Skip to main content
Whitesec AU
Back to Insights

Compliance18 June 2026

Essential Eight Maturity Level 2: What Assessors Actually Look For

Whitesec Intelligence Team
Executive Summary

Most organisations that claim Maturity Level 2 against the ASD Essential Eight are scored lower on independent assessment. The gap is rarely the control itself — it is the evidence behind it.

Australian organisations bidding into government and tier-1 supply chains are increasingly asked a blunt question: what is your Essential Eight maturity level? Many answer "Level 2" on the strength of a self-assessment. Independent assessment frequently lands somewhere lower.

The reason is usually not that the control is missing. It is that maturity, as the Australian Signals Directorate defines it, is about consistency and coverage — and consistency is measured in evidence, not intent.

Maturity is measured per strategy, not per organisation

The Essential Eight Maturity Model assigns a level to each of the eight mitigation strategies independently. Your overall maturity is the lowest level achieved across all eight. A single weak strategy caps the whole assessment.

This surprises organisations that have invested heavily in one or two areas. Excellent multi-factor authentication does not compensate for inconsistent patching. There is no averaging.

Where Level 2 claims typically fall down

Patch cadence measured in intent, not telemetry

Level 2 expects patches for internet-facing services within two weeks of release, and within 48 hours where an exploit exists. Most organisations have a patching policy that says exactly this. Far fewer can produce a report showing the actual interval between vendor release and deployment, per asset, over the last quarter.

An assessor does not read the policy. They ask for the data.

Application control scoped to a pilot

Application control is the strategy most often claimed and least often implemented at scale. A common pattern: AppLocker or WDAC is deployed in audit mode on a subset of workstations, the pilot never expands, and the policy remains unenforced. Audit mode is not enforcement, and a subset is not coverage.

Administrative privileges granted permanently

Level 2 expects privileged access to be validated when first requested and revalidated at least annually, with privileged accounts prevented from accessing the internet, email, and web services. Standing domain administrator rights held by long-departed contractors remain one of the most common findings in this area.

Backups never restored

Backup regimes are frequently well designed and rarely exercised. Level 2 expects restoration to be tested, and expects unprivileged accounts to be unable to modify or delete backups. If the last documented restoration test predates your current backup platform, the control is unproven.

What an evidence-backed assessment involves

Independent verification looks different from a questionnaire. Rather than asking whether a control exists, it samples the environment for proof that the control is operating:

  • Group Policy and Intune configuration exports, not screenshots
  • Vulnerability scanner output showing patch age distribution across assets
  • Conditional Access policy exports, including which legacy authentication paths remain open
  • Privileged account inventories cross-referenced against current staff
  • Backup immutability settings and dated restoration test records

Each of these is something a prime contractor's risk team can inspect. That is the point: the artefact has to survive somebody else's scrutiny, not just satisfy your own.

Why the distinction matters commercially

Procurement portals increasingly ask for maturity claims to be substantiated. Where a self-assessed claim is later contradicted by an independent review — or by an incident — the commercial consequences land on the organisation that made the claim, not the assessor who accepted it.

Treating the Essential Eight as an evidence exercise rather than a declaration exercise changes what you build. You end up with the same controls, documented in a way that holds up when someone asks to see the data behind them.

Where to start

If you are preparing for a tender that specifies a maturity level, work backwards from the evidence an assessor will request. Pick the two strategies you are least confident about and try to produce the artefacts yourself. The gap between what you can demonstrate and what you assumed is your actual remediation scope.

That exercise takes a few days and is considerably cheaper than discovering the gap during a procurement review.

WS

Written by Whitesec Intelligence Team

Offensive Security Practitioners & ISO 27001 Auditors

Whitesec AU is an accredited Australian cybersecurity firm providing VAPT, Essential Eight gap analysis, CPS 234 compliance, and vCISO governance out of Perth, WA.

Need Technical Verification for Your Security Posture?

Speak with our Perth-based consultants to discuss your audit, tender, or penetration testing requirements.