Essential Eight Maturity Level 2 Guide
Practical considerations for organisations targeting ML2 across the complete assessment boundary.
This guide summarises implementation themes rather than reproducing the control requirements. Always use the current ASD Essential Eight Maturity Model when designing or assessing controls.
What Is Essential Eight Maturity Level 2?
ML2 builds on ML1 and focuses on malicious actors willing to invest more effort in targeting and use more effective tradecraft. It requires stronger coverage, timeliness, control over privileged activity and resistance to bypass. The target should be chosen using risk and applicable obligations.
Application Control at ML2
Organisations need reliable control over executable files and relevant content, supported by maintained rules and coverage across the assessed workstations. Assessment evidence should show effective enforcement, governance and handling of changes and exceptions.
Patch Applications at ML2
Teams need authoritative application visibility, processes to identify vulnerabilities and patch deployment that meets current ASD requirements. Evidence must reconcile assets, vulnerability information, deployment results and approved exceptions.
Microsoft Office Macro Settings at ML2
Macro controls should restrict untrusted sources, constrain who can change settings and support investigation of macro activity. Confirm that policy applies to the assessed users and devices rather than relying on a template configuration alone.
User Application Hardening at ML2
Security settings for browsers, Microsoft Office, PDF software and other user applications should reduce exposed functionality and prevent users weakening the controls. Validate policy application and exceptions on representative devices.
Restrict Administrative Privileges at ML2
Separate privileged and unprivileged activity, tightly control membership and access, and review administrative privileges regularly. Service accounts, emergency access and remote administration require the same evidence-based treatment as named administrator accounts.
Patch Operating Systems at ML2
Maintain an accurate operating-system inventory, identify vulnerabilities and deploy updates in line with current ASD requirements. Unsupported or unmanaged platforms should be visible, risk-assessed and addressed rather than silently excluded.
Multi-Factor Authentication at ML2
MFA coverage and factor strength must meet the current model for the relevant users, systems and services. Assess the real authentication path, including legacy protocols, recovery processes and privileged access—not only the identity-provider policy.
Regular Backups at ML2
Backups should cover important data, software and configuration, be protected from inappropriate access and be tested through restoration. Evidence needs to show successful operation and recovery, not just the existence of scheduled jobs.
Evidence Required for an ML2 Assessment
Useful evidence includes policy and configuration exports, device and application inventories, management-platform reports, vulnerability and patch records, identity and privilege data, MFA configuration, backup and restore results, exception records, logs, interviews and observed demonstrations.
Common ML2 Gaps
- Controls cover standard workstations but not the complete boundary
- Asset inventories do not reconcile with patch or application-control platforms
- Privileged accounts are used for routine activity
- MFA can be bypassed through legacy or recovery paths
- Policies are configured centrally but not verified on endpoints
- Unsupported applications or operating systems remain in production
- Backup success is monitored but restoration is not tested
- Exceptions lack an owner, expiry or compensating controls
Moving From ML1 to ML2
Establish a verified ML1 baseline, identify the incremental and cumulative ML2 requirements, map dependencies and sequence uplift work. Plan for operational ownership, reporting and reassessment—not only initial configuration.
Essential Eight ML2 Assessment
CCircle provides Essential Eight ML2 assessment and uplift services, including support from Essential Eight consultants in Canberra. See the full Essential Eight assessment process before defining scope.