a self-assessment questionnaire. A managed IT or security provider should be able to produce a written gap report that maps each control against the ACSC's maturity requirements and identifies specific remediation steps.

Ready to take the next step?

Talk to a senior Logical Systems engineer — no sales deck, no pressure.

Get a free Essential Eight gap assessment

Ready to run technology logically?

Book a no-obligation conversation with a senior engineer — not a salesperson. We'll tell you honestly whether we're the right fit.