Ask an organisation where they stand on the Essential Eight and you will usually get one of two answers. Either a maturity level quoted with suspicious confidence, or a variation of "we're doing the Essential Eight", which is not an answer at all. The maturity model is the part of the framework that turns eight good ideas into a score someone can hold you to, and it is the part most often misread. Here is how it actually works.
Four levels, defined by attacker effort
The model runs from Maturity Level Zero to Maturity Level Three, and the levels are not arbitrary steps of "more security". Each one is calibrated to the tradecraft of the adversary it is meant to frustrate.
Level Zero is not a starting point you declare, it is a finding. It means there are weaknesses in your overall posture significant enough that the strategies, as implemented, would not withstand even commodity attacks.
Level One is designed to frustrate attackers using widely available tools and techniques, the opportunistic intrusions that make up the bulk of what actually arrives at most organisations. Phishing kits, public exploits for unpatched systems, credential stuffing.
Level Two targets adversaries willing to invest time and effort in you specifically: better phishing, some target research, a preparedness to work around basic controls rather than move on to an easier victim.
Level Three is built for adversaries who are well resourced, adaptive, and not deterred by the controls that stop everyone else. Very few commercial organisations face this threat profile, and pursuing Level Three without it spends money on the wrong risks.
You are scored at your weakest control
This is the rule that catches people. Your overall maturity level is the minimum you achieve across all eight strategies, not the average. Seven strategies at Level Two and one at Level One scores as Level One. Partial progress, however real, does not move the headline number.
The Commonwealth's own results show how much this matters. In the 2025 reporting, individual strategies sat between 46 and 70 per cent at Maturity Level 2 or above, yet only 22 per cent of entities reached Level 2 overall. These are organisations with a mandate, a budget and an audit function. The gap between per-strategy performance and the overall score is the minimum rule at work, and it is usually one or two stubborn strategies, most often application control or privileged access, holding the number down.
What a level actually requires
Each strategy has specific requirements at each level, and they escalate in kind, not just degree. Multi-factor authentication at Level One is about coverage of internet-facing services. By Level Three the model is asking about phishing-resistant methods and the paths that bypass MFA entirely. Backups at Level One means they exist and are tested. Higher levels care about how quickly privileged access to backups can be misused and whether an attacker who owns your environment can reach them at all.
The practical consequence: you cannot read your level off a product list. Owning an MFA product, a patching tool and a backup platform says nothing about coverage, cadence and tested restoration, which is what assessment actually measures. When we wrote about what insurers and auditors now expect, this was the core of it: the questions have shifted from "do you have it" to "show us it operating".
Choosing a target level
Level One is the sensible floor for most commercial organisations without a specific threat profile or contractual driver. Level Two is increasingly the expectation for organisations holding sensitive data at scale, operating in critical sectors, or selling into government supply chains, where the requirement often arrives in a contract with a date attached. Level Three is for organisations that have concluded, on evidence, that they face well-resourced and persistent adversaries.
It is legitimate to hold different levels across the eight strategies for a period, provided the gaps are chosen rather than discovered. What does not work is choosing a target because a customer questionnaire has a dropdown, then reverse-engineering the paperwork.
The model is changing, the logic is not
ASD has signalled that the Essential Eight will be retired within about two years, folded into a new Essentials series beginning with Essentials for enterprise IT. The stated direction includes stronger connections between threats, controls and evidence, which is to say: more of what the maturity model already rewards and less tolerance for maturity claims that rest on policy documents. Work that hardens the environment carries across. A score on a slide does not.
We cover the full picture, including sequencing an uplift and the evidence that survives assessment, in our Essential Eight uplift guide. And if you need a maturity level with a date attached, our cyber security practice runs assessments scored against what exists, not what is written down. A practitioner replies within one business day.