Essential Eight Maturity Level 2 has quietly become the price of doing business in Australia. It is not law for most small and medium businesses, but it is now the level cyber insurers ask you to prove, the level government buyers specify in tender documents, and the level larger clients check before they sign. Most Australian SMBs are sitting at Level 0 or Level 1 and do not know it.
This guide explains what Maturity Level 2 actually requires, control by control, what it realistically costs, and how long it takes to get there without hiring a security team.
What the Essential Eight actually is
The Essential Eight is a set of eight mitigation strategies published by the Australian Signals Directorate through the Australian Cyber Security Centre. It exists because the ASD found that a small number of controls, done properly, stop the overwhelming majority of intrusions they investigate.
Each of the eight controls is assessed against four maturity levels:
- Maturity Level 0 — the control is not in place, or has significant weaknesses
- Maturity Level 1 — protects against commodity attacks using widely available tooling
- Maturity Level 2 — protects against attackers willing to invest time and effort in a specific target
- Maturity Level 3 — protects against adaptive, well-resourced attackers
The critical detail most businesses miss: your maturity level is the lowest score across all eight controls. Seven controls at Level 2 and one at Level 0 means you are at Level 0. There is no partial credit, and this is where most self-assessments fall apart.
Why Level 2 is the target in 2026
Level 2 is where the commercial pressure sits. Australia’s 2026–2028 Cyber Security Strategy positions Maturity Level 2 as the recommended baseline across sectors, with Level 3 reserved for critical infrastructure. In practice, three forces are pushing Australian SMBs toward it:
Cyber insurance. Underwriters now routinely require documented evidence of MFA, tested backups and patching cadence before they will quote or renew. Premiums increasingly reflect demonstrated maturity rather than a signed declaration.
Government and enterprise procurement. Federal and state contracts specify minimum maturity levels. Large private buyers increasingly cascade the same requirement down their supply chain.
Due diligence. If you handle client data, your clients’ auditors will eventually ask. The Australian Cyber Security Centre puts the average cost of a cybercrime incident for a small business at over $46,000 — and that figure excludes the contracts you lose afterwards.
The eight controls at Maturity Level 2
Here is what Level 2 asks of each control in plain terms. Verify the current wording against the ASD’s published maturity model before a formal assessment, as the definitions are periodically revised.
1. Patch applications
Internet-facing services need patching within two weeks of a patch being released, and within 48 hours where a working exploit exists. Other applications follow a one-month cadence. You also need an automated method of discovering what is installed — you cannot patch software you do not know about.
2. Patch operating systems
The same cadence applies to operating systems on workstations, servers and network devices. Operating systems that are no longer vendor-supported must be replaced. This is the control that catches businesses still running old server hardware.
3. Multi-factor authentication
MFA is required for remote access, for all users of internet-facing services that handle your data, and for privileged accounts. At Level 2 it must also be applied to important data repositories, and authentication events need logging. Push notifications and app-based codes generally satisfy Level 2; SMS is weak and increasingly rejected.
4. Restrict administrative privileges
Privileged accounts must be separate from day-to-day accounts, and must not be able to browse the web, access email, or open documents from the internet. Access requests need validation when first requested, and privileged access must be reviewed and disabled when no longer needed. This is the single most commonly failed control in SMB assessments.
5. Application control
Only approved executables, scripts, installers and libraries should run — on workstations and internet-facing servers. Level 2 also requires blocklisting rules published by Microsoft to be implemented, and allowed and blocked execution events to be logged.
6. Restrict Microsoft Office macros
Macros must be disabled for users without a demonstrated business need. Macros from the internet must be blocked, macro security settings must be locked so users cannot change them, and macro execution events must be logged.
7. User application hardening
Web browsers must not process Java from the internet or web advertisements. Internet Explorer 11 must be disabled or removed. Level 2 extends hardening to Office and PDF readers, blocks Office from creating child processes, and requires the ASD’s hardening guidance to be applied.
8. Regular backups
Backups must be performed and retained in line with your actual business continuity requirements, and restoration must be tested — not assumed. Critically, unprivileged accounts and non-backup administrators must be unable to modify or delete backups. Ransomware operators target backups first, and this requirement exists precisely because of that.
What it realistically costs
Cost splits into tooling and labour. For a typical Australian business of 20 to 50 staff already running Microsoft 365, the licensing uplift is usually modest because much of what Level 2 needs is already included in Business Premium and simply switched off.
| Cost area | Typical range | Notes |
| Gap assessment | $2,000 – $6,000 once-off | Evidence-based, control by control |
| Licensing uplift | $0 – $15 per user / month | Often $0 if already on Business Premium |
| Remediation project | $8,000 – $30,000 once-off | Driven by application control and admin restructure |
| Ongoing management | $25 – $60 per user / month | Patching cadence, logging, backup testing |
The variable that moves the number most is application control. If your team runs a narrow, predictable set of software, it is straightforward. If everyone installs their own tools, expect a longer and more contested rollout.
A realistic timeline
Most businesses reach Level 2 in three to six months. Attempting all eight controls simultaneously is the usual reason projects stall.
- Weeks 1–3: assess. Score all eight controls honestly against the current maturity model. Document evidence, not intentions.
- Weeks 4–8: quick wins. MFA, macro settings, browser hardening and backup permissions. These are largely configuration changes with low disruption.
- Weeks 9–16: patching discipline. Establish asset discovery, then hold the two-week and 48-hour cadences. This is a process change more than a tooling change.
- Weeks 12–24: privilege and application control. Separate privileged accounts, remove standing admin rights, then phase application control in audit mode before enforcing.
- Ongoing: evidence. Logging, quarterly restore tests and a reassessment every six months.
Where Australian SMBs most often fail
Across assessments, the same four gaps recur:
- Standing local admin rights. Convenient, and fatal to Control 4. Removing them is unpopular and non-negotiable.
- Backups that have never been restored. A backup job with a green tick is not a tested backup.
- Patching internet-facing services late. The 48-hour window for known exploits is tight and requires a real process, not goodwill.
- No logging. Level 2 requires evidence. Controls working without records still score poorly in assessment.
Getting there without a security team
Very few Australian SMBs can justify a full-time security hire, and Level 2 does not require one. What it requires is consistent process — patching on a cadence, privileges reviewed, restores tested, events logged.
That consistency is exactly what a managed provider is for. At The Anand Technologies we handle Essential Eight uplift as part of our managed IT services, combining advanced endpoint protection with the patching, backup and privilege discipline the framework demands. Where a business needs a roadmap before committing, our IT consulting and strategy service starts with an evidence-based gap assessment so you know exactly which controls are costing you the score.
Frequently asked questions
Is Essential Eight compliance mandatory in Australia?
It is mandatory for non-corporate Commonwealth entities. For most private businesses it is not legally required, but it is increasingly required commercially — by cyber insurers before they will quote, by government buyers in tender conditions, and by enterprise clients through supply chain due diligence.
What maturity level should a small business aim for?
Maturity Level 2 is the practical target for most Australian SMBs in 2026. It satisfies the majority of cyber insurance questionnaires and procurement requirements. Level 3 is aimed at critical infrastructure and organisations facing targeted, well-resourced attackers.
How long does it take to reach Maturity Level 2?
Three to six months is typical for a business of 20 to 50 staff starting from Level 0 or 1. Configuration controls such as MFA and macro settings move quickly; application control and administrative privilege restructuring take longest because they change how people work.
Can we self-assess our Essential Eight maturity?
You can, and it is a sensible starting point. Be aware that self-assessments commonly overstate maturity because they score intent rather than evidence. Insurers and government buyers increasingly ask for independent assessment, so document evidence for every control from the outset.
Does Microsoft 365 alone make us Essential Eight compliant?
No. Microsoft 365 Business Premium includes many of the capabilities Level 2 needs — Conditional Access, Defender, macro controls — but they are not enabled by default and licensing is not the same as configuration. The framework also covers backups, patching cadence and application control across your whole environment, not just your productivity suite.
The bottom line
Essential Eight Maturity Level 2 is achievable for an Australian SMB on a normal budget and a normal timeline. What defeats most businesses is not cost — it is treating it as a project with an end date rather than a set of operating habits. Start with an honest assessment, fix the configuration controls first, then commit to the patching and privilege discipline that Level 2 really measures.
If you would like a straight answer on where your business currently scores, get in touch for an Essential Eight gap assessment.