Essential Eight Maturity Calculator
Understand where your organisation stands against the Australian Government's Essential Eight mitigation strategies. This free self-assessment tool provides an indicative maturity level across all eight strategies.
All calculations happen in your browser. No data is sent to our servers.
How It Works
Answer Questions
For each of the 8 strategies, answer 4 yes/no questions progressing from baseline to advanced controls.
Get Your Score
Your maturity level per strategy is the highest consecutive level where you answered "Yes".
Overall Level
Your overall maturity is the lowest level across all 8 strategies, reflecting the holistic approach.
| Maturity Level | Description |
|---|---|
| ML0 | Not aligned. Weaknesses exist that could be exploited. |
| ML1 | Partly aligned. Mitigates commodity-level threats from opportunistic adversaries. |
| ML2 | Mostly aligned. Mitigates adversaries with moderate capability targeting your organisation. |
| ML3 | Fully aligned. Mitigates sophisticated adversaries with advanced tradecraft. |
Self-Assessment Wizard
Complete each strategy step-by-step. Rate how well each control is implemented.
Application Control
Prevents the execution of unapproved or malicious programs on workstations and servers.
Does your organisation restrict the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications, and control panel applets on workstations to an approved set?
Are application control rules applied to both workstations and internet-facing servers, with rules validated on an annual or more frequent basis?
Are Microsoft's recommended application blocklist and recommended driver blocklist implemented, and are application control rules validated at least every six months?
Does your organisation's application control cover all user-accessible locations including temporary folders, and are allowed and blocked execution events centrally logged and monitored?
Your Results
Overall Maturity Level
Strategy Breakdown
| Strategy | Q1 | Q2 | Q3 | Q4 | Level |
|---|
Maturity Level 0
Significant gaps exist. Controls are absent or insufficient. Immediate action is recommended. Consider engaging a professional assessor.
Maturity Level 1
Baseline controls in place. Protected against commodity-level threats. Review ML2 requirements and plan your uplift.
Maturity Level 2
Enhanced controls in place. Recommended baseline for most Australian Government entities. Consider ML3 for high-value targets.
Maturity Level 3
Advanced controls in place. Protected against sophisticated adversaries. Maintain posture through regular validation and monitoring.
Limitations of Self-Assessment
This tool provides a directional understanding of your Essential Eight maturity. It is not a substitute for a professional assessment.
Self-reported answers may not accurately reflect your actual security posture
Evidence verification is not performed -- a professional assessment validates controls through testing
Nuances and exceptions in the ISM controls are simplified for accessibility
Organisational context (threat profile, data sensitivity, regulatory requirements) is not factored in
Ready for a Professional Assessment?
Our assessors hold current IRAP endorsements and have deep experience with the Essential Eight across Commonwealth, Defence, and critical infrastructure organisations.