Module 2 of StartCloud's Essential Eight for Australian Business pathway, in five short units with a knowledge check: the four ASD maturity levels (Zero through Three) defined by the attacker tradecraft each is built to stop, the commonly missed rule that you must reach the same level across all eight controls before moving higher, how to choose a target level based on how desirable a target you are and how badly a breach would hurt, how exceptions can be handled without failing a level, and a practical first-pass self-assessment.
Maturity Levels Without the Jargon
Four levels, not three
There are four maturity levels, not three. Level Zero is a real level and a lot of businesses are sitting in it without knowing.
Here is the part that makes the whole model click: the levels are not defined by how much effort you have put in. They are defined by the kind of attacker they are designed to stop. ASD builds each level around a level of tradecraft and targeting, so choosing a level is really choosing which sort of attacker you want to be resistant to.
Not a badge of shame, just an honest starting point. It means there are gaps in the overall security posture that, if exploited, could compromise your data or your systems. Most businesses that have never looked start here, including plenty who assume otherwise.
Aimed at attackers using commodity tradecraft that is widely available, for example a publicly available exploit against an unpatched online service, or logging in with credentials that were stolen, reused, brute forced or guessed. ASD describes these attackers as looking for any victim rather than a specific victim.
A modest step up. These attackers invest more time and better tools, actively target credentials with phishing, and use technical and social engineering techniques to get around weak multi-factor authentication. They are more selective about targets, and will hunt for accounts with special privileges.
Attackers who are much less reliant on public tools, who exploit weaknesses like old software or poor logging, and who can circumvent even stronger multi-factor authentication by stealing authentication token values. They pivot across a network, seek password hashes, and cover their tracks.
ASD makes a useful point here. The same attacker might use crude methods against one target and sophisticated ones against another, so trying to guess "who would attack us" is the wrong question. Ask instead what level of skill and persistence you want to be resistant to.
This is the single most commonly missed rule in the whole model, and getting it wrong makes a business sound much better prepared than it is.
ASD is explicit. The eight strategies are designed to complement each other and cover different threats, so you implement to achieve the same maturity level across all eight, then move up. Being brilliant at backups and hopeless at patching does not average out to something respectable. Your maturity is effectively set by your weakest of the eight.
Pouring effort into the two controls you find easiest, reaching Level Two on those, and describing the business as "working towards Level Two". Meanwhile application control has never been touched, so the honest answer is still Level Zero.
Get all eight to Level One first, even where that feels unambitious. A flat Level One across the board is genuinely stronger, and far easier to defend to an assessor, than a jagged profile with a couple of showpieces.
Real businesses have awkward corners: the legacy application that breaks when patched, the machine that cannot be locked down. ASD expects a risk-based approach. Keep exceptions few and narrow, use compensating controls, limit how many systems and users are affected, and document and approve each one through a proper process, then review them regularly. Handled that way, an exception does not automatically stop you meeting a maturity level.
ASD asks you to pick a target level suitable for your environment and work up to it. Two things drive that choice: how desirable a target you are, and how badly a breach would hurt, in terms of the confidentiality of your data and the availability and integrity of your systems.
Level One is built to stop attackers hunting for any victim rather than a specific one, which is precisely the traffic a typical Perth business faces. Automated scanning, reused passwords, unpatched services. Get all eight to Level One and you have removed yourself from the easy pile, which is most of the benefit for a fraction of the cost.
Worth considering if you hold sensitive client data, move significant money, sit in a supply chain that makes you a stepping stone, or a contract requires it. Level Two assumes attackers who will phish your people properly and try to work around weak multi-factor authentication, so it changes what counts as good enough MFA.
Level Three is demanding and expensive, and it is normally driven by a government directive, a regulator, or a contract rather than a business choosing it. ASD is also blunt that Level Three will not stop an attacker willing and able to invest enough time, money and effort. There is no level that makes you safe.
A business at a genuine, evidenced Level One is in far better shape than one that has spent two years reaching for Level Three and finished neither. Pick the level you will actually complete across all eight, get there, then reassess.
You cannot claim a level without checking, and checking is more straightforward than most people expect. The detailed requirements live in the maturity model itself: Appendices A through C set out what each of Levels One, Two and Three demand, control by control. Appendix D compares the levels side by side with the changes shown in bold, which is the fastest way to see what stepping up would actually cost you.
For a formal assessment, ASD publishes a separate Essential Eight assessment process guide. Module 8 of this pathway covers assessments and evidence properly, including the question everyone asks about whether you need to be certified.
- Take the eight controls one at a time and write down what you actually do today, not what you intend to do
- For each, decide honestly whether it is nothing, partial, or genuinely in place everywhere
- Anything partial is not that level yet. Partial is the most common self-assessment error
- Your overall position is your weakest control, not your average
- Write the gaps down with a rough cost and an owner. That list is now your plan
Our Essential Eight self-assessment checklist turns all of this into 24 plain-English questions you can work through in a sitting. No email required, and it prints cleanly if you would rather do it on paper with the team.
Open the free self-assessment checklistDo not be discouraged if that afternoon ends with Level Zero written at the bottom of the page. That is where most businesses genuinely start, and knowing it is the difference between a plan and a guess. The next four modules walk through the eight controls themselves, so you will know exactly what "in place" looks like for each one.
- cyber.gov.au: Essential Eight maturity model (Australian Signals Directorate)
- cyber.gov.au: Essential Eight explained
Maturity level descriptions checked against ASD guidance at the time of writing (August 2026). The model was first published in June 2017 and is updated regularly, so read the current version before committing to a target level or answering a tender.
Knowledge check
5 quick questions. Get 4 right and the module is yours.
1. How many maturity levels are there, and what does the lowest mean?
2. You are strong on backups and MFA but have never looked at application control. What is your maturity?
3. What kind of attacker is Maturity Level One designed to stop?
4. Why does Maturity Level Two change what counts as acceptable multi-factor authentication?
5. Your business has one legacy application that cannot be patched. Does that stop you meeting a maturity level?