Skip to content

The Essential Eight, and which maturity level your business needs.

Your insurer, your biggest client or your auditor has probably asked about it. The Essential Eight is a control set from the Australian Cyber Security Centre (ACSC), and it is what your business gets scored against. Aim at the right maturity level and most of those questions answer themselves.

The Essential Eight explained

Eight controls that stop most attacks on Australian businesses.

The Australian Signals Directorate publishes and maintains the list through the ACSC. Eight controls are not the whole of cybersecurity, but they are the shared language. Insurers score against them, larger clients ask about them, and regulators reference them. Almost every serious incident post-mortem traces back to one or more of them.

It is the framework you will be asked about, so it is the one our services are built around.

Go to the source

The ACSC's own Essential Eight documents.

If you are producing evidence for a regulator or an auditor, quote from these rather than from us. The ACSC's wording is the one that counts.

Maturity levels

Maturity levels ML0 to ML3, and which one your business should aim for.

ML0 to ML3 are the four maturity levels, zero through three. Your overall score is your weakest control, not an average. Aim for the lowest level that satisfies the people auditing you and the people whose data you keep, then add a margin.

ML0 Where most businesses start

Controls partly in place or missing, and no evidence written down. Most mid-market Australian businesses land here before anyone has assessed them properly. Nobody aims for ML0. The question is what a realistic path to ML1 or above looks like.

ML1 If a breach would mostly hurt you, not the people you serve

Controls that stand up to the attack tools anyone can download. Right if you don't keep client information that would do real damage if it leaked. Most cyber-insurance renewals and vendor-security audits now expect this much.

ML2 If a breach would significantly affect others

Controls tuned against attackers who know what they are doing, with admin access properly isolated and evidence you can produce on request. Right for law, finance, health and regulated services. It is the level we build for.

ML3 If you handle classified work or you're a named enterprise target

Central logging of everything an admin does, credentials protected by hardware, and validation that never stops. Built for defence supply chains, classified environments, and businesses big enough to attract an attacker who targets them by name.

Find your level

Which level should you aim for?

Three questions get you most of the way there.

Maturity level picker

Q1Has a defence contractor, classified-information body or named regulator specifically asked you for Essential Eight ML3?
Q2If your environment were breached tomorrow, who would be harmed?
Q3Do regulators or insurers ask you to prove that your IT controls are working?

Your recommended target

?

Your target level appears here once all three questions are answered, along with the reason for it.

By industry

Which level fits your industry.

  • ML1

    You keep no data that would seriously harm your clients if it leaked. A breach costs you time and money, but nobody else pays for it. Trades, light retail, logistics, marketing and professional services without sensitive client files usually land here. Our Managed IT Complete stack is built to maintain ML1 without you thinking about it.

  • ML2

    You carry information whose exposure would do real harm to your clients, patients, donors or counterparties. Law firms, financial services, accounting, health and allied-health, education, not-for-profits with beneficiary data, conveyancers. Our Managed IT Complete plus Compliance stack is built to reach ML2 and stay there.

  • ML3

    You handle classified or highly sensitive information under a specific obligation: defence supply chain, top-secret work, critical-infrastructure operators. If you're wondering whether ML3 applies, it almost certainly doesn't. The parties who need ML3 have been told so in writing.

  • ML0

    A starting point. If an accurate assessment puts you here, the next question is which of the three levels above your business needs.

Free self-assessment

Score yourself. Get a branded PDF.

Eight questions, your estimated maturity level, a report you can share.

Answer for where you actually sit today, not where you plan to be. You get an estimated maturity level and a CCP-branded PDF you can hand to your board, your broker or your auditor. It runs entirely in your browser. No email required, and nothing reaches us unless you decide to book a call.

Take the self-assessment

Assessment to uplift

What an Essential Eight uplift involves, from assessment to review.

Assess, gap-analyse, plan, uplift, review, then start again. Reaching a maturity level is one job and sustaining it is another, because your staff change, your vendors change and the attacks change. Each pass through the loop, we re-audit against the current bar and step you up from there.

Step 01

Assess where you actually sit.

A written audit of your environment against the ACSC criteria, control by control. You get a rating for each of the eight controls, and one overall maturity level set by the weakest of them.

Common questions

What business owners actually ask about the Essential Eight.

Is Essential Eight ML1 enough for my business?
Who actually audits Essential Eight compliance?
How does the Essential Eight map to our cyber insurance questionnaire?
Do we have to do all eight controls, or can we pick?
Can you give us a rough budget and timeline for the ML0 to ML1 move?

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit