CTS - Computer Technology Specialists
Essential Eight Maturity Levels Explained
The ACSC Essential Eight uses four maturity levels — ML0 through ML3 — to describe how completely each of the eight mitigation strategies is implemented. Understanding what each level requires is the starting point for building a realistic compliance roadmap.
Melbourne IT support with visible local credentials
CTS - Computer Technology Specialists has supported Melbourne SMBs since 2000. Contact: 1300 790 780, hello@cts.au, L30 - 35 Collins St Melbourne 3000.
Certifications, affiliations and technology partners
Microsoft Partner, ACSC Essential Eight aligned, ISO 27001 practices, NBN Business Accredited Adviser, Cisco Partner, Dell Partner, HPE Partner, Arcserve Partner, Broadcom Partner, Kyocera Partner.
Maturity Level 0 — not implemented
Maturity Level 0 means the control is either not implemented at all, or is implemented in a way so incomplete that it provides no meaningful protection. Examples include having no MFA on any accounts, no formal patch management process, or backups that have never been tested. ML0 across multiple controls places a business at severe risk and typically means a cyber insurance policy is either unavailable or comes with significant exclusions. For Melbourne businesses starting from ML0, the gap analysis and remediation roadmap are the first priorities.
Maturity Level 1 — partial implementation
Maturity Level 1 addresses the most common, low-sophistication attack techniques. For MFA, ML1 means MFA is enforced on internet-facing services but may not cover all cloud apps or privileged accounts. For patching, ML1 means patches are applied but within 30 days rather than the tighter timelines required at higher levels. For backups, ML1 means backups exist but may not be immutable or may not have been tested. ML1 provides a basic security baseline but is generally insufficient for businesses holding regulated data, handling client financial or health records, or subject to insurance or regulatory requirements.
Maturity Level 2 — the practical compliance target
Maturity Level 2 is the practical target for most Melbourne SMBs in 2026. At ML2, all eight controls are fully implemented to a standard that addresses more sophisticated, targeted attacks. Key ML2 requirements: MFA enforced on all cloud services (not just internet-facing services), critical patches applied within 48 hours of release, application control implemented on all workstations, admin accounts restricted with no standing access for daily work, backups tested for restorability within the last three months, and operating systems not running beyond vendor-supported versions. ML2 satisfies most cyber insurance requirements and is the level referenced in APRA guidance for regulated entities.
Maturity Level 3 — advanced threat protection
Maturity Level 3 addresses advanced threat actors with significant capabilities. ML3 requirements include phishing-resistant MFA (FIDO2 hardware keys or device-bound passkeys) for all users — not just authenticator apps, patch application within 48 hours across all categories (not just critical), application control with hash-based validation rather than path-based rules, time-based privileged access with just-in-time provisioning, and backups tested quarterly with documented recovery results. ML3 is required for defence contractors, APRA-regulated financial institutions, critical infrastructure operators, and organisations under Australian government security frameworks.
Conducting a gap analysis
A gap analysis maps the current state of each control against the target maturity level. The process involves reviewing the Microsoft 365 tenant (MFA coverage, conditional access policies, Defender configuration), endpoint management tooling (patch compliance reports, application control status), Active Directory or Entra ID (admin account audit, standing access review), and backup system (schedule, retention, immutability, last restore test date). The output is a maturity matrix showing the achieved level for each control and a prioritised remediation list. CTS conducts Essential Eight gap analyses as standalone assessments or as part of managed IT onboarding.
Building the compliance roadmap
A realistic Essential Eight compliance roadmap for a Melbourne SMB sequences remediation by risk impact: MFA and admin privilege restriction first (highest impact, fastest to deploy), then patching and EDR, then application control and hardening, then backup hardening and testing. CTS delivers most Melbourne SMBs from gap analysis to Maturity Level 2 within 90 days. The roadmap includes the remediation tasks, responsible parties, target completion dates, and the evidence that will be produced as each control reaches the target level.
Frequently asked questions
What maturity level should my Melbourne business target?
Maturity Level 2 is the practical target for most Melbourne SMBs. It satisfies cyber insurance requirements, APRA guidance for regulated entities, and the supplier assessments that enterprise and government clients conduct. ML3 is required for defence contractors, large financial institutions, and critical infrastructure operators — a minority of Melbourne SMBs.
How do I know what maturity level I'm currently at?
A formal gap analysis maps each of the eight controls against the ML1, ML2, and ML3 requirements and produces a maturity matrix showing your current state. Without a structured assessment, self-declared maturity levels are unreliable — the gap analysis is the essential first step in any compliance program.