If you're trying to understand where your organisation sits against the Australian Signals Directorate's Essential Eight — or preparing to engage an assessor — this guide covers what a maturity assessment actually involves, what the four maturity levels mean in practice, what gaps Australian organisations most commonly find, and how to use the results.
The Essential Eight is now the most widely referenced cybersecurity framework in Australia. It's embedded in the SOCI Act CIRMP obligations, expected of federal government suppliers, and increasingly required by enterprise customers of all kinds. Getting your maturity level right — and being able to evidence it — matters more in 2026 than ever before.
What is an Essential Eight maturity assessment?
An Essential Eight maturity assessment is a structured evaluation of how effectively your organisation has implemented each of the ASD's eight priority mitigation strategies, and at what level of maturity. The output is a maturity score for each of the eight strategies, an overall view of where you sit relative to your target level, and a prioritised list of gaps to address.
It is not a one-size-fits-all audit. The methodology varies depending on whether it's conducted as a self-assessment, a third-party assessment, or a full technical deep-dive. The ASD publishes guidance on assessment methodology, and assessors typically combine interviews, documentation review, and technical testing to produce a defensible result.
Importantly, a maturity assessment is not the same as a penetration test or a vulnerability scan — though both may be components of a thorough assessment. The focus is on whether controls are implemented, consistently applied, and operating effectively across the scope — not just whether they exist on paper.
The four maturity levels explained
The ASD's Essential Eight Maturity Model defines four levels. Understanding what each level actually means in your environment — not just as an abstract description — is essential for setting a realistic target and building a credible roadmap.
Maturity Level 0 — Not implemented
One or more of the eight strategies has not been implemented or is not on the roadmap. At ML0, an organisation is exposed to the most common categories of cyber threat with minimal mitigating controls. The CISC and ASD consider ML0 unacceptable for any regulated organisation.
In practice, ML0 is more common than most organisations expect. It often manifests not as complete absence of a control but as a control that exists in a specific environment but hasn't been applied consistently — for example, MFA deployed for corporate email but not for remote desktop access, or application whitelisting applied to servers but not workstations.
Maturity Level 1 — Partly aligned
Controls are partially implemented and provide some protection against opportunistic attackers — typically less sophisticated threat actors using commodity tools and techniques. ML1 is the absolute minimum for any organisation with meaningful cyber risk exposure, and it's where most Australian SMEs sit when they first go through an assessment.
ML1 is characterised by inconsistent application. Controls may be deployed in some environments but not others, applied to some users but not all, or implemented technically without corresponding governance documentation.
Maturity Level 2 — Mostly aligned
Controls are consistently applied across the organisation and provide protection against a wider range of adversaries, including those using more targeted techniques. ML2 is the recommended target for most Australian enterprises, regulated industry participants, and government suppliers.
The shift from ML1 to ML2 is often the hardest part of an uplift program. It requires not just deploying controls but embedding them in operational processes, governance frameworks, and change management — ensuring that new systems, users, and vendors are brought into scope consistently rather than as an afterthought.
Maturity Level 3 — Fully aligned
The highest maturity level. Controls are fully implemented, continuously monitored, and validated through testing. ML3 provides protection against sophisticated and persistent adversaries — the threat actors most likely to target critical infrastructure and high-value targets.
ML3 is explicitly required for critical infrastructure operators under the SOCI Act, and for organisations assessed as Systems of National Significance (SoNS). It is also increasingly expected of defence industry suppliers and organisations handling highly sensitive data. The controls at ML3 are not fundamentally different from ML2 — what distinguishes ML3 is the completeness of implementation, the rigour of testing, and the continuous assurance cycle.
How a maturity assessment works — step by step
Step 1: Scoping
Before any assessment activity begins, the scope needs to be clearly defined. This means identifying which environments, systems, and user populations are in scope — corporate IT, OT environments, cloud infrastructure, remote access systems, and third-party access. For organisations with both IT and OT environments, the scoping decision has significant implications: OT systems have different applicability rules for some of the eight strategies.
Scoping also includes defining the target maturity level. This should be based on your regulatory obligations, your risk profile, and any contractual requirements from customers or government. For SOCI-regulated entities, the target level should be documented in your CIRMP.
Step 2: Documentation and evidence review
The assessor will request documentation covering each of the eight strategies — policies, standards, configuration baselines, system lists, user access records, patch management logs, backup schedules and test results, and MFA enrollment records. This phase establishes the governance and process layer of the assessment.
A common mistake is treating this phase as the whole assessment. Documentation is necessary but not sufficient — CISC auditors and sophisticated assessors will look for evidence that controls are actually operating, not just that policies exist.
Step 3: Technical testing and configuration review
For a rigorous assessment, documentation review is complemented by technical testing. This typically includes:
- Configuration review — examining system and application configurations against the ASD's guidance for each strategy
- Patch currency analysis — assessing whether operating systems and applications are patched to the required currency within the required timeframe
- Application control testing — attempting to execute unapproved applications or scripts to validate enforcement
- MFA validation — verifying that MFA is enforced across all required access paths, including administrative access, remote access, and internet-facing services
- Backup and recovery testing — reviewing whether backups are taken at the required frequency, are isolated from the main network, and have been tested for successful recovery
For organisations with OT environments, the technical testing phase requires specialist expertise and careful planning. Active testing in an OT environment can cause operational disruption if not managed correctly — passive assessment approaches are used where active testing carries operational risk.
Step 4: Interviews and walkthroughs
Structured interviews with IT staff, security personnel, and relevant business stakeholders provide context that documentation and technical testing alone cannot capture. Interview questions focus on how controls are applied in practice — what happens when a new user is onboarded, how patches are tested and deployed, how exceptions are managed, and how incidents are handled.
The interview phase also helps identify compensating controls — situations where a control isn't implemented as specified by the ASD guidance but where an alternative measure provides equivalent protection. These need to be documented and justified.
Step 5: Gap analysis and maturity scoring
With evidence collected, the assessor scores each of the eight strategies against the four maturity levels. This requires judgement — the ASD guidance provides criteria for each level, but applying those criteria to a complex, real-world environment isn't always black and white.
The output is a maturity score per strategy, not just an overall score. An organisation might be at ML2 for most strategies but ML0 for application control, for example. Understanding the per-strategy profile is more useful than an aggregate score for planning remediation.
Step 6: Prioritised remediation roadmap
The final output of a maturity assessment is a prioritised roadmap — not just a list of gaps. Effective remediation roadmaps account for:
- Risk impact — which gaps expose the organisation to the greatest risk if exploited
- Effort and cost — which gaps can be closed quickly and cheaply, and which require significant project investment
- Dependencies — which gaps need to be addressed before others (for example, getting a complete asset inventory before assessing patch currency)
- Regulatory deadlines — particularly important for SOCI-regulated entities with CIRMP reporting obligations and annual report deadlines
For CIRMP purposes, the roadmap needs to be tied to your chosen framework's reporting cycle. The September 2026 CIRMP annual report deadline is approaching — any gaps identified in an assessment now should be reflected in your current CIRMP and your annual report.
Most common gaps found in Australian organisations
Based on Essential Eight assessments across Australian enterprise and critical infrastructure environments, these are the areas where gaps are most frequently found:
Application control is consistently one of the hardest strategies to implement comprehensively. Many organisations have application whitelisting on servers but not workstations, or have a whitelist that hasn't been reviewed since it was created. Keeping an application allowlist current in a dynamic environment requires operational processes that most organisations don't have in place.
Patching currency — particularly for internet-facing services — is a persistent challenge. The ASD's current guidance requires patches for internet-facing services to be applied within 48 hours for vulnerabilities with a CVSS score of 9 or above. Many organisations are patching within days or weeks, not hours. For OT environments, the challenge is more fundamental — patches may require vendor testing and a scheduled maintenance window that can't be accelerated.
Restricting administrative privileges often reveals more accounts with admin access than anyone expected. Service accounts with unnecessary admin rights, shared admin accounts, and help desk staff with domain admin privileges are common findings. The remediation is straightforward in principle but disruptive in practice.
Multi-factor authentication is frequently incomplete rather than absent. MFA is deployed for some systems but not all — and the gaps are often in the highest-risk access paths: administrative accounts, legacy systems, or remote access solutions that predate the MFA rollout.
Macro settings — configuring Microsoft Office to block macros from the internet and restrict execution to trusted sources — is often partially configured or inconsistently applied across different Office versions or user populations.
How to choose your target maturity level
For most Australian organisations, ML2 is the right target. It provides meaningful protection against the most common threat actors, satisfies most regulatory and contractual requirements, and is achievable within a reasonable timeframe and budget.
ML3 is required if you are:
- A responsible entity under the SOCI Act operating in a high-risk sector
- Assessed as a System of National Significance (SoNS)
- A defence industry supplier with relevant obligations
- Contractually required to achieve ML3 by a government customer
ML1 is only appropriate as a very short-term interim target for organisations that are starting from ML0 and need to demonstrate immediate progress. It should not be treated as an endpoint.
If you're unsure what target level applies to your organisation, your regulatory obligations — including your CIRMP obligations if you're a SOCI Act responsible entity — should be the starting point.
Using assessment results
The output of a maturity assessment is most valuable when it's directly connected to action. That means:
Feeding results into your CIRMP. If you've adopted the Essential Eight as your CIRMP cybersecurity framework, your assessment results need to be documented in your CIRMP and reflected in your annual report. The assessment is the evidence that you've assessed your cybersecurity posture — which is a core CIRMP obligation.
Building a realistic uplift program. The roadmap from your assessment should drive a time-bound remediation program with clear ownership and milestones. Without this, assessments become a periodic exercise that produces reports nobody acts on.
Establishing a continuous assurance cycle. The Essential Eight is updated by the ASD — most recently in September 2025. The threat landscape changes. Your environment changes. A maturity assessment is not a one-time exercise — it should feed into an ongoing monitoring and review cycle, with formal reassessment at least annually.
Preparing for external scrutiny. If you're a SOCI-regulated entity, CISC auditors may request evidence of your Essential Eight assessment and the currency of your maturity status. If you're a government supplier, your customers may request evidence of your maturity level. Having a current, documented, evidence-backed assessment position is the difference between a credible compliance posture and a paper exercise.
How ASE Tech approaches Essential Eight assessments
ASE Tech's cybersecurity team conducts Essential Eight maturity assessments across IT and OT environments for Australian enterprises and critical infrastructure operators. Our assessments are structured around the ASD's guidance, complement CIRMP obligations for SOCI-regulated clients, and produce a maturity score per strategy backed by documented evidence rather than self-reported responses.
For energy sector operators, we integrate AESCSF maturity assessment into the process — giving you a single assessment that addresses both your Essential Eight position and your AESCSF obligations.
The output is a prioritised remediation roadmap that fits your operational constraints — not a list of IT security recommendations that can't be implemented in your environment.
Contact our team to discuss your Essential Eight assessment, or visit our cybersecurity services page to learn more about how we support Australian organisations with Essential Eight uplift.
.jpg)