If someone has asked your business for an “Essential Eight maturity level” — an insurer at renewal, a tender document, a client in a regulated industry — you have probably found that the official explanation is written for security professionals rather than business owners.
This page fixes that. Four levels, what each one actually means, which one your business should be aiming at, and what ASD’s June 2026 announcement changes.
If you want a walkthrough of the eight strategies themselves, start with our Essential Eight guide for Australian small businesses. This article is about the maturity levels only.

What the maturity model actually measures
The Essential Eight is a set of eight security controls. The maturity model published by ASD is the scoring system that sits on top of them.
ASD first published the model in June 2017 and has updated it regularly since. It defines four levels, numbered Zero through Three. Importantly, you get a level for each of the eight controls — not one score for your whole business.
Here is the part most explanations get wrong. The levels are not a measure of how much paperwork you have. ASD sets them according to the type of attacker each level is designed to stop. Above Level Zero, the levels are based on mitigating increasing degrees of adversary tradecraft and targeting. Tradecraft means the tools and techniques an attacker brings. Targeting means how much time and money they are willing to spend on you specifically.
Policies, staff training and incident response plans all matter enormously. They are simply not what this particular model measures.
The four maturity levels in plain English

Maturity Level Zero
There are gaps large enough that the control is not meaningfully protecting you. Multi-factor authentication switched on for two administrators and nobody else sits here. So does a backup that has never been test-restored.
Maturity Level One
Enough to stop attackers using widely available, off-the-shelf tools. These attackers are not after you specifically — they scan broadly, find whoever left something open, and move on if you are not easy. Think of someone walking down a street trying every car door handle.
Maturity Level Two
Enough to stop attackers who have chosen you and will spend more to get in. Better tooling, more persistence, and more effort spent working around your controls rather than straight through them. Someone who picked your building rather than the street.
Maturity Level Three
Enough to stop attackers who adapt. They do not rely on publicly available tools, they actively hunt for weaknesses in older software and weaker forms of MFA, and they change approach when blocked. Someone who studied your building before they arrived.
Which maturity level should your business target?
ASD does not mandate a level for private businesses. Federal government entities work to their own required baselines, and some tenders and defence supply chain programs specify a level in writing. Outside of that, the choice is yours — and it should follow your risk, not your budget.
In practice, for the 5 to 40 seat businesses we support across South-East Queensland:
- Maturity Level One across all eight controls is the right first target for most businesses. It is achievable in a normal small business environment, it addresses the attacks that actually reach organisations your size, and it is the level insurers and clients tend to ask questions around.
- Maturity Level Two is worth aiming at if you hold genuinely sensitive client data — legal files, patient records, financial records — or if you supply into government or a regulated industry that will eventually ask you to prove it.
- Maturity Level Three is rarely the right target for a small business. It is expensive, it constrains how your people work day to day, and if you are genuinely facing adversaries at that level you have architectural questions the Essential Eight was never designed to answer.
If you do not know where you currently sit, that is a completely normal starting position — and it is a question worth answering before you spend anything.
The mistake we see most often
ASD’s guidance is to choose a target level and bring all eight controls up to it, working through the levels in order. The common mistake is uneven implementation: Level Three multi-factor authentication sitting alongside Level Zero application control.
That does not average out. An attacker only needs the weakest control to be weak. Eight controls at Level One is a genuinely stronger position than three at Level Three and five at Zero.
ASD also expects a risk-based approach. Where a control genuinely cannot be implemented, the exception should be documented, formally approved, given a compensating control, and reviewed on a regular basis — not quietly left alone and forgotten.
What is changing: ASD is retiring the Essential Eight
On 24 June 2026, ASD confirmed it intends to retire the Essential Eight within two years and replace it with a broader Essentials series.
The reason is structural rather than cosmetic. The Essential Eight was designed for on-premises Windows networks at a time when cloud services were not yet standard. Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre, told iTnews that the framework started before cloud was a significant factor, and that a business running no cloud at all today would have a genuinely surprising architecture.
The replacement splits security into separate domains rather than one universal checklist. Enterprise IT is the first chapter, with operational technology and cloud to follow, and a chapter covering agentic AI under consideration. Consultation on the first chapter closed on 12 July 2026.
The timeline is deliberately slow:
- Both frameworks run side by side during a transition period
- ASD expects to begin deprecating the Essential Eight at around the 12-month mark
- Full retirement at around 24 months
What this means for you in practical terms: nothing changes today. The Essential Eight remains the live framework, it is still what tenders and insurers reference, and ASD has been explicit that work already completed carries across. Horlyck’s position was that the investment made under the Essential Eight will still be relevant under the Essentials.
If you were holding off on starting until the new framework lands, don’t. Multi-factor authentication, patching, tested backups and restricted administrator accounts are not going anywhere. They will simply be described differently.
Where to start
- Find out where you actually are. An honest assessment against all eight controls, scored level by level. Guessing produces false confidence, which is worse than knowing you have gaps.
- Pick a target level and write it down. Including the reason. When a client or insurer asks, the reasoning matters as much as the number.
- Fix the zeros first. Lifting a Level Zero control to Level One buys you far more real protection than pushing an already-strong control higher.
- Reassess on a schedule. Environments drift. A control that was at Level One last year may not be today, particularly after staff changes or a new application rollout.
Getting a straight answer on where you stand
Netcomp has been supporting Australian businesses since 2002, and Essential Eight implementation is a core part of what we do for legal, accounting, healthcare and not-for-profit clients across Brisbane and South-East Queensland.
We run a free 30-minute benchmark against all eight controls — no obligation, and you get your current level either way. Book your Essential Eight audit, or call us on 1300 363 127.

