Published 16 July 2026
Essential Eight maturity levels explained (0 to 3)
Someone has probably asked you about your "Level" lately. A broker wanting to know your Essential Eight maturity, an insurance renewal form, or a bigger customer's security questionnaire. If you went looking for an answer and came back more confused, you're in good company. Most explanations stay abstract. This one covers what the levels mean in practice, and how to work out where your business really sits.
Update, 18 July 2026: ASD has announced the Essential Eight will evolve into the new Essentials series over roughly two years. The maturity levels explained below come from the current model, which remains in force throughout the transition.
The four maturity levels, in plain English
Essential Eight maturity runs from Level 0 to Level 3, and each of the eight controls (MFA, backups, patching and so on) gets its own score. If you want the bigger picture on the framework first, start with our Essential Eight compliance guide.
- Level 0: one or more of the basics for that control aren't in place. That doesn't always mean nothing has been done. Usually what exists is partial, patchy, or nobody can show evidence of it.
- Level 1: partly aligned. There's progress, but coverage has holes. MFA is on for admins but not everyone, say, or backups run but nobody has ever tested a restore.
- Level 2: mostly aligned. The control is applied consistently and is starting to be monitored, not just switched on. Most Australian small businesses aim here, and it's the level insurers and brokers most commonly reference.
- Level 3: fully aligned. Advanced measures aimed at more capable attackers: MFA on data repositories, tighter patch timeframes, logging of admin activity. It's built for organisations facing sophisticated, targeted threats.
These definitions come from the ASD's Essential Eight Maturity Model, the same public framework behind the free self-assessment.
Levels are cumulative, so you can't skip Level 1
This is the most common misunderstanding. People assume Level 2 is just "a bit more" than Level 1, so they check the Level 2 criteria and stop. That's not how the ACSC model works. To reach Level 2 on a control, you need all of that control's Level 1 criteria met, plus everything specific to Level 2. Miss a single Level 1 requirement and the control caps at Level 0. It doesn't matter how impressive your Level 2 or 3 measures look.
Here's how that plays out. A business sets up phishing-resistant MFA for its admin team (a Level 2 measure) but never turned on MFA for everyday staff logins to email. That control still fails Level 1, because the baseline requirement ("MFA is used for the organisation's online services") isn't fully met. The strong admin setup doesn't rescue it.
Your overall score is your weakest control, not an average
Second surprise. Your overall Essential Eight maturity is the lowest level across all eight controls that apply to you. Not an average. Not "5 out of 8 at Level 2." That's on purpose: attackers don't go after your strongest control, they look for the weakest door.
Take a business with excellent backups (Level 3), solid MFA (Level 2) and tested patching (Level 2), but no restrictions on Microsoft Office macros (Level 0). Its overall maturity is Level 0, even though six of the seven other applicable controls are strong. So the fastest way to lift your overall level is almost never polishing your best control. Find the weakest one and fix that.
What actually changes between levels
"Mostly aligned" on its own doesn't tell you much. Here's what the shift looks like for the four controls small businesses ask about most:
| Control | Level 1 (partly aligned) | Level 2 (mostly aligned) | Level 3 (fully aligned) |
|---|---|---|---|
| Multi-factor authentication | MFA is used for online services holding sensitive data, using a factor the user has (e.g. a code or app) | MFA extends to all privileged and unprivileged users, successful/failed attempts are logged centrally, and it's phishing-resistant (e.g. passkeys/hardware keys) | MFA extends to data repositories |
| Regular backups | Backups run on a schedule matching business needs; ordinary user accounts can't modify or delete them | Privileged accounts (other than the backup admin) can't access other users' backups | Even the backup administrator account can't modify or delete backups during the retention period |
| Patch applications | Critical vulnerabilities in internet-facing services patched within 48 hours; everyday apps within two weeks | Patches for other applications applied within one month | Even office productivity apps and browsers get critical patches within 48 hours |
| Application control | Workstations only run an organisation-approved set of executables, scripts and installers. See what application control actually means | Microsoft's recommended application blocklist is added, and the approved-application ruleset is reviewed at least annually | Microsoft's vulnerable driver blocklist is added on top of the Level 2 controls |
That's a sample, not the full criteria. The ACSC model runs to around 150 detailed requirements across the eight controls. What matters is the pattern. Each level adds coverage (more of the organisation, more consistently) or speed/rigour (faster patch windows, stronger authentication factors). It doesn't bolt on some unrelated new requirement.
Which level should a small business target?
For most Australian SMBs, Level 2 is the sensible target. It's mostly aligned, you can get there without enterprise-grade tooling, and it's the level insurers and brokers commonly reference when they ask about your security posture. If you're just starting out, Level 1 is a reasonable baseline. Level 3 is generally overkill unless you handle unusually sensitive data or have a specific reason to expect a sophisticated attacker. It's built for that threat profile, not everyday SMB risk.
Two honest caveats. A maturity level is not a guarantee of insurance approval or a particular premium, and it doesn't rule out an incident. Insurers make their own underwriting decisions, and the Essential Eight reduces risk rather than eliminating it. So treat "Level 2" as a sensible target to document and work towards. It isn't a pass/fail gate.
Find out your own level
Knowing the scale is one thing. Knowing where your business sits on it is another. Our free Essential Eight self-assessment takes you through plain-English questions for each control (the same ones covered in how to do an Essential Eight self-assessment) and calculates your indicative Level 0–3 per control and overall. It takes about 20 minutes, and you don't need an account to see your result. It's a self-assessment, not an audit or certification: it reflects your own answers, not independent verification.
FAQ
Is Level 0 illegal or non-compliant? No. For most private businesses the Essential Eight isn't a law. Level 0 just means there are gaps attackers commonly exploit. It's a risk signal, not a legal breach.
Do I need to reach Level 3? Not usually. Level 3 targets sophisticated, adaptive attackers and typically suits organisations with unusually sensitive data or specific threat exposure. Most SMBs aim for Level 2.
Can different controls sit at different levels? Yes. Each of the eight controls is scored on its own. Your overall figure is the lowest of the applicable ones, which is why closing your single weakest control usually moves your overall score more than improving one that's already strong.
How often should I re-check my level? At least once a year, ideally timed to your insurance renewal. Controls drift as staff, software and exceptions change, so last year's result may not reflect reality any more.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).