The Australian Government standard

What is the Essential Eight?

The Essential Eight is the Australian Government's baseline cyber security framework — eight practical mitigation strategies published by the Australian Signals Directorate (ASD) that, implemented together, stop the large majority of cyber attacks Australian businesses actually face. Progress is measured in three maturity levels.

The eight controls, explained

The framework is deliberately practical: each control blocks a real attack path. In the Australian Signals Directorate's own grouping:

1Application control

Only trusted, approved software is allowed to run on your computers. If ransomware or an unknown program tries to execute, it's blocked by default — the single most effective control against malware. Otaris implements this with tools like ThreatLocker.

2Patch applications

Programs like browsers, Office and PDF readers are updated promptly so known security holes get closed before attackers exploit them. Higher maturity levels shorten the deadline: critical vulnerabilities patched within 48 hours.

3Configure Microsoft Office macro settings

Macros — the hidden code inside Office documents that attackers use to deliver malware — are blocked for users who don't need them, and only allowed from trusted, vetted sources for those who do.

4User application hardening

Risky features nobody needs — like Internet Explorer 11, Java in the browser and web advertisements — are disabled or removed, shrinking the attack surface your team exposes every day.

5Restrict administrative privileges

Admin accounts are limited, separated from everyday accounts, and re-validated regularly — so one phished password can't hand an attacker the keys to your whole environment.

6Patch operating systems

Windows and other operating systems are kept current with the latest security fixes, and unsupported operating systems are replaced — old, unpatched systems are the easiest way in.

7Multi-factor authentication

A second check at sign-in (an app prompt or security key) so a stolen password alone isn't enough. MFA stops the overwhelming majority of account-takeover attacks and is required for remote access, email and important systems.

8Regular backups

Recent, tested copies of your important data, kept where ransomware can't reach them — with restores actually rehearsed, so recovery is a procedure rather than a hope.

The full framework is public — read the standard on cyber.gov.au.

The three maturity levels

The Essential Eight is measured against a maturity model: the same eight controls, implemented progressively more rigorously depending on who you need to keep out.

Maturity Level 1

The baseline for most Australian businesses.

Protects against opportunistic attackers using widely-available tools — the commodity phishing and malware campaigns that catch most businesses out. All eight controls implemented to the Level 1 specification.

Maturity Level 2

For businesses adversaries deliberately target.

Defends against attackers willing to invest real time and effort in you specifically — tighter patching deadlines, stronger MFA, more logging. The level commonly expected for government and defence-adjacent work.

Maturity Level 3

The highest level.

Built to withstand determined, well-resourced and adaptive attackers. The strictest implementation of all eight controls, for organisations that cannot afford 'almost'.

Every Otaris managed IT plan implements the Essential Eight — Fortress ($139/user/month) delivers full Maturity Level 1, Knox ($179) Level 2, and Titan ($199) Level 3. To see where your business stands today, start with the free Essential Eight Cyber Security Scorecard, or read our deeper dive on the maturity levels.

Frequently asked questions

The Essential Eight means eight specific security controls the Australian Signals Directorate recommends every organisation implement: application control, patching applications, restricting Office macros, hardening user applications, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. They are grouped as “essential” because together they block the attack methods ASD sees most often in real incidents. Each control is implemented to one of three maturity levels, so doing the Essential Eight always means doing all eight to a stated level — not picking the convenient ones.

The Essential Eight is Australia’s baseline cyber security framework, written by the Australian Signals Directorate for Australian conditions and published free on cyber.gov.au. It is mandated for non-corporate Commonwealth entities, and used as the reference standard by Australian cyber insurers, defence supply chains and larger customers assessing their vendors. In June 2026 ASD announced it will be superseded by a broader “Essentials” series — see the next question.

Yes. On 24 June 2026 the Australian Signals Directorate announced the Essential Eight will be replaced by a new “Essentials” series, beginning with Essentials for enterprise IT. ASD expects to deprecate the Essential Eight around mid-2027 and retire it around mid-2028. The reason is structural: the Essential Eight was designed for on-premises, Windows-centred networks, and its controls do not map cleanly onto cloud and SaaS environments where responsibility is shared with the provider. ASD has said organisations that have already implemented the Essential Eight will not lose that work, because the new guidance is expected to align closely with the existing controls. If you are being asked for Essential Eight evidence today, it still applies — keep going, and expect the language to change. Call 1800 456 567 if you want to know what the transition means for your business.

For private businesses the Essential Eight is not legislated, but it is rapidly becoming unavoidable in practice: cyber insurers ask for it, government and defence supply chains (including DISP) expect it, and larger customers increasingly require evidence of it from their vendors. For non-corporate Commonwealth entities, Essential Eight implementation is mandated under government policy. Otaris aligns Adelaide businesses to the framework and provides the evidence. Call 1800 456 567.

Maturity Level 1 means all eight controls are implemented well enough to stop opportunistic attacks using commodity tools — application control, prompt patching, macro restrictions, application hardening, restricted admin privileges, multi-factor authentication and tested backups. It is the sensible baseline for most Australian businesses, and the level the Otaris Fortress plan delivers in full.

With Otaris, full Essential Eight Maturity Level 1 is built into the Fortress plan at $139 per user per month — with Level 2 (Knox, $179) and Level 3 (Titan, $199) above it and pricing published openly. There's no separate compliance project fee: the controls are implemented and maintained as part of managed IT. Call 1800 456 567 for a quote.

The Australian Signals Directorate (ASD), through the Australian Cyber Security Centre (ACSC) — the Australian Government's technical authority on cyber security. The full framework and its maturity model are public on cyber.gov.au, so you can verify everything a provider tells you against the standard itself.

Start with an assessment against each of the eight controls. Otaris runs this as the free Essential Eight Cyber Security Scorecard — a plain-English review of your environment that scores your business against the framework and gives you a clear maturity level and a prioritised fix list. Call 1800 456 567 or book it online.

Find out your Essential Eight maturity level.

Book your free Essential Eight Cyber Security Scorecard and we'll score your business against the Australian Government's framework — a clear maturity level and a prioritised fix list, in plain English. No jargon, no obligation.

  • A plain-English Essential Eight Cyber Security Scorecard
  • Your current maturity level across all eight controls
  • A prioritised, costed path to the level you need

Prefer to talk?

Call 1800 456 567

Powered by Calendly — your data is handled securely.

Our office · Level 2, Suite 201, 7 James Place, Adelaide

By submitting, you agree to our terms and privacy policy. No spam — ever.