Most Australian SMBs should target Essential Eight Maturity Level 1 as a credible cyber baseline; Maturity Level 2 is the practical bar when DISP membership, defence supply-chain work, or a tender questionnaire explicitly expects it. ML0 means the control is not implemented to the documented standard. Jumping straight to ML2 without evidence of ML1 usually wastes money and fails audits for the same reason: maturity is scored control-by-control against ASD's Essential Eight, not as a vendor badge you buy once.
This guide explains what ML1 and ML2 actually mean in practice, who needs which level, how assessment differs from uplift, and how to pick the next step without mistaking a scan for proof.
What are Essential Eight maturity levels?
Essential Eight maturity levels (ML0–ML3) describe how thoroughly your organisation implements each of the eight ASD mitigation strategies — not a single company-wide score. Assessors look at each strategy (application control, patch applications, macro settings, user application hardening, restrict admin privileges, patch operating systems, multi-factor authentication, and regular backups) and assign a level based on evidence that the control meets ASD's documented criteria.
In plain terms:
- ▸ML0: The strategy is missing, partial, or not evidenced to the documented standard.
- ▸ML1: Foundational implementation that materially reduces common opportunistic attacks.
- ▸ML2: Stronger, more consistent implementation — typically what defence industry and many government-facing questionnaires expect.
- ▸ML3: Highly hardened posture; rarely the first target for an SMB starting from scratch.
ASD publishes the model and mitigation strategies on cyber.gov.au. Treat blog summaries (including this one) as a buyer's lens — always verify against the current official tables when you scope work or answer a tender.
What does Maturity Level 1 actually require?
Maturity Level 1 is the ASD-documented foundation for each Essential Eight strategy: the control exists, is applied to the right assets, and you can show evidence it is working. For most Australian SMBs under insurance, board, or general tender pressure — but not locked into DISP ML2 — ML1 is the sensible first target.
Practically, ML1 usually means things like:
- ▸Multi-factor authentication covering the accounts and remote access paths that matter
- ▸Patching processes for applications and operating systems with defined windows
- ▸Admin privileges limited to people who need them, with a countable admin set
- ▸Backups that are tested, not just scheduled
- ▸Application control / hardening / macro settings implemented to the ML1 criteria for your environment
What ML1 is not: a checkbox interview with no technical sample, a vulnerability scan PDF, or a penetration test report alone. Those artefacts can support an uplift plan, but maturity is scored against Essential Eight criteria with technical evidence — configuration samples, policy artefacts, inventory coverage, and verification that controls apply where they claim to.
If you need the cost and inclusions of a fixed-fee independent assessment (board summary, gap analysis, roadmap), see our guide to Essential Eight assessment cost in Australia.
What does Maturity Level 2 add?
Maturity Level 2 tightens each strategy beyond ML1: broader coverage, stronger consistency, and fewer exceptions that leave easy attack paths open. Where ML1 establishes the foundation, ML2 expects the control to hold under more realistic operational pressure — more of the estate covered, fewer "temporary" carve-outs, and evidence that the control still works when people change laptops, vendors change SaaS apps, or admins rotate.
Typical ML2 themes (always confirm against the current ASD tables for each strategy):
- ▸MFA and privileged-access controls applied more completely across remote and privileged pathways
- ▸Faster or more complete patching expectations for higher-risk applications and systems
- ▸Stronger application control / hardening / macro posture with fewer unmanaged exceptions
- ▸Backup and recovery practices that demonstrably support recovery objectives, not just a successful nightly job log
DISP context: For organisations pursuing Defence Industry Security Program (DISP) membership where ICT is in scope, Maturity Level 2 against Essential Eight is the widely understood practical bar for the cyber controls that membership and supply-chain questionnaires care about. That is not the same as "every Australian SMB must be ML2 by law." For the legal vs practical distinction, read Is Essential Eight mandatory in Australia?.
ML1 vs ML2: side-by-side for SMB buyers
- ▸Dimension: Buyer fit
- ▸Maturity Level 1: Most SMBs needing insurance, board, or general tender evidence
- ▸Maturity Level 2: DISP / defence supply chain / questionnaires that name ML2
- ▸Dimension: Control depth
- ▸Maturity Level 1: Foundational implementation per ASD ML1 criteria
- ▸Maturity Level 2: Stronger coverage and consistency per ASD ML2 criteria
- ▸Dimension: Effort
- ▸Maturity Level 1: Often achievable in a focused uplift program from a messy baseline
- ▸Maturity Level 2: Usually a second phase after ML1 gaps are closed
- ▸Dimension: Evidence bar
- ▸Maturity Level 1: Technical samples + process artefacts for each strategy
- ▸Maturity Level 2: Same evidence types, harder to pass with exceptions and partial coverage
- ▸Dimension: Common failure
- ▸Maturity Level 1: Treating a scan or interview as "we're ML1"
- ▸Maturity Level 2: Jumping to ML2 while still ML0/ML1 on core strategies
Rule of thumb we use with Australian SMBs: if nobody has named ML2 in a contract, DISP pack, or insurer questionnaire, start by proving ML1 with evidence. If DISP or a named ML2 requirement is live, plan a phased path — baseline honestly first, then uplift the strategies that fail ML2 — rather than buying a "ML2 certificate" that does not exist.
Who needs ML2 (and who is fine at ML1)?
You likely need a credible path to ML2 when a counterparty or scheme expects it — especially DISP with in-scope ICT, defence primes, or tenders that cite Essential Eight Maturity Level 2. You are usually fine targeting ML1 first when your driver is cyber insurance renewal support, a board asking for a technical baseline, a non-defence commercial tender, or an MSP-hosted environment where independence matters more than a defence label.
Decision shortcuts:
- Named ML2 / DISP in writing → assess against ML2 criteria; uplift the failing strategies with a prioritised roadmap.
- Insurance / board / general cyber baseline → aim for evidenced ML1; keep dated artefacts for renewals.
- Enterprise buyer asking for ISO 27001 → that is a governance/ISMS question; see Essential Eight vs ISO 27001 — E8 technical maturity and ISO certification solve different problems.
- Unclear "just make us compliant" → run an independent baseline assessment before spending on tools or uplift projects.
Independence matters here. An MSP marking its own environment "ML2" is a conflict of interest insurers and auditors increasingly push back on. Independent assessment does not replace your MSP — it validates what they built.
Assessment vs uplift vs penetration testing
An Essential Eight assessment scores maturity and gaps; uplift is the remediation project; a penetration test proves exploitable impact — they are complementary, not synonyms. Mixing them up is how SMBs overpay or under-prove.
- ▸Essential Eight assessment (Aussie Pentest: fixed $4,950 + GST for environments up to 50 seats): maturity across all eight strategies, technical evidence file, gap analysis with risk ratings, prioritised 90-day / 12-month roadmap, board-ready executive summary, and a live debrief. Assessment and advisory only — not implementation.
- ▸Uplift / remediation: MSP or internal IT work (or Spectrum Stream Managed IT as a separately scoped engagement) to close gaps. Assessment does not include doing the build.
- ▸Automated security assessment ($80–$2,000): analyst-reviewed vulnerability assessment for web/API targets — useful finding triage, not an Essential Eight maturity score and not a penetration test.
- ▸Human-led penetration test (from $5,000–$20,000): PoC-backed exploitation evidence for insurers, tenders, and technical risk ranking — maps to frameworks in the report, but does not by itself produce an E8 maturity matrix.
If your insurer asked for "a pentest," clarify whether they want exploitable findings, Essential Eight evidence, or both. Our breakdown of what Australian insurers actually require helps you match the ask to the right artefact.
How should Australian SMBs choose ML1 or ML2 as the next target?
Choose the maturity target from the obligation in front of you, then baseline with technical evidence before you buy tools or book uplift weeks. Guessing "we're probably ML2" is how boards get surprised six weeks before a DISP submission.
A practical sequence:
- Write down the driver — DISP pack, named tender clause, insurer questionnaire, or board baseline.
- Run an independent Essential Eight assessment against the current ASD model so you know which strategies are ML0 / ML1 / ML2 today.
- Set the target — ML1 for most SMBs; ML2 only where the driver requires it.
- Uplift in priority order — close the strategies that unlock the obligation first (often MFA, patching, admin rights, and backups), not the shiny tooling project.
- Re-evidence — update the evidence file after uplift; do not claim ML2 from an old assessment.
- Keep Essential Eight work moving even while ASD consults on a successor Essentials series — see what to do about the Essentials series now.
Soft next step: if you want a fixed-scope independent baseline (up to 50 seats) with a board pack and roadmap, start with an Essential Eight assessment rather than another scanner dump.
Common mistakes when chasing ML1 or ML2
The most expensive mistakes are treating maturity as a badge, skipping evidence, and confusing scans with Essential Eight scores.
Watch for:
- ▸Interview-only "assessments" with no technical sampling of configs, inventories, or backups
- ▸Claiming company-wide ML2 when two strategies are still ML0
- ▸Buying ML2 tooling first before knowing which strategies actually fail
- ▸Letting the implementing MSP grade its own homework for insurer or DISP packs
- ▸Pausing all E8 work because of Essentials-series headlines — today's questionnaires still use Essential Eight
- ▸Substituting a vulnerability scan or automated assessment for maturity evidence — useful inputs, wrong artefact
What should you do this week?
If you have a live DISP, tender, or insurance deadline: book an independent Essential Eight baseline this month and set ML1 or ML2 from the written obligation — not from vibes. If you only need a first technical look at a web app or API, an analyst-reviewed automated assessment from $80 is a faster wedge; if you need PoC-backed exploit evidence, scope a human-led pentest from $5,000. For ongoing board reporting without pretending advisory is incident response, a vCISO retainer ($2,500–$6,500/month) can keep the risk register honest between assessments.
Aussie Pentest is Australian-owned, Melbourne-based, and independent of your MSP. We assess and advise; we do not sell you a fake "E8 certified" sticker, and we will not call an $80 scan a penetration test.
Primary CTA: Talk to us about a fixed-fee Essential Eight assessment ($4,950 + GST, ≤50 seats) or the right-sized test for your insurer or tender — aussiepentest.com.au.

