Understanding the Essential Eight Maturity Levels (ML1, ML2, ML3)
The Australian Signals Directorate defines three maturity levels for the Essential Eight framework. ML1 protects against opportunistic attackers using common malware. ML2 mitigates targeted attacks from adversaries who invest time to bypass standard defences. ML3 defends against highly capable adversaries utilizing advanced, bespoke tools.
Small businesses often start at ML1 to establish basic hygiene. Moving to ML2 introduces structural constraints that actively disrupt adversary tradecraft, such as enforcing multi-factor authentication across all remote access services. Organizations operating at ML3 typically include government agencies or critical infrastructure providers handling highly sensitive classified data.
| Maturity Level | Target Adversary | Primary Business Fit |
|---|---|---|
| Level 1 (ML1) | Opportunistic (phishing, commodity ransomware) | Micro-businesses, low-risk retail |
| Level 2 (ML2) | Targeted (spear-phishing, credential theft) | B2B services, Defence supply chain SMEs |
| Level 3 (ML3) | Advanced Persistent Threats (state-sponsored) | Federal government, critical infrastructure |
Why ML2 is a Crucial Target for Australian Small Businesses
Achieving ML2 compliance directly secures commercial opportunities within the Australian government and defence sectors. Procurement frameworks increasingly mandate ML2 as a baseline for vendors handling official information. Without demonstrable ML2 compliance, small businesses risk losing existing contracts and failing vendor risk assessments for new tenders.
Beyond compliance, ML2 effectively neutralizes the most common attack vectors used against Australian small businesses. By enforcing application control and restricting administrative privileges, organizations drastically reduce the blast radius of a successful phishing attempt. You can review the primary source documentation on the ACSC Essential Eight guidelines for specific adversary models. If your organization struggles to map these requirements to internal systems, our Essential Eight Maturity Assessments provide a clear gap analysis.
Detailed Requirements for Each Essential Eight Control at ML2
Reaching ML2 requires strict adherence to specific technical configurations across all eight mitigation strategies. It demands a shift from manual administration to automated enforcement. Below are the precise technical thresholds an organization must meet to satisfy the ML2 requirements.
| Mitigation Strategy | ML2 Technical Requirement |
|---|---|
| Application Control | Execution of executables, software libraries, scripts, and installers is restricted to an approved set. Microsoft AppLocker or Windows Defender Application Control must be enforced on all workstations. |
| Patch Applications | Extreme risk vulnerabilities in applications must be patched within 48 hours. Other vulnerabilities require patching within two weeks. |
| Configure Microsoft Office Macros | Microsoft Office macros must be blocked from executing files downloaded from the internet. Only digitally signed macros from trusted publishers are permitted. |
| User Application Hardening | Web browsers cannot process Java from the internet. Unnecessary features in Microsoft Office must be explicitly disabled. |
| Restrict Administrative Privileges | Privileged accounts are strictly separated from everyday email and web browsing activities. Access to privileged accounts must be automatically logged and audited. |
| Patch Operating Systems | Operating system updates for critical vulnerabilities must be applied within 48 hours. Unsupported operating systems must be decommissioned entirely. |
| Multi-Factor Authentication | MFA is enforced for all users authenticating to internet-facing services and all remote access solutions. SMS-based MFA does not meet the strict phishing-resistant requirements necessary for higher assurance. |
| Regular Backups | Data backups must be performed daily and stored offline or in an immutable cloud repository. Backup restoration must be tested and validated at least quarterly. |
Practical Strategies and Cost-Effective Tools for ML2 Implementation
Implementing ML2 requires leveraging existing technology stacks rather than purchasing entirely new security appliances. Small businesses using Microsoft 365 Business Premium already possess the licensing required to achieve ML2 across identity, device management, and application control. Centralizing configuration management through a unified platform reduces both capital expenditure and operational overhead.
Begin by deploying Microsoft Intune to enforce patch management and application control policies automatically. For example, use Intune OMA-URI settings to deploy AppLocker policies that strictly block unapproved executables in user profiles. Next, configure Conditional Access policies within Entra ID to mandate phishing-resistant MFA (like FIDO2 security keys or Microsoft Authenticator number matching) and explicitly block legacy authentication protocols across all internal and external authentications. For businesses lacking dedicated internal IT staff, engaging Virtual CISO services ensures architectural decisions align directly with ASD specifications without the cost of a full-time executive.
Common Pitfalls When Aiming for ML2 and How to Avoid Them
Organizations frequently fail ML2 assessments because they rely on written policies rather than verifiable technical enforcement. Assessors do not accept intention; they require audit logs proving controls operate continuously. Another common failure point is implementing MFA solely for external access while leaving internal administrative interfaces secured only by passwords.
To avoid these pitfalls, conduct quarterly internal audits of your firewall rules and access control lists. Ensure your backup strategy includes absolute immutability, preventing even a compromised global administrator account from deleting archives. Document your exclusions meticulously, as any system lacking an ML2 control requires a formally accepted risk management plan.
Resources and Next Steps for Maintaining ML2 Compliance
Maintaining ML2 is an operational commitment requiring continuous monitoring and immediate response to new vulnerabilities. Compliance drifts quickly when new devices are provisioned outside standard operating environments. Establish an automated reporting cadence to track patch compliance and unauthorized software execution attempts.
Review the official ACSC resources monthly for updates to the Essential Eight maturity model. Schedule an independent assessment annually to validate that your controls remain effective against evolving adversary tradecraft. Achieving ML2 is not a one-off project; it is a permanent shift in how your organization manages identity, devices, and operational risk.
Frequently Asked Questions
What is Essential Eight Maturity Level 2?
Maturity Level 2 of the Essential Eight is a cyber security baseline established by the Australian Signals Directorate. It requires organisations to implement specific controls to mitigate targeted cyber attacks from adversaries.
Is Essential Eight ML2 mandatory for Australian small businesses?
It is not legally mandatory for all small businesses. However, many government contracts, defence industry supply chains, and large enterprise partners now strictly require ML2 compliance as a condition of doing business.
How much does it cost to implement Essential Eight ML2?
Costs vary based on existing infrastructure and organisation size. Small businesses typically spend between $5,000 and $20,000 on software licensing, configuration, and consulting to reach ML2 compliance.