Framework guide • Australia

Essential Eight: Essential Eight

The Essential Eight is the Australian Signals Directorate's (ASD / ACSC) baseline of eight cyber-mitigation strategies, assessed with the Essential Eight Maturity Model. Organisations implement all eight strategies to a chosen target maturity level (1, 2 or 3). Komply maps the November 2023 model as 24 requirements, one per strategy per maturity level.

Last updated · By the Faseel compliance team · Not legal advice

Essential Eight at a glance

Published by
Australian Signals Directorate — Australian Cyber Security Centre (ASD's ACSC)
Version mapped
Essential Eight Maturity Model, November 2023
Structure
8 mitigation strategies × Maturity Levels 1, 2 and 3
Applies to
Mandatory for many Australian non-corporate Commonwealth entities; widely expected of their suppliers and used across the private sector
In Komply
24 requirements, all mapped to ISO 27001:2022

Who must comply with Essential Eight

Australian government entities

Commonwealth entities that must report their Essential Eight maturity.

Government suppliers

Vendors whose contracts ask for a stated Essential Eight maturity level.

Any organisation

A practical, prioritised baseline for organisations anywhere.

The eight strategies

  • Application control
  • Patch applications
  • Configure Microsoft Office macro settings
  • User application hardening
  • Restrict administrative privileges
  • Patch operating systems
  • Multi-factor authentication
  • Regular backups

Essential Eight domains and control counts

24 controls across 8 areas, as mapped in Komply.

Essential Eight domains with number of controls
DomainControls
Application Control3
Patch Applications3
Restrict Office Macros3
User Application Hardening3
Restrict Admin Privileges3
Patch Operating Systems3
Multi-Factor Authentication3
Regular Backups3
Total24

How Essential Eight maps to ISO 27001

All 24 Essential Eight requirements map to ISO/IEC 27001:2022 Annex A technical controls.

Komply tracks your target maturity level for each strategy and the evidence behind it, next to ISO 27001. See how Komply works.

Essential Eight FAQ

What is the Essential Eight?

The Essential Eight is a set of eight mitigation strategies from the Australian Signals Directorate's ACSC: application control, patching applications, Office macro settings, user application hardening, restricting admin privileges, patching operating systems, MFA and regular backups. Implementation is measured with a maturity model.

What are the Essential Eight maturity levels?

The model defines Maturity Levels One, Two and Three, each giving increasing protection against more capable adversaries. Organisations are advised to implement all eight strategies to the same target level before moving higher.

Is the Essential Eight mandatory?

It is mandatory for many Australian non-corporate Commonwealth entities and is increasingly expected of their suppliers. For other organisations it is a strongly recommended baseline.

How does Komply help with the Essential Eight?

Komply maps all eight strategies at each maturity level (24 requirements) to ISO 27001. You track your target level and evidence in one place.

Do ISO 27001 once. Prove Essential Eight too.

Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.