ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Framework · Essential Eight · Maturity model

The Essential Eight maturity model, level by level.

ASD defines four maturity levels by the adversary each one is built to stop, and publishes the exact requirements a system must meet at Maturity Level One, Two and Three. Most summaries stop at the level names. This page reproduces every requirement for every strategy, so you can see what a step up adds before you commit to it.

See the requirementsHow an assessment works

Four levels

Each level is defined by the adversary it is meant to stop.

The model does not grade effort or spend. It grades which class of attacker a system can withstand, and it sets the bar with the same eight strategies at every level. Only the strictness changes.

ML0

Weaknesses in overall posture

The level ASD uses for a system that does not meet Maturity Level One. It is not a target. It describes exposure to tooling anyone can download.

ML1

Commodity tradecraft

Stops actors using widely available tools and techniques against whichever target presents itself: a public exploit for an unpatched service, a password that was stolen, reused or guessed.

ML2PSPF mandate

A modest step-up in capability

Stops actors willing to invest more time in a specific target and in the effectiveness of their tools: better phishing, and workarounds for weaker forms of MFA.

ML3

Adaptive tradecraft

Stops actors ASD describes as more adaptive and much less reliant on public tools and techniques. ASD says plainly that even this level will not stop a sufficiently resourced adversary.

Level definitions follow ASD's Essential Eight maturity model (November 2023). The PSPF requires non-corporate Commonwealth entities to implement every strategy to at least Maturity Level Two.

How the model is applied

Pick a target level and reach it across all eight before moving up.

All eight to the same level

You choose a target level and reach it across every strategy before moving up. The model is implemented and assessed as a package, and an assessor will not test a system against ML2 until ML1 has been demonstrated. A system with three strategies at ML3 and one at ML1 is at ML1.

Exceptions are decisions, with an expiry

ASD allows exceptions, and expects each one to be documented, owned, covered by compensating controls, approved by an appropriate authority, and reviewed within a year. Accepting the risk of not implementing a whole strategy is not an exception. The assessor treats it as not implemented.

Effective, or the level is not met

A strategy counts as implemented only when every one of its requirements is assessed as Effective or Alternate control. One Ineffective finding in one strategy means the target level cannot be claimed for the system. There is no partial credit and no certificate; the outcome is an assessment report.

How the outcomes and exceptions are assessed

The requirements

What ML1, ML2 and ML3 ask of each strategy.

Requirements are reproduced in ASD's wording from the Essential Eight maturity model (November 2023). Lists are cumulative: a system at ML2 must meet everything ML1 asks as well. The number in each cell is what that level adds; select a cell to read the requirements.

Show
Strategy

ML1

Maturity Level One

ML2

Maturity Level Two

ML3

Maturity Level Three

01

Patch applications

02

Patch operating systems

03

Multi-factor authentication

04

Restrict administrative privileges

05

Application control

06

Restrict Microsoft Office macros

07

User application hardening

08

Regular backups

Maturity Level Two

Multi-factor authentication

12 added at this level

  1. 01Multi-factor authentication is used to authenticate privileged users of systems.
  2. 02Multi-factor authentication is used to authenticate unprivileged users of systems.
  3. 03Multi-factor authentication used for authenticating users of online services is phishing-resistant.
  4. 04Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.
  5. 05Multi-factor authentication used for authenticating users of systems is phishing-resistant.
  6. 06Successful and unsuccessful multi-factor authentication events are centrally logged.
  7. 07Event logs are protected from unauthorised modification and deletion.
  8. 08Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.
  9. 09Cyber security events are analysed in a timely manner to identify cyber security incidents.
  10. 10Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.
  11. 11Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered.
  12. 12Following the identification of a cyber security incident, the cyber security incident response plan is enacted.

Fortnightly asset discovery, daily scanning of online services, and patches within 48 hours when the vendor rates a vulnerability critical or an exploit exists.

  1. 01An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
  2. 02A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
  3. 03A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
  4. 04A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.
  5. 05Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
  6. 06Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
  7. 07Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within two weeks of release.
  8. 08Online services that are no longer supported by vendors are removed.
  9. 09Office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

Source: Australian Signals Directorate, Essential Eight maturity model (November 2023), Appendices A to C. Extracted 2026-09-12. The one-line summaries in each cell are ours; the numbered requirements are ASD's.

In Alvor

Run a target level as a control set, not a spreadsheet.

The requirements above are the same ones the pack installs. What changes is that each one gets an owner, evidence with a date on it, and a status nobody can set by hand.

Every strategy at every level, as controls

The Essential Eight pack installs with each strategy's requirements at ML1, ML2 and ML3 as controls with named owners, evidence and review dates. You set the target level; the dashboard shows what is assessed, what is stale and what has no evidence at all.

Compliance

An exception is a risk with an expiry

ASD wants each exception owned, compensated and reviewed within a year. In Alvor an exception is a risk register entry with an owner, a compensating control and an expiry date, so the assessor reads a decision rather than a gap.

Risk Management

Evidence freshness you can see before the assessor does

Each piece of evidence carries a valid-until date. The dashboard buckets it as fresh, expiring, stale or missing, which is the difference between an assessment you prepare for and one you scramble for.

Compliance

Status is set by assessment, never by a dropdown

A control's status comes from an audit assessment, an automated check bound to it, or a recorded override with a reason and an expiry. Nobody can pick Compliant from a menu, so a green control always traces back to a named assessor and dated evidence.

How an assessment works

Questions

Common questions about the Essential Eight maturity model

Maturity Level Two if you are a non-corporate Commonwealth entity, because the PSPF mandates it. Everyone else chooses by the adversary they expect: ML1 stops opportunistic attackers using public tooling, ML2 stops attackers willing to invest in a specific target, and ML3 stops attackers who write their own tools. ASD says even ML3 will not stop a sufficiently resourced adversary, so the level is a floor, not a finish line.

Get started

See how Alvor works for your role

Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.

Request DemoView Pricing
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign
  • Australia

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • ISM
  • IRAP
  • Essential Eight
  • ASD Essentials
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyDisclosure