Skip to content

Published 20 July 2026

Multi-factor authentication for Australian small business

So you've told a broker, a renewal form or a bigger customer's security questionnaire that your business "has MFA." Fair enough. Someone set up an authenticator app at some point. But the real question is usually sharper than that: MFA on what, for whom, and using which kind of factor? A simple yes can hide a setup that meets none of those.

Update, 18 July 2026: ASD has announced the Essential Eight will evolve into a new Essentials series over roughly two years. The MFA criteria below come from the current model, which remains in force throughout the transition.

What multi-factor authentication actually is

Multi-factor authentication means a password alone won't get you in. You also need something you have (a code from an app, a security key) or something you are (a fingerprint), on top of something you know. The idea is simple. A stolen or guessed password stops being enough to get into an account. Most break-ins start with compromised credentials, so this is one of the cheapest, highest-impact controls a small business can put in place. Most setups need no new hardware. You're usually just switching on a feature your business software already has.

What the Essential Eight expects, level by level

MFA is one of the Essential Eight's eight controls, and like the rest it's scored from maturity Level 0 to Level 3. Here's what actually changes between levels, based on the ASD's Essential Eight Maturity Model. For the plain-English rundown of why each requirement matters, see the full MFA control page.

Level 1: partly aligned. MFA is used for the organisation's own online services that handle sensitive data, and for any third-party services (like a cloud accounting platform) that do the same. The factor can be something you have plus something you know, or something you have that's unlocked by something you know or are. That's a fairly broad definition, and it covers most authenticator apps and hardware tokens.

Level 2: mostly aligned. Coverage widens and the bar rises. MFA now applies to privileged users (admins) and unprivileged users (everyday staff), not admins only. Successful and unsuccessful MFA attempts are logged centrally, so odd sign-in activity shows up instead of going unnoticed. And the method itself has to be phishing-resistant. That's a real step up from "any second factor will do."

Level 3: fully aligned. Scope goes one step further, to the data repositories themselves, not just the systems in front of them.

Across all three levels you'll see the same pattern that runs through the whole framework. Each level adds broader coverage (more systems, more people) or more rigour (a stronger, harder-to-phish factor). Never an unrelated new requirement.

Why insurers ask about this specifically

On an Australian cyber insurance application or renewal form, MFA is commonly the most-asked-about control. It's also often the one most likely to cause trouble if the honest answer is no. There's a reason for that. Insurers price risk on what actually turns into claims, and stolen credentials are still one of the most common ways small businesses get compromised. Why would an attacker bother breaching a firewall when they can log in with a password bought off a leak list?

That said, MFA is not a guarantee of anything. Insurers make their own underwriting decisions and weigh MFA alongside backups, patching and admin-access controls together. No single control is a promise of cover, a particular premium, or protection from every incident. What MFA reliably does is shut one of the easiest doors into your business. That's exactly why it comes up first.

How to check where your business actually stands

Knowing the criteria is one thing. Knowing whether you meet them is another. Gaps often only show up once someone checks properly: MFA on for admins but not the rest of the team, or a factor type that technically works but wouldn't hold up against a determined phishing attempt.

Our free Essential Eight self-assessment takes you through plain-English questions on MFA and the other seven controls, and calculates an indicative Level 0–3 for each. That includes where your MFA setup specifically falls short of Level 1, 2 or 3. For the questions we ask and why, see the MFA control guide. It takes about 20 minutes, with no account needed to see your result. It's a self-assessment based on your own answers, not a certification or an audit. It is, though, a much faster way to find out than guessing, or waiting for a renewal questionnaire to ask.

FAQ

Is SMS-based MFA good enough for the Essential Eight? At Level 1, the Essential Eight accepts a broad range of factor types, and an SMS code can qualify as "something you have." From Level 2 up, ACSC pushes towards phishing-resistant methods (like passkeys or hardware security keys), because SMS codes can be intercepted or socially engineered. If you're starting from nothing, SMS-based MFA is a legitimate first step. Just don't treat it as the finish line.

Do all staff need MFA, or just admins? Level 1 requires MFA on the organisation's online services and any third-party services holding sensitive data. That means staff logins generally, not only admins. Level 2 explicitly separates privileged (admin) and unprivileged (everyday staff) users and expects MFA on both. Admin-only MFA, on its own, does not meet the baseline.

What is phishing-resistant MFA? It's an MFA method that can't be beaten by tricking someone into approving a fake prompt or handing over a one-time code. Think hardware security keys or passkeys, not SMS codes or basic push approvals. The Essential Eight expects it at Level 2 for authenticating users of systems.

Does Microsoft 365 or Google Workspace MFA count? Generally, yes. Both platforms have built-in MFA (authenticator apps, security keys) that lines up with the Essential Eight's factor-type requirements, as long as it's actually switched on for the accounts and services that matter and not left optional.

Will MFA alone get my business cyber insurance? One control on its own is not a guarantee of cover. Insurers make their own underwriting decisions and typically look at MFA alongside backups, patching and admin access together. MFA is commonly the first question asked, and the one most likely to cause a decline if it's missing, but it's one piece of the picture, not the whole application.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).