Step Fwd IT Logo

What Does Essential Eight Maturity Level 2 Actually Mean?

Anonymous | March 25, 2026

Quick Answer

Essential Eight Maturity Level 2 means your cybersecurity controls are consistently implemented, enforced, and evidenced across your organisation.

This includes stronger multi-factor authentication, faster patching timeframes, tighter control of administrative privileges, and secure backup practices.

For most 20–100 user organisations, reaching Level 2 is typically a structured uplift project that takes several months, not a quick technical fix.

If you have been told your business needs to reach Essential Eight Maturity Level 2, you are not alone.

The confusion is understandable.

Most guidance is written for security professionals, not business leaders.

This article explains what Level 2 actually means, what assessors look for, and how organisations typically achieve it in practice.

A note on what's changing

In June 2026, the Australian Signals Directorate announced that the Essential Eight will gradually move toward a broader "Essentials" series. The consultation period for the first chapter, Essentials for enterprise IT, closed on 12 July 2026.

For now, the Essential Eight remains an important cyber security baseline for Australian organisations, and it is still widely referenced in contracts, audits, insurance conversations and procurement requirements.

The key message is simple: work already done on the Essential Eight is not wasted. Controls such as multi-factor authentication, patching, application control and backups remain practical steps that support stronger cyber resilience as the guidance evolves.

Step Fwd IT is tracking the transition and will help clients understand which changes are needed, what stays relevant, and what action is required as the new guidance becomes clearer.

What Is the Essential Eight?

The Essential Eight is a baseline set of cybersecurity strategies developed by the Australian Signals Directorate to help organisations reduce the likelihood and impact of cyber attacks.

It focuses on eight key areas:

  • application control
  • patch applications
  • patch operating systems
  • multi-factor authentication
  • restricting administrative privileges
  • restricting Microsoft Office macros
  • user application hardening
  • regular backups

Each of these controls is assessed using a maturity model, which defines four levels of implementation from Level 0 to Level 3.

The model is designed to help organisations progressively strengthen their security posture.

If you want a broader overview, it may help to explore Essential Eight explained for SMBs.

What Does Maturity Level 2 Actually Mean?

Maturity Level 2 means your security controls are:

  • consistently implemented
  • actively managed and monitored
  • designed to stop common cyber attacks, not just accidental issues

In practical terms, it means your security works by default, not because someone remembers to apply it.

Controls are applied across the environment, exceptions are limited and documented, and there is evidence available to demonstrate that controls are working.

This is the point where security becomes structured and enforceable, not just assumed.

The Biggest Misconception About Level 2

One of the most common misunderstandings is: “We have the tools, so we must be compliant.”

This is not how assessments work.

For example:

  • MFA must be enforced consistently, not just enabled
  • administrative privileges must be tightly controlled
  • patching must follow defined timeframes and be verified
  • backups must be protected, not just exist

Assessors evaluate consistency and enforcement, not tool ownership.

What Changes Between Level 1 and Level 2?

The simplest way to understand the difference is:

Level 1 = basic cyber hygiene
Level 2 = controlled, enforced, and harder to bypass.

Multi-Factor Authentication

At Level 2, MFA is applied more broadly and securely.

Partial coverage or weaker implementations are no longer acceptable.

Patch Management

Critical vulnerabilities must be addressed quickly and consistently.

This includes applications, operating systems, and supporting components.

Administrative Privileges

Access to privileged accounts must be:

  • tightly controlled
  • documented regularly
  • regularly reviewed

Backup Security

Backups must be protected from unauthorised access or deletion, not just stored.

If you want to better understand this area, it may help to review backup and disaster recovery: what most businesses get wrong.

What Auditors and Assessors Look For

When organisations are assessed, the focus is typically on four key areas:

1. Clear Policies

Controls must be documented, approved, and current.

2. Technical Evidence

Reports, logs, and configurations must demonstrate that controls are active.

3. Consistency

Controls must apply across all users, devices, and systems.

4. Governance of Exceptions

Any gaps must be documented, approved, and regularly reviewed.

Without evidence, controls are treated as not implemented.

A Plain-English Checklist for Level 2 Readiness

For business leaders, these are the key questions to consider:

Identity and Access

  • Is MFA enforced consistently across users and systems?
  • Are privileged accounts tightly controlled?

Patch Management

  • Can you demonstrate that vulnerabilities are patched within the required timeframes?
  • Are unsupported systems still in use?

Endpoint Security

  • Are risky behaviours (such as macros) controlled?
  • Are users prevented from weakening security settings?

Backup and Recovery

  • Are backups protected from deletion or unauthorised access?
  • Can you prove recovery processes work?

Governance and Evidence

  • Are policies documented and current?
  • Can you produce evidence quickly if required?

How Long Does It Take to Reach Level 2?

For most 20-100 user organisations:

  • typically 3-6 months with a structured approach
  • longer if starting from unmanaged or inconsistent environments.

The biggest delays are usually caused by legacy systems, insufficient documentation, and unclear ownership, not by the technology itself.

Why Regulated Businesses Target Level 2

For many organisations, Level 2 remains a practical and achievable benchmark. It is still widely referenced in contracts, insurance requirements, audits and procurement processes. As ASD's guidance evolves towards the broader Essentials series, Level 2 is best viewed as a strong current baseline rather than a permanent end point.

It demonstrates that:

  • controls are actively managed
  • risks are understood
  • security is consistent
  • governance processes are in place

For a broader view of how this aligns with compliance, it may help to explore cybersecurity for regulated businesses.

What "Good" Looks Like

A business operating at Maturity Level 2 typically has:

  • consistent security settings across systems
  • controlled and monitored privileged access
  • structured patching processes
  • protected and tested backups
  • clear documentation and governance
  • the ability to produce evidence on demand

This is the difference between assuming security is in place and being able to demonstrate it.

Level 2 as a Structured Uplift

Reaching Level 2 should be viewed as part of an ongoing cyber security improvement journey, rather than a one-time project or a final destination.

It is a structured uplift that requires:

  • aligning controls to recognised cyber security guidance
  • implementing consistent processes
  • improving visibility and documentation
  • maintaining ongoing governance

Without structure, organisations often remain stuck between partial compliance and audit readiness.

This is where approaches such as The Fwd Steps process help ensure improvements are applied consistently.

Final Thoughts

Essential Eight Maturity Level 2 is not about perfection.

It is about demonstrating control, consistency, and intent.

For most organisations, the challenge is not understanding the guidance. It is implementing controls consistently, maintaining evidence, and demonstrating that they are working in practice. As ASD's cyber security guidance evolves, organisations that have established strong foundations today will be better positioned to adapt tomorrow.

Unsure Where You Currently Sit?

If your organisation has been asked about Essential Eight compliance but you are not confident where you stand, it may be worth reviewing your environment.

If you cannot clearly demonstrate your current maturity level, that is often the first indicator of risk.

Step Fwd IT provides Essential Eight and cyber baseline assessments to identify gaps, assess maturity, and define a practical path forward. We also help organisations prepare for the evolution of ASD's cyber security guidance as the Essentials series develops.

If you want a clearer view of your current position, you can request an Essential Eight Readiness Assessment or explore Managed IT Services.

Related Insights

chevron-downchevron-leftchevron-right