Essential Eight explained: the eight strategies, the maturity model and ISO 27001
The Essential Eight is the set of eight mitigation strategies that the Australian Signals Directorate (ASD) describes as the most effective of its Strategies to mitigate cyber security incidents. It comes with a maturity model, first published in June 2017 and updated regularly since, and it is designed for internet-connected IT networks.
What are the eight strategies?
Patch applications
Apply security fixes to applications promptly, starting with internet-facing ones.
Patch operating systems
Apply security fixes to operating systems on workstations, servers and network devices.
Multi-factor authentication
Require more than one proof of identity, especially for remote access and privileged accounts.
Restrict administrative privileges
Limit who holds admin rights and what those accounts can do.
Application control
Allow only approved applications to run.
Restrict Microsoft Office macros
Block macros unless there is a business need and they come from a trusted source.
User application hardening
Configure browsers and other user applications to reduce what attackers can exploit.
Regular backups
Back up important data, software and settings, and make sure restores work.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
What is the Essential Eight maturity model?
ASD pairs the strategies with a maturity model so an organisation can say how far it has implemented each one. The model was first published in June 2017 and ASD updates it regularly; the November 2023 release made the most recent set of changes listed on the page we reviewed. Organisations pick a target maturity level based on the threats they face and then close the gaps strategy by strategy.
Source: ASD: Essential Eight explained · Read 29 Sep 2026
How is the Essential Eight assessed?
ASD publishes an Essential Eight assessment process guide that assessors use to test each strategy against the maturity model. ASD also maps the Essential Eight to controls in its Information Security Manual (ISM). The page we reviewed describes assessments rather than a certificate, which is the main practical difference from ISO 27001.
How does the Essential Eight relate to ISO 27001?
| ISO/IEC 27001 | Essential Eight | |
|---|---|---|
| Publisher | ISO and IEC, committee ISO/IEC JTC 1/SC 27 | Australian Signals Directorate |
| What it is | Requirements for an information security management system | Eight mitigation strategies with a maturity model |
| Current version | ISO/IEC 27001:2022, Edition 3, published October 2022 | Maturity model first published June 2017, updated regularly, most recent changes November 2023 |
| Outcome | Certification by a certification body after an audit | Assessment against a maturity level using ASD's assessment process guide |
| Scope | Any organisation, any sector | Designed for internet-connected IT networks |
| Cost of the text | CHF 155 for the standard on iso.org | Published on cyber.gov.au |
The two work together. An ISMS built for ISO 27001 gives you the risk assessment, policies and review cycle; the Essential Eight gives you a concrete technical baseline to put inside it. Many of the Essential Eight strategies line up with controls you would already select in an ISO 27001 Statement of Applicability, but the Essential Eight asks for a specific maturity level, so evidence has to show how far each control goes.
Source: ISO/IEC 27001:2022 on iso.org, ASD: Essential Eight explained · Read 29 Sep 2026
Which compliance platforms publish Essential Eight support?
Of the six vendors on this site, only Vanta publishes an Essential Eight product page (pre-mapped templates across all eight strategies). For the others we found no Essential Eight page on the pages reviewed on 29 September 2026.
Common questions
What are the Essential Eight?
Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening and regular backups.
When was the Essential Eight maturity model first published?
In June 2017. ASD updates it regularly, and the page we reviewed lists changes from the November 2023 release.
Who publishes the Essential Eight?
The Australian Signals Directorate, on cyber.gov.au.
Is ISO 27001:2022 the current version?
Yes. ISO/IEC 27001:2022 is Edition 3, published in October 2022, with one amendment listed on iso.org.