Essential Eight Maturity Calculator
Understand where your organisation stands against the Australian Government's Essential Eight mitigation strategies. This free self-assessment tool provides an indicative maturity level across all eight strategies.
All calculations happen in your browser. No data is sent to our servers.
How It Works
Answer Questions
For each of the 8 strategies, answer 4 yes/no questions progressing from baseline to advanced controls.
Get Your Score
Your maturity level per strategy is the highest consecutive level where you answered "Yes".
Overall Level
Your overall maturity is the lowest level across all 8 strategies, reflecting the holistic approach.
| Maturity Level | Description |
|---|---|
| ML0 | Not aligned. Weaknesses exist that could be exploited. |
| ML1 | Partly aligned. Mitigates commodity-level threats from opportunistic adversaries. |
| ML2 | Mostly aligned. Mitigates adversaries with moderate capability targeting your organisation. |
| ML3 | Fully aligned. Mitigates sophisticated adversaries with advanced tradecraft. |
Self-Assessment
Answer all 32 questions below, then click "Calculate Maturity" to see your results.
Answer all 32 questions to enable calculation
Your Results
Overall Maturity Level
| Strategy | Q1 | Q2 | Q3 | Q4 | Level |
|---|
Maturity Level 0
Significant gaps exist. Controls are absent or insufficient. Immediate action is recommended. Consider engaging a professional assessor.
Maturity Level 1
Baseline controls in place. Protected against commodity-level threats. Review ML2 requirements and plan your uplift.
Maturity Level 2
Enhanced controls in place. Recommended baseline for most Australian Government entities. Consider ML3 for high-value targets.
Maturity Level 3
Advanced controls in place. Protected against sophisticated adversaries. Maintain posture through regular validation and monitoring.
Limitations of Self-Assessment
This tool provides a directional understanding of your Essential Eight maturity. It is not a substitute for a professional assessment.
Self-reported answers may not accurately reflect your actual security posture
Evidence verification is not performed -- a professional assessment validates controls through testing
Nuances and exceptions in the ISM controls are simplified for accessibility
Organisational context (threat profile, data sensitivity, regulatory requirements) is not factored in
Ready for a Professional Assessment?
Our assessors hold current IRAP endorsements and have deep experience with the Essential Eight across Commonwealth, Defence, and critical infrastructure organisations.