Framework · Essential Eight · Maturity model
ASD defines four maturity levels by the adversary each one is built to stop, and publishes the exact requirements a system must meet at Maturity Level One, Two and Three. Most summaries stop at the level names. This page reproduces every requirement for every strategy, so you can see what a step up adds before you commit to it.
Four levels
The model does not grade effort or spend. It grades which class of attacker a system can withstand, and it sets the bar with the same eight strategies at every level. Only the strictness changes.
Weaknesses in overall posture
The level ASD uses for a system that does not meet Maturity Level One. It is not a target. It describes exposure to tooling anyone can download.
Commodity tradecraft
Stops actors using widely available tools and techniques against whichever target presents itself: a public exploit for an unpatched service, a password that was stolen, reused or guessed.
A modest step-up in capability
Stops actors willing to invest more time in a specific target and in the effectiveness of their tools: better phishing, and workarounds for weaker forms of MFA.
Adaptive tradecraft
Stops actors ASD describes as more adaptive and much less reliant on public tools and techniques. ASD says plainly that even this level will not stop a sufficiently resourced adversary.
Level definitions follow ASD's Essential Eight maturity model (November 2023). The PSPF requires non-corporate Commonwealth entities to implement every strategy to at least Maturity Level Two.
How the model is applied
All eight to the same level
You choose a target level and reach it across every strategy before moving up. The model is implemented and assessed as a package, and an assessor will not test a system against ML2 until ML1 has been demonstrated. A system with three strategies at ML3 and one at ML1 is at ML1.
Exceptions are decisions, with an expiry
ASD allows exceptions, and expects each one to be documented, owned, covered by compensating controls, approved by an appropriate authority, and reviewed within a year. Accepting the risk of not implementing a whole strategy is not an exception. The assessor treats it as not implemented.
Effective, or the level is not met
A strategy counts as implemented only when every one of its requirements is assessed as Effective or Alternate control. One Ineffective finding in one strategy means the target level cannot be claimed for the system. There is no partial credit and no certificate; the outcome is an assessment report.
The requirements
Requirements are reproduced in ASD's wording from the Essential Eight maturity model (November 2023). Lists are cumulative: a system at ML2 must meet everything ML1 asks as well. The number in each cell is what that level adds; select a cell to read the requirements.
ML1
Maturity Level One
ML2
Maturity Level Two
ML3
Maturity Level Three
01
Patch applications
02
Patch operating systems
03
Multi-factor authentication
04
Restrict administrative privileges
05
Application control
06
Restrict Microsoft Office macros
07
User application hardening
08
Regular backups
Maturity Level Two
Multi-factor authentication
12 added at this level
Fortnightly asset discovery, daily scanning of online services, and patches within 48 hours when the vendor rates a vulnerability critical or an exploit exists.
Source: Australian Signals Directorate, Essential Eight maturity model (November 2023), Appendices A to C. Extracted 2026-09-12. The one-line summaries in each cell are ours; the numbered requirements are ASD's.
In Alvor
The requirements above are the same ones the pack installs. What changes is that each one gets an owner, evidence with a date on it, and a status nobody can set by hand.
Every strategy at every level, as controls
The Essential Eight pack installs with each strategy's requirements at ML1, ML2 and ML3 as controls with named owners, evidence and review dates. You set the target level; the dashboard shows what is assessed, what is stale and what has no evidence at all.
ComplianceAn exception is a risk with an expiry
ASD wants each exception owned, compensated and reviewed within a year. In Alvor an exception is a risk register entry with an owner, a compensating control and an expiry date, so the assessor reads a decision rather than a gap.
Risk ManagementEvidence freshness you can see before the assessor does
Each piece of evidence carries a valid-until date. The dashboard buckets it as fresh, expiring, stale or missing, which is the difference between an assessment you prepare for and one you scramble for.
ComplianceStatus is set by assessment, never by a dropdown
A control's status comes from an audit assessment, an automated check bound to it, or a recorded override with a reason and an expiry. Nobody can pick Compliant from a menu, so a green control always traces back to a named assessor and dated evidence.
How an assessment worksQuestions
Maturity Level Two if you are a non-corporate Commonwealth entity, because the PSPF mandates it. Everyone else chooses by the adversary they expect: ML1 stops opportunistic attackers using public tooling, ML2 stops attackers willing to invest in a specific target, and ML3 stops attackers who write their own tools. ASD says even ML3 will not stop a sufficiently resourced adversary, so the level is a floor, not a finish line.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.