Essential Eight Maturity Calculator

Understand where your organisation stands against the Australian Government's Essential Eight mitigation strategies. This free self-assessment tool provides an indicative maturity level across all eight strategies.

All calculations happen in your browser. No data is sent to our servers.

How It Works

1

Answer Questions

For each of the 8 strategies, answer 4 yes/no questions progressing from baseline to advanced controls.

2

Get Your Score

Your maturity level per strategy is the highest consecutive level where you answered "Yes".

3

Overall Level

Your overall maturity is the lowest level across all 8 strategies, reflecting the holistic approach.

Maturity Level Description
ML0 Not aligned. Weaknesses exist that could be exploited.
ML1 Partly aligned. Mitigates commodity-level threats from opportunistic adversaries.
ML2 Mostly aligned. Mitigates adversaries with moderate capability targeting your organisation.
ML3 Fully aligned. Mitigates sophisticated adversaries with advanced tradecraft.

Self-Assessment

Answer all 32 questions below, then click "Calculate Maturity" to see your results.

Progress 0 of 32 answered

Answer all 32 questions to enable calculation

Ready for a Professional Assessment?

Our assessors hold current IRAP endorsements and have deep experience with the Essential Eight across Commonwealth, Defence, and critical infrastructure organisations.

Evidence-based assessments with full ISM control mapping
Gap analysis with prioritised remediation roadmaps
Uplift support to reach your target maturity level
Board-ready reporting that translates findings into business risk
Get a Professional Assessment

Frequently Asked Questions

Is this tool free?
Yes. The self-assessment calculator is completely free with no registration required.
Will my answers be stored?
No. All calculations happen in your browser. No data is sent to our servers.
Which maturity level should my organisation target?
Organisations are recommended to implement a consistent maturity level across all eight strategies based on their threat profile. Most Australian Government entities are expected to achieve at least ML2. Critical infrastructure operators should consider ML3.
How often should I reassess?
We recommend reassessing quarterly, or whenever significant changes occur to your IT environment, threat landscape, or regulatory requirements.