Edition 2026.09 · Desk research from public vendor pages, last reviewed 29 September 2026

Essential Eight explained: the eight strategies, the maturity model and ISO 27001

Short answer

The Essential Eight is the set of eight mitigation strategies that the Australian Signals Directorate (ASD) describes as the most effective of its Strategies to mitigate cyber security incidents. It comes with a maturity model, first published in June 2017 and updated regularly since, and it is designed for internet-connected IT networks.

G-01

What are the eight strategies?

01

Patch applications

Apply security fixes to applications promptly, starting with internet-facing ones.

02

Patch operating systems

Apply security fixes to operating systems on workstations, servers and network devices.

03

Multi-factor authentication

Require more than one proof of identity, especially for remote access and privileged accounts.

04

Restrict administrative privileges

Limit who holds admin rights and what those accounts can do.

05

Application control

Allow only approved applications to run.

06

Restrict Microsoft Office macros

Block macros unless there is a business need and they come from a trusted source.

07

User application hardening

Configure browsers and other user applications to reduce what attackers can exploit.

08

Regular backups

Back up important data, software and settings, and make sure restores work.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

G-02

What is the Essential Eight maturity model?

ASD pairs the strategies with a maturity model so an organisation can say how far it has implemented each one. The model was first published in June 2017 and ASD updates it regularly; the November 2023 release made the most recent set of changes listed on the page we reviewed. Organisations pick a target maturity level based on the threats they face and then close the gaps strategy by strategy.

Source: ASD: Essential Eight explained · Read 29 Sep 2026

G-03

How is the Essential Eight assessed?

ASD publishes an Essential Eight assessment process guide that assessors use to test each strategy against the maturity model. ASD also maps the Essential Eight to controls in its Information Security Manual (ISM). The page we reviewed describes assessments rather than a certificate, which is the main practical difference from ISO 27001.

G-04

How does the Essential Eight relate to ISO 27001?

ISO/IEC 27001:2022 and the ASD Essential Eight side by side
ISO/IEC 27001Essential Eight
PublisherISO and IEC, committee ISO/IEC JTC 1/SC 27Australian Signals Directorate
What it isRequirements for an information security management systemEight mitigation strategies with a maturity model
Current versionISO/IEC 27001:2022, Edition 3, published October 2022Maturity model first published June 2017, updated regularly, most recent changes November 2023
OutcomeCertification by a certification body after an auditAssessment against a maturity level using ASD's assessment process guide
ScopeAny organisation, any sectorDesigned for internet-connected IT networks
Cost of the textCHF 155 for the standard on iso.orgPublished on cyber.gov.au

The two work together. An ISMS built for ISO 27001 gives you the risk assessment, policies and review cycle; the Essential Eight gives you a concrete technical baseline to put inside it. Many of the Essential Eight strategies line up with controls you would already select in an ISO 27001 Statement of Applicability, but the Essential Eight asks for a specific maturity level, so evidence has to show how far each control goes.

Source: ISO/IEC 27001:2022 on iso.org, ASD: Essential Eight explained · Read 29 Sep 2026

G-05

Which compliance platforms publish Essential Eight support?

Of the six vendors on this site, only Vanta publishes an Essential Eight product page (pre-mapped templates across all eight strategies). For the others we found no Essential Eight page on the pages reviewed on 29 September 2026.

See the Australia section

G-06

Common questions

What are the Essential Eight?

Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups.

When was the Essential Eight maturity model first published?

In June 2017. ASD updates it regularly, and the page we reviewed lists changes from the November 2023 release.

Who publishes the Essential Eight?

The Australian Signals Directorate, on cyber.gov.au.

Is ISO 27001:2022 the current version?

Yes. ISO/IEC 27001:2022 is Edition 3, published in October 2022, with one amendment listed on iso.org.