Skip to content

Security & SOC3 min read

Essential Eight Maturity Level 2 Assessment in 2026: Evidence Assessors Test and What ASD's New Essentials Means

Essential Eight assessment in 2026: Maturity Level 2 evidence assessors test, gap analysis steps, and how ASD's new Essentials series changes uplift planning.

Share

Key takeaways

  • ASD's 2026 Essentials consultation continues, keep uplifting against current ML2 while versioning the assessment.
  • Same maturity level must be achieved across all eight strategies before claiming that level.
  • ML2 evidence is operational: patch telemetry, phishing-resistant MFA logs, admin lifecycle, restore tests.
  • Assessors prefer simulated tests and live configuration over screenshots and policy statements.
  • Essential Eight has no universal independent certification, though a regulator, policy or contract can require one.
  • AiRAT delivers Essential Eight gap analysis and uplift engineering, we are not IRAP assessors.
On this page7 sections

Essential Eight assessment and Essential Eight maturity assessment work in 2026 must account for ASD's proposed Essentials series consultation (opened 15 June 2026) while the current Essential 8 maturity level 2 model remains published. This guide covers Essential Eight gap analysis, Essential Eight compliance Australia evidence expectations, and Essential Eight remediation / uplift engineering, with remote delivery and Australian residency where required. We are not IRAP assessors.

2026 update: evolve the programme, do not pause it

ASD's Essentials consultation does not pause ML2 uplift. Until final guidance lands:

Continue closing ML1/ML2 gaps: controls still address real attack paths

Version the assessment model and guide date used

Map requirement → enforcement point → evidence for Essentials remapping

Avoid policy-only remediation: live enforcement survives framework changes

What ML2 actually represents

ASD defines four maturity levels. ML2 targets step-up actors beyond commodity attacks.

  1. Achieve the same maturity level across all eight strategies before claiming that level
  2. No universal independent certification, though regulators or contracts may require one

A system with strong MFA but weak patching is not “ML2 because identity is ML2”.

Essential Eight ML2 evidence quality ladder and shared evidence platforms

ML1 vs ML2: what changes in practice

ML1 often means foundational controls exist but evidence is thin: policies without timestamps, partial MFA coverage, informal patching.

ML2 adds measurable operational requirements: defined patch windows, phishing-resistant MFA, privileged-access lifecycle, application control on workstations and internet-facing servers, hardened Office/browser/PDF config, central logging, protected backups with restore tests.

Assessors need timestamped scanner history, IdP policy plus sign-in logs, PAM exports, blocked-execution tests, not screenshots alone.

Evidence assessors test at ML2

StrategyML2 themesEvidence to produce
Patch applicationsScanning cadence, critical patch windowsScanner history, vuln age, patch records
Patch operating systemsInternet-facing daily scanOS inventory, compliance, exceptions
MFAPhishing-resistant MFA, central auth loggingIdP policy, live login test, SIEM events
Restrict admin privilegesRevalidation, inactive disable, jump hostsPAM exports, admin event logs
Application controlWorkstations + internet-facing serversPolicy, blocked-execution test, logs
Restrict Office macrosBusiness-need only, internet macros blockedGroup Policy/MDM, test document
User app hardeningBrowser/Office/PDF, PowerShell loggingLive config, process-creation events
Regular backupsSecure retention, restore tests, ACL separationJob history, restore report

Central SIEM, endpoint, vuln management, IAM/PAM and backup platforms generate reusable evidence. See SOC automation evidence for audit-grade artefact design.

Essential Eight uplift services: practical sequence

ASD ranks evidence: simulated tests / live config (strongest) → screenshots → policy (weakest).

Week 1–2: scope boundary, maturity snapshot, Essential Eight gap analysis

Week 3–6: close enforcement gaps (MFA, patching telemetry, admin lifecycle, logging)

Week 7+: simulated tests, retest pack, Essentials transition mapping

Delivery uses AEST/AEDT overlap with architectures that keep production data in Australian Regions when required. See Australia hub and residency guide.

Readiness checklist

  • Define assessment boundary and target maturity level
  • Map each strategy to enforcement point and evidence artefact
  • Record ASD guide version used in the assessment
  • Close ML1 gaps before claiming ML2 on any strategy
  • Run simulated control tests for weakest strategies
  • Prepare Essentials remapping register for 2026 transition

Limitations

Not legal advice. No ASD endorsement claimed. IRAP assessments are out of scope. Essential Eight gap assessment and uplift engineering only.


Sources: ASD Essential Eight, verified 8 August 2026.

Next step: Scope Essential Eight gap assessment · E8 assessment pillar · Australia hub

Essential EightMaturity Level 2ASDCybersecurityAustraliaAssessment

Written by

Anurag Sogani

Founder & Principal Engineer, AiRAT

Anurag leads AiRAT's platform engineering practice, shipping production SOC, XDR and agent-security systems for regulated enterprises across UAE, India, Singapore, Europe, Australia and the US. He writes from delivery work: the frameworks here come out of live programmes, not vendor decks.

Common questions

7 questions

Is the Essential Eight being replaced in 2026?

ASD is consulting on an evolution into a new Essentials series. As of 8 August 2026 the current Essential Eight guidance remains published; continue current uplift while versioning the assessment and preparing to remap to final guidance.

What does Essential Eight Maturity Level 2 require in practice?

ML2 adds measurable requirements across patching, phishing-resistant MFA, privileged access, application control, Office/browser/PDF hardening, central logging and protected/restorable backups.

What evidence do Essential Eight assessors prefer?

ASD's assessment guide ranks simulated control testing and direct review of live configuration above copied configurations/screenshots, with policy statements or verbal assertions as the weakest evidence.

Can we be Maturity Level 2 if only some Essential Eight strategies meet ML2?

ASD says organisations should plan to achieve the same maturity level across all eight mitigation strategies before moving to a higher level.

Does Essential Eight require independent certification?

No universal certification is required by the Essential Eight itself, but an independent assessment may be required by a government directive, regulator, policy or contract.

Does Maturity Level 2 require phishing-resistant MFA?

Yes, the ML2 model includes phishing-resistant MFA requirements for users of online services and systems, plus central logging of successful and unsuccessful MFA events.

Is AiRAT an IRAP assessor?

No. AiRAT can perform Essential Eight gap assessments and uplift engineering, but it is not an IRAP assessor and does not provide IRAP assessments.

Stay current

Engineering insights, when we publish them.

Production notes on AI, security, and data infrastructure. No marketing, only the pieces worth reading.

No spam. Unsubscribe anytime.

Get started

Leave your email - we'll reach out.

Share your work email and we'll follow up with a tailored note on security, AI, or data programmes - usually within one business day.

No spam. We only use your email to respond to this request.

Explore services →