Essential 8 Maturity Level 1, 2 or 3: Which Do You Need?

Claymation illustration of a business owner weighing up three escalating threat figures, the Essential 8 maturity levels

Most businesses read the Essential 8 maturity levels as a grade: how good is our security, one out of three. The Australian Signals Directorate (ASD) does say the levels can give a high-level indication of an organisation's cyber security maturity, so the reading is half right. But open the level descriptions themselves and they are not describing you at all. They describe the attacker. The model is graduated by malicious actors' tradecraft and targeting, which means each level answers one question: how much skill, patience and money would someone need to invest before your controls stopped mattering.

That changes what choosing a level actually is. It is a question about who is likely to come for you and what it would cost you if they got in, not about how organised your IT feels. And it changes the conversation with a provider. If somebody quotes you a maturity level before they understand your business, they have answered a question about you using a number that describes somebody else.

TL;DR: What to remember

  • ✅ There are four levels, Zero through Three. Zero is not a target; it records that the requirements of Level One have not been met.
  • ✅ The levels are defined by attacker tradecraft and targeting, not by how organised your IT is. You are choosing how much effort it should take to get past you.
  • ✅ ASD's general guidance: Level One may suit small to medium enterprises, Level Two large enterprises, Level Three critical infrastructure and high threat environments. Your own target still follows from how desirable a target you are and what a breach would cost.
  • ✅ Level Three is not immunity. ASD says plainly it will not stop an attacker willing to invest enough time, money and effort.
  • ✅ If a client, insurer or regulator has already named a level, the decision has been made for you. The useful work is understanding what you have been signed up to.

Contents

Maturity Level Zero: the controls are not there yet

Level Zero is the odd one out, because it does not describe an attacker. ASD defines it as signifying weaknesses in an organisation's overall cyber security posture which, when exploited, could compromise the confidentiality of data or the integrity and availability of systems. In plain terms, it exists to record the cases where the requirements of Level One have not been met.

An assessment that comes back at Level Zero is not saying your business is uniquely bad. It is saying the controls are not yet at the point where the model has anything to measure. That is a starting position, and a very common one for a business that has never been asked the question before. The distance to Level One is usually shorter than the label makes it feel.

Maturity Level One: commodity attacks looking for any victim

Level One is aimed at attackers using commodity tradecraft that is widely available. ASD's examples: opportunistically running a publicly available exploit against an online service that had not been patched, or logging in with credentials that were stolen, reused, brute forced or guessed. Nothing here is bespoke. The tools are off the shelf and the targets are whoever left a door open.

The defining detail is who these attackers are looking for. ASD's phrasing is that they are generally looking for any victim rather than a specific victim, seeking common weaknesses across many targets instead of investing heavily in one. They will use common social engineering to trick users. If an account they compromise happens to have privileges, they will use them. And depending on what they are there for, they may destroy data, backups included.

This is the level that covers the attacks most Australian small and medium businesses actually meet. Nobody chose you. You were reachable.

Maturity Level Two: attackers prepared to work for it

The step up to Level Two is not raw genius. It is willingness to invest. These actors will spend more time on a target and, ASD notes, more importantly on the effectiveness of their tools. They employ well known tradecraft, but they employ it specifically to bypass the controls you have put in place and to evade detection. Your defences are now part of their planning.

Two details in ASD's description deserve a hard look, because they name things businesses often assume they have already solved. First, these actors actively target credentials using phishing. Second, they use technical and social engineering techniques to circumvent weak multi-factor authentication (MFA). Having MFA switched on is one thing. Having MFA that survives someone who came prepared for it is another, and Level Two is where that gap gets tested.

Their targeting is more selective, but it is still commercially rational: ASD describes them as somewhat conservative about the time, money and effort they will spend. Compromise an account without privileges and they go looking for one that has them, and they may destroy all data a privileged account can reach.

Maturity Level Three: adaptive attackers who picked you

Level Three describes actors who are adaptive and far less reliant on public tools and techniques. They exploit the specific weaknesses in your posture, and ASD names two by example: older software, and inadequate logging and monitoring. They are not just after access. The purpose is to extend it, evade detection and solidify a presence. What Maturity Level 3 involves has its own full guide; here it matters as the top of the ladder you are choosing a rung on.

The tradecraft gets noticeably more specific at this level. Social engineering a user not just into opening a malicious document but into unknowingly helping bypass a control. Circumventing stronger multi-factor authentication by stealing authentication token values to impersonate a user. Gaining privileged credentials or password hashes, pivoting across a network, covering their tracks on the way through.

ASD closes the section with a sentence worth quoting to anyone who treats Level Three as the finish line: it will not stop malicious actors willing and able to invest enough time, money and effort to compromise a target. The model itself says organisations at Level Three still need to consider the wider mitigation strategies and the Information Security Manual. There is no level where the work is finished. There is only a level where you have made yourself expensive.

How to choose a level, and who may have chosen for you

ASD gives a clean two-part test. Your likelihood of being targeted is influenced by how desirable you are to malicious actors. The consequences depend on your requirement for the confidentiality of your data and for the availability and integrity of your systems. Put those two answers next to the level descriptions above and the target usually names itself.

ASD adds one instruction that saves a lot of unproductive argument: consider what level of tradecraft and targeting you are aiming to mitigate, rather than which malicious actors. You are not trying to name your enemy. You are setting a bar for how much effort it should take to get past you.

Four practical consequences follow from the choice:

  • Aim for one level across all eight strategies. ASD's guidance is to reach the same maturity level across all eight before moving higher, because the strategies are designed to complement each other. Strong patching does not offset absent application control. Exceeding the level in places is fine: ASD states organisations should not be penalised for implementing stronger measures than the level being assessed against, and notes it can be more efficient to implement a higher level's requirement directly than to deploy a weaker control and replace it later.
  • Higher is not automatically better. A target above what your risk justifies costs money and operational friction for protection you did not need. The model asks for a level suitable for your environment, not the highest one on the shelf.
  • Somebody may have chosen for you. Where a client contract, an insurer or a regulator names a level, that document is your scope and your target. Read what it actually says, including which systems it covers.
  • The choice should be revisited. Desirability changes when you win a bigger client, take on more sensitive data, or get acquired. A target set in 2024 was set for the business you were in 2024.

For a business in financial services, healthcare or construction, the level is very often decided by the party asking. That is the situation inSUPPORT sees most often, and the practical work is translating somebody else's requirement into a scoped piece of work against the frameworks that apply to your industry, then maintaining it. A maturity level is not a project you finish. It is a state you keep evidencing.

Making sense of which level applies to you

Our client asked for "Essential 8 compliance" without naming a level. What do we do?
Go back and ask, because the phrase does not have a fixed meaning. The Essential 8 is a maturity model, not a certification, so there is no single compliant state to reach. Ask which maturity level they require and which systems they expect it to cover. A vague requirement answered with a vague response is how businesses end up doing the work twice.

Is there a level ASD suggests for a business our size?
Yes, and it is worth knowing before anyone quotes you. ASD's Essential Eight maturity model FAQ states that generally, Maturity Level One may be suitable for small to medium enterprises, Maturity Level Two may be suitable for large enterprises, and Maturity Level Three may be suitable for critical infrastructure providers and other organisations operating in high threat environments. Treat that as a starting position rather than a ceiling: the model still asks you to identify a target suitable for your own environment, and a mid-sized business holding sensitive data in a targeted sector may reasonably sit above the general guidance. If a client, insurer or regulator has named a level, theirs governs.

Can we be at different levels for different systems?
Assessments are conducted against a system, and target levels are set for a system, so different systems can carry different targets where that genuinely reflects their risk. What ASD warns against is uneven implementation within a single scope: reaching the same level across all eight strategies before moving up is the stated approach. Keep the scope boundaries explicit and documented, because a scope that shifts quietly is how a claimed level stops being true.

How long does it take to move up a level?
It depends entirely on the distance and the environment, and any provider quoting a fixed duration before assessing you is quoting a sales figure rather than a plan. What is reasonable to expect is a costed, sequenced list after an assessment, so you can see the work, decide what to do first, and hold someone to it.

See where you actually stand

inSUPPORT works with Australian businesses of roughly 30 to 300 users in financial services, healthcare and construction, where a framework requirement usually arrives from a client, a board or an insurer with a date attached. If a level has landed on your desk and you need to know how far away you are from it, a Cyber Strength Audit records where each of the eight sits today and what closing the distance would cost. We start with the first useful conversation: what you have actually been asked for.

Book a Cyber Strength Audit →

Citations

  • "Essential Eight maturity model", Australian Signals Directorate. The source of every level description above, the guidance to consider tradecraft and targeting rather than named actors, the same-level-across-all-eight rule, and the statement that Maturity Level Three will not stop an attacker willing to invest enough time, money and effort. cyber.gov.au
  • "Essential Eight explained", Australian Signals Directorate. The eight mitigation strategies and their relationship to the wider Strategies to Mitigate Cyber Security Incidents. cyber.gov.au
  • "Essential Eight assessment process guide", Australian Signals Directorate. How a target level is assessed in practice, including the standardised outcomes and the treatment of exceptions and compensating controls. cyber.gov.au
  • "Essential Eight maturity model FAQ", Australian Signals Directorate. The source of ASD's general guidance on which maturity level may suit which size of organisation, the statement that the levels can indicate cyber security maturity, and the position that organisations should not be penalised for implementing stronger measures than the level assessed against. cyber.gov.au

Framework guidance changes. This reflects ASD's published maturity model as at August 2026, and ASD opened a consultation on evolving the Essential Eight in June 2026. Check current ASD guidance before committing to a target level.

Kane Nawrocki, Founder and CEO of inSUPPORT

About the author: Kane Nawrocki is the founder and CEO of inSUPPORT. He has spent more than 25 years in IT and built inSUPPORT to give Australian businesses managed IT, security and compliance as one model, with the remediation an audit finds included in the support fee rather than billed back as a surprise project.

Content reviewed by Probably Genius for accuracy and relevance.

Want to discuss this topic more?
CLICK HERE