Essential Eight: Essential Eight
The Essential Eight is the Australian Signals Directorate's (ASD / ACSC) baseline of eight cyber-mitigation strategies, assessed with the Essential Eight Maturity Model. Organisations implement all eight strategies to a chosen target maturity level (1, 2 or 3). Komply maps the November 2023 model as 24 requirements, one per strategy per maturity level.
Last updated · By the Faseel compliance team · Not legal advice
Essential Eight at a glance
- Published by
- Australian Signals Directorate — Australian Cyber Security Centre (ASD's ACSC)
- Version mapped
- Essential Eight Maturity Model, November 2023
- Structure
- 8 mitigation strategies × Maturity Levels 1, 2 and 3
- Applies to
- Mandatory for many Australian non-corporate Commonwealth entities; widely expected of their suppliers and used across the private sector
- In Komply
- 24 requirements, all mapped to ISO 27001:2022
Who must comply with Essential Eight
Australian government entities
Commonwealth entities that must report their Essential Eight maturity.
Government suppliers
Vendors whose contracts ask for a stated Essential Eight maturity level.
Any organisation
A practical, prioritised baseline for organisations anywhere.
The eight strategies
- Application control
- Patch applications
- Configure Microsoft Office macro settings
- User application hardening
- Restrict administrative privileges
- Patch operating systems
- Multi-factor authentication
- Regular backups
Essential Eight domains and control counts
24 controls across 8 areas, as mapped in Komply.
| Domain | Controls |
|---|---|
| Application Control | 3 |
| Patch Applications | 3 |
| Restrict Office Macros | 3 |
| User Application Hardening | 3 |
| Restrict Admin Privileges | 3 |
| Patch Operating Systems | 3 |
| Multi-Factor Authentication | 3 |
| Regular Backups | 3 |
| Total | 24 |
How Essential Eight maps to ISO 27001
All 24 Essential Eight requirements map to ISO/IEC 27001:2022 Annex A technical controls.
Komply tracks your target maturity level for each strategy and the evidence behind it, next to ISO 27001. See how Komply works.
Essential Eight FAQ
What is the Essential Eight?
The Essential Eight is a set of eight mitigation strategies from the Australian Signals Directorate's ACSC: application control, patching applications, Office macro settings, user application hardening, restricting admin privileges, patching operating systems, MFA and regular backups. Implementation is measured with a maturity model.
What are the Essential Eight maturity levels?
The model defines Maturity Levels One, Two and Three, each giving increasing protection against more capable adversaries. Organisations are advised to implement all eight strategies to the same target level before moving higher.
Is the Essential Eight mandatory?
It is mandatory for many Australian non-corporate Commonwealth entities and is increasingly expected of their suppliers. For other organisations it is a strongly recommended baseline.
How does Komply help with the Essential Eight?
Komply maps all eight strategies at each maturity level (24 requirements) to ISO 27001. You track your target level and evidence in one place.
Do ISO 27001 once. Prove Essential Eight too.
Komply maps 14 frameworks and 1,100+ controls into one control set. Start with a free gap assessment.