Essential Eight, at the maturity level you actually need.

All eight mitigation strategies across maturity levels one to three — 149 controls, with evidence attached.

A maturity model, not a checklist

The ACSC Essential Eight is eight mitigation strategies, each assessed at one of three maturity levels. That structure is its strength and the reason it trips people up: claiming Maturity Level Two means meeting every requirement at that level across all eight strategies, not averaging out.

For Australian government entities and their suppliers it is effectively mandatory, and the assessment expects evidence rather than assertion.

OpenGRC includes the Essential Eight Maturity Model bundle — 149 controls spanning all three levels — on every plan.

Built for maturity levels

Know which level you are actually at.

Maturity tracked per control

Maturity tracked per control

Implementations carry maturity, so you can see where a single unmet requirement is holding an entire strategy at a lower level — which is usually the thing nobody notices until assessment.

Patch windows that chase themselves

Patch windows that chase themselves

Two of the eight strategies are patching, with time windows measured in days. Workflow automation and recurring assessment cadence handle the chasing.

Evidence for assessment

Evidence for assessment

Each control carries implementation detail, test procedures and evidence, and assessors get a time-bounded portal rather than a shared folder.

The eight mitigation strategies

StrategyPurpose
Application controlPrevent execution of unapproved programs
Patch applicationsClose known vulnerabilities within defined windows
Configure Microsoft Office macro settingsBlock a common delivery mechanism
User application hardeningReduce attack surface in browsers and productivity tools
Restrict administrative privilegesLimit the damage of a compromised account
Patch operating systemsClose known vulnerabilities within defined windows
Multi-factor authenticationMake stolen credentials insufficient
Regular backupsRecover from ransomware and destructive incidents

Each strategy is assessed at Maturity Level One, Two or Three. The bundle covers all three, so you can target a level and see exactly what closing the gap requires.

Essential Eight questions

Which maturity levels are included?

All three. The bundle holds 149 controls spanning Maturity Level One, Two and Three across the eight strategies.

Is the Essential Eight mandatory?

Can we target Level Two on some strategies and Level One on others?

Does it work alongside ISO 27001?