Essential Eight Maturity Calculator

Understand where your organisation stands against the Australian Government's Essential Eight mitigation strategies. This free self-assessment tool provides an indicative maturity level across all eight strategies.

All calculations happen in your browser. No data is sent to our servers.

How It Works

1

Answer Questions

For each of the 8 strategies, answer 4 yes/no questions progressing from baseline to advanced controls.

2

Get Your Score

Your maturity level per strategy is the highest consecutive level where you answered "Yes".

3

Overall Level

Your overall maturity is the lowest level across all 8 strategies, reflecting the holistic approach.

Maturity Level Description
ML0 Not aligned. Weaknesses exist that could be exploited.
ML1 Partly aligned. Mitigates commodity-level threats from opportunistic adversaries.
ML2 Mostly aligned. Mitigates adversaries with moderate capability targeting your organisation.
ML3 Fully aligned. Mitigates sophisticated adversaries with advanced tradecraft.

Self-Assessment Wizard

Complete each strategy step-by-step. Rate how well each control is implemented.

Strategy 1 of 8 0% complete
1
2
3
4
5
6
7
8
1

Application Control

Prevents the execution of unapproved or malicious programs on workstations and servers.

ML0 to ML1

Does your organisation restrict the execution of executables, software libraries, scripts, installers, compiled HTML, HTML applications, and control panel applets on workstations to an approved set?

ML1 to ML2

Are application control rules applied to both workstations and internet-facing servers, with rules validated on an annual or more frequent basis?

ML2 to ML3

Are Microsoft's recommended application blocklist and recommended driver blocklist implemented, and are application control rules validated at least every six months?

ML3 Validation

Does your organisation's application control cover all user-accessible locations including temporary folders, and are allowed and blocked execution events centrally logged and monitored?

1 / 8

Ready for a Professional Assessment?

Our assessors hold current IRAP endorsements and have deep experience with the Essential Eight across Commonwealth, Defence, and critical infrastructure organisations.

Evidence-based assessments with full ISM control mapping
Gap analysis with prioritised remediation roadmaps
Uplift support to reach your target maturity level
Board-ready reporting that translates findings into business risk
Get a Professional Assessment

Frequently Asked Questions

Is this tool free?
Yes. The self-assessment calculator is completely free with no registration required.
Will my answers be stored?
No. All calculations happen in your browser. No data is sent to our servers.
Which maturity level should my organisation target?
Organisations are recommended to implement a consistent maturity level across all eight strategies based on their threat profile. Most Australian Government entities are expected to achieve at least ML2. Critical infrastructure operators should consider ML3.
How often should I reassess?
We recommend reassessing quarterly, or whenever significant changes occur to your IT environment, threat landscape, or regulatory requirements.