Essential Eight Maturity Level 2 Checklist for Australian Companies

The Essential Eight was once thought of as a federal government framework — useful for Commonwealth agencies and the contractors supplying them, but not directly relevant to a 50-person professional services firm. That framing no longer holds. Through 2024 and 2025 the Essential Eight became the de facto baseline for Australian commercial cybersecurity: federal procurement requires it, customer due diligence questionnaires reference it, and board-level conversations now use its language.

The framework defines three maturity levels. Maturity Level 1 gets an organisation started but stops well short of meaningful adversary resistance. Maturity Level 3 is engineered for organisations facing targeted state-level threats — and rightly costs commensurately. For most Australian SMBs, Maturity Level 2 is the realistic and worthwhile target: practical security that materially reduces risk, without Level 3’s operational overhead.

This article is the Essential Eight Maturity Level 2 checklist an SMB IT team can take into a planning meeting today.

Why ML2 Is the Right Target for Most Australian SMBs

The temptation when starting Essential Eight work is to aim either too low or too high. Maturity Level 1 looks attractive because it’s achievable in weeks — but it provides limited resistance against any attacker with motivation and basic tooling. The controls at ML1 are inconsistent in coverage and largely reactive; they catch known threats but don’t fundamentally change the organisation’s posture. SMBs reaching ML1 and stopping often discover that their cyber insurance underwriters, government customers, and audit findings don’t actually treat ML1 as adequate.

Maturity Level 3 is the opposite problem. It’s designed for organisations facing adaptive, well-resourced adversaries — state-level actors, organised crime running multi-month campaigns, supply chain compromises targeted specifically at the organisation. The controls at ML3 demand sustained operational discipline: application control with comprehensive exclusion management, patch windows measured in hours not days, multi-factor authentication that’s phishing-resistant across the entire user base. Most Australian SMBs don’t face the threats that justify ML3’s running cost.

ASD Essential Eight ML2 sits where most Australian mid-market needs are: meaningful resistance against the threats the organisation actually faces. ML2 controls assume the attacker has effort and tooling but isn’t running a bespoke campaign — which describes the ransomware-as-a-service ecosystem that targets SMBs today. ML2 is the level cyber insurance underwriters increasingly expect, federal supply chain conversations treat as credible, and competitor due diligence questionnaires accept.

The Eight Strategies — A 60-Second Refresher

The Essential Eight comprises eight mitigation strategies that the Australian Signals Directorate has identified as the most effective baseline controls against the most common attack patterns. The eight strategies, in order:

  • Application control
  • Patch applications
  • Configure Microsoft Office macro settings
  • User application hardening
  • Restrict administrative privileges
  • Patch operating systems
  • Multi-factor authentication
  • Regular backups

Each strategy has specific implementation criteria at each maturity level. The remainder of this guide focuses on what Maturity Level 2 looks like in practice for an Australian SMB — what to implement, what to measure, and where teams typically stall.

ML2 Implementation Checklist by Strategy

3.1 Application Control

At ML2, application control moves from advisory to enforced. Only approved applications, scripts, libraries, and installers can execute on workstations and servers.

  • Allowlisting deployed across all workstations and servers (not just servers).
  • Allowlist managed centrally with a documented exception process.
  • Microsoft’s Recommended Block Rules implemented to prevent commonly abused executables.
  • Driver execution restricted to vendor-signed and known-good drivers.
  • Allowlist event logs centralised and reviewed.

3.2 Patch Applications

ML2 expects rapid patching of internet-facing and high-risk applications.

  • Internet-facing services patched within 48 hours of vendor critical patch release.
  • Other applications patched within two weeks.
  • Vulnerability scanning runs at least weekly.
  • Unsupported applications removed or formally exempted with compensating controls.
  • Patch failures tracked and remediated within the same window.

3.3 Configure Microsoft Office Macro Settings

Macro abuse remains a primary delivery vector. ML2 demands targeted restriction, not just user warnings.

  • Macros disabled by default for users without a documented need.
  • Macros from the internet blocked entirely (Mark of the Web enforcement).
  • Macros allowed only when digitally signed by trusted publishers.
  • Macro activity logged and reviewed.
  • Users with macro exceptions documented with business justification and review date.

3.4 User Application Hardening

The browser and document viewer are the highest-risk applications on most endpoints. ML2 hardens them deliberately.

  • Web browsers configured to block ads and untrusted Java content.
  • Internet Explorer mode disabled or restricted to documented legacy applications only.
  • PDF reader hardened — JavaScript disabled where not required.
  • .NET Framework 3.5 and below disabled.
  • Office applications configured to block child process creation.

3.5 Restrict Administrative Privileges

Standing administrative access is the single biggest preventable risk in most SMBs. ML2 requires separation and just-in-time elevation.

  • Privileged accounts separated from standard user accounts (no daily login as admin).
  • Privileged access workstations used for administrative tasks where practical.
  • Domain admin / Global admin access restricted to a small documented group.
  • Just-in-time elevation used in place of standing access where the tooling supports it.
  • Privileged access reviews conducted at least every six months.

For the endpoint-side controls that support privileged access protection in practice, SentinelOne Singularity’s Identity module handles credential-theft detection and lateral-movement signals.

3.6 Patch Operating Systems

ML2 patches operating systems on the same urgency-tiered basis as applications.

  • Internet-facing operating systems patched within 48 hours of vendor critical patch release.
  • Other operating systems patched within two weeks.
  • End-of-life operating systems removed from the environment.
  • Patch compliance reporting reviewed monthly.
  • Failed patches tracked to resolution.

3.7 Multi-Factor Authentication

MFA at ML2 expands beyond privileged accounts to cover the realistic attack surface.

  • MFA enforced for all users accessing internet-facing services.
  • MFA enforced for all privileged accounts on all systems.
  • MFA enforced for users accessing important data repositories.
  • SMS-based MFA being phased out in favour of authenticator apps or hardware tokens.
  • MFA bypass exceptions documented with business justification and review date.

For deeper background on the architectural direction Australian organisations are moving towards, see our Zero Trust security guide.

3.8 Regular Backups

ML2 backups are tested, isolated, and restorable on a realistic timeline.

  • Daily backups of important data, applications, and configuration.
  • Backup retention at least one month for daily backups.
  • At least one backup copy offline or immutable.
  • Restore tests conducted at least quarterly with documented results.
  • Recovery time objectives defined and measured against actual restore performance.

Common SMB Gaps That Block ML2

Three patterns appear repeatedly when Australian SMBs assess their actual maturity against ML2 expectations.

First, the tooling-versus-process gap. An organisation buys an application control platform, deploys it in audit-only mode, and assumes the box is ticked. Essential Eight implementation in Australia at the ML2 level requires enforced allowlisting with a managed exception process — not just monitoring. Having the tool is the entry ticket, not the destination.

Second, the IT-team-of-one bottleneck. Patch windows, allowlist management, MFA enforcement, and quarterly restore tests all require sustained operational attention. An SMB with a single IT manager who is also handling helpdesk, procurement, and end-user training can’t realistically run those controls at ML2 cadence. The controls slip silently and the maturity claim becomes aspirational rather than actual.

Third, the assessment gap. Most SMBs don’t have an objective baseline of where they actually sit today, which makes “reach ML2” untethered. The first move is a current-state assessment against the framework — including evidence of control operation, not just control existence.

For SMBs without the in-house capacity to run ML2 controls daily, an IT outsourcing arrangement covers the operational tax that makes the difference between aspirational and achieved.

Frequently Asked Questions

Is Maturity Level 2 mandatory for Australian SMBs?

Not universally — but increasingly required by customers, insurers, and federal supply chain conversations. ML2 has shifted from “good security” to “table stakes” for organisations selling to government, financial services, healthcare, and supply chains where due diligence matters.

How long does ML2 implementation typically take for an SMB?

Realistic timelines range from four to nine months, depending on starting position. Organisations already running modern endpoint management, MFA, and centralised patching can reach ML2 inside six months. Greenfield environments take longer because the baseline tooling needs to be in place first.

Does Microsoft 365 cover most of these strategies?

The right Microsoft 365 tier covers a meaningful subset — particularly MFA, macro settings, browser hardening, and patching for managed devices. It doesn’t cover application control, restore testing, or the operational discipline around the controls. Microsoft 365 is a starting point, not a complete solution.

How is ML2 maturity assessed?

Through evidence-based assessment against the framework’s specific criteria for each strategy. The assessment looks at control operation across the organisation, not just whether the control exists somewhere in the environment.

Build the Roadmap to Real ML2 Maturity

Reaching Essential Eight Maturity Level 2 isn’t a tooling project — it’s an operating discipline. The eight strategies need running, measuring, and updating as the threat landscape shifts. ANP Technology helps Australian SMBs scope where they sit today, build a practical roadmap to ML2, and operate the controls that need running so the maturity rating is real, not aspirational.

Talk to ANP Technology about your Essential Eight roadmap →