Essential 8 Maturity Levels: ML1 vs ML2 vs ML3
The Essential 8 maturity levels measure how well an organisation has implemented the Australian Cyber Security Centre’s eight mitigation strategies, ranked from ML0 (not yet implemented) to ML3 (fully mature against sophisticated adversaries). Most Australian government contracts and critical infrastructure obligations require at least ML1, with ML2 and ML3 expected as risk and regulatory exposure increases.
The Four Essential Eight Maturity Levels at a Glance
Not Yet Implemented
Weaknesses in cyber security posture that could be exploited by common, publicly available tools.
Baseline Protection
Protects against adversaries using basic, widely available techniques and tools opportunistically.
Moderately Sophisticated Threats
Protects against adversaries who invest more time and effort, evading detection and bypassing basic controls.
Highly Sophisticated Threats
Protects against adversaries who are highly adaptive and less reliant on public tools, targeting specific organisations.
According to the Australian Signals Directorate’s Essential Eight Maturity Model, organisations should select a target maturity level based on their threat environment and the extent to which they are a target, rather than assuming ML3 is always the goal.
Essential Eight Controls: ML1 vs ML2 vs ML3
Each of the eight strategies has distinct requirements at every maturity level. The table below breaks down what changes as you move from ML1 to ML3, in plain English rather than technical jargon.
| Control | ML1 | ML2 | ML3 |
|---|---|---|---|
| Patch Applications | Patch within 1 month; scan monthly | Patch critical vulns in 48 hrs; scan fortnightly | Patch critical vulns in 48 hrs; scan weekly; remove unsupported apps |
| Patch Operating Systems | Patch within 1 month; scan monthly | Patch critical vulns in 48 hrs; scan fortnightly | Patch critical vulns in 48 hrs; scan weekly; no unsupported OS versions |
| Multi-Factor Authentication | MFA on remote access and important data repositories | MFA for all users on all internet-facing services | Phishing-resistant MFA (e.g. hardware keys) across the board |
| Restrict Admin Privileges | Validate admin need annually; restrict to dedicated admin accounts | Admin accounts blocked from internet, email, web browsing | Just-in-time admin privileges; privileged access continuously monitored |
| Application Control | Control executables on workstations from common storage locations | Extend control to scripts, installers, DLLs; servers included | Control extended to drivers; centrally managed allow-list |
| Restrict Microsoft Office Macros | Macros disabled for users without a demonstrated business need | Macros only run from trusted, vetted locations; blocked from internet | Macro activity logged and monitored centrally; allow-listed macros only |
| User Application Hardening | Block ads, Flash, Java in browsers | Harden Office, PDF software; block web ads and untrusted content | Application hardening centrally managed and enforced; settings can’t be changed by users |
| Regular Backups | Backups of important data, software, configs; tested annually | Backups synchronised; restoration tested; unprivileged accounts can’t modify or delete | Backups tested as part of DR exercises; unprivileged accounts blocked from accessing other users’ backups |
In our client engagements, the biggest gap we see between ML1 and ML2 is rarely the technology itself. It is the operational discipline required to sustain 48-hour patching cycles and centrally enforced application control across an entire fleet, not just a subset of systems.
Who Needs Which Essential Eight Maturity Level
The right target level depends on contractual obligations, sector regulation, and how attractive your organisation is as a target, not on picking the highest number available.
ML1 — General SMEs and Low-Risk Suppliers
Suitable for small and medium businesses with no specific government or regulatory mandate, or suppliers handling low-sensitivity data. Establishes baseline hygiene against opportunistic attacks.
ML2 — Government Contractors and Regulated Sectors
Increasingly required for organisations tendering for Australian Government contracts, handling official-sensitive information, or operating in sectors with baseline cyber obligations such as finance and health.
ML3 — Critical Infrastructure and High-Value Targets
Expected of critical infrastructure operators under the SOCI Act, defence-related entities, and organisations holding highly sensitive data that would attract sophisticated, targeted adversaries.
When advising clients, we start by mapping their actual contractual and regulatory drivers before recommending a target level. Overshooting to ML3 without a genuine risk case often means spending budget on controls that do not match the organisation’s real threat profile.
ML1 to ML2 Effort Estimate: What Actually Changes
Moving from ML1 to ML2 is less about new technology and more about tightening operational discipline across controls you likely already have in place. For a mid-sized organisation, the uplift typically takes 6 to 12 weeks depending on environment size and legacy system complexity.
Patching Cadence
Shifting from monthly to 48-hour patching for critical vulnerabilities usually requires automated patch management tooling and tighter change control, not just more frequent manual checks.
MFA Coverage
Extending MFA from remote access only to all internet-facing services is often the fastest win, but legacy applications without native MFA support can extend this stage.
Application Control Scope
ML2 extends control from workstations to servers and adds scripts, installers, and DLLs. This is usually the most time-intensive change, as it requires baselining what is legitimately in use before restricting the rest.
Across our Essential Eight engagements, the organisations that move fastest are the ones that tackle application control scoping early, since it has the longest lead time and the most dependencies on other teams.
Essential Eight Maturity Levels: Frequently Asked Questions
What is the Essential Eight maturity model?
The Essential Eight maturity model is a framework from the Essential Eight security compliance framework that ranks how well an organisation has implemented the ACSC’s eight mitigation strategies, from ML0 (not implemented) to ML3 (mature against sophisticated adversaries).
What is the difference between ML1 and ML2?
ML1 protects against basic, opportunistic attacks with baseline controls. ML2 tightens patching timeframes to 48 hours for critical vulnerabilities, extends MFA to all internet-facing services, and expands application control from workstations to servers.
How long does it take to reach ML2?
Moving from ML1 to ML2 typically takes 6 to 12 weeks for a mid-sized organisation, depending on environment size and legacy system complexity. Application control scoping is usually the longest-running task.
Which companies need Essential Eight ML2 or ML3?
ML2 is increasingly required for Australian Government contractors and regulated sectors such as health and finance. ML3 is expected of critical infrastructure operators under the Security of Critical Infrastructure Act and defence-related entities.
Do I need Essential Eight compliance for healthcare?
Healthcare organisations handling sensitive patient data are increasingly expected to reach ML2 given regulatory and privacy obligations. See our guide on healthcare data security audits and HIPAA compliance for sector-specific detail.
Content Reviewed By
Ketki Tidke
Cyber Security and GRC Lead Auditor — ISO 27001 Lead Auditor
Ketki is a certified ISO 27001 Lead Auditor specialised in Governance, Risk and Compliance, with experience consulting public, private, and government clients. She evaluates threats, risk impacts, and regulatory requirements across multiple industry frameworks.
Check Your Essential Eight Maturity Level
Speak with our GRC specialists to find out where your organisation sits today and what it takes to reach your target maturity level.
Check Your Maturity Level