What the Essential Eight requires — and what Maturity Level 2 actually means
The Essential Eight framework is the ACSC's set of eight prioritised cybersecurity mitigation strategies. Maturity Level 2 is the target for most Australian businesses — required for non-corporate Commonwealth entities, and increasingly expected by government customers, insurers, and enterprise clients. Here is what each control demands at ML2.
1. Application control
Only approved software is allowed to run. At Maturity Level 2, application control must be enforced on workstations and internet-facing servers using an allow-list — blocking unauthorised executables, scripts, and installers before they can run. Microsoft implements this through Windows Defender Application Control (WDAC) policies deployed and enforced via Intune.
2. Patch applications
Applications with known vulnerabilities must be patched promptly. At ML2, security patches for critical vulnerabilities in internet-facing applications must be applied within two weeks, and unsupported applications removed. Intune and Defender Vulnerability Management provide the visibility and enforcement mechanism.
3. Configure Microsoft Office macro settings
Office macros are a primary malware delivery vector. At ML2, macros from the internet must be blocked, only vetted macros may execute, and macro antivirus scanning must be enabled. These settings are enforced centrally through Intune administrative templates.
4. User application hardening
Web browsers and PDF software must be hardened against web-based threats — blocking ads, Java, and unnecessary browser features, and preventing users from changing these settings. ML2 requires these controls to be enforced centrally rather than left to user choice.
5. Restrict administrative privileges
Privileged access must be limited to those who genuinely need it, revalidated regularly, and used only for admin tasks — never for email or web browsing. At ML2, privileged accounts are managed through Entra ID Privileged Identity Management (PIM) with just-in-time elevation and MFA enforcement.
6. Patch operating systems
Operating systems must be patched within defined timeframes — at ML2, critical OS vulnerabilities must be remediated within two weeks and end-of-life operating systems replaced. Windows Update for Business rings managed through Intune automate this enforcement.
7. Multi-factor authentication
MFA must be enforced for all users, including remote access and privileged actions. At ML2, MFA applies to all remote access, all users accessing sensitive data, and all privileged accounts — enforced through Entra ID Conditional Access with phishing-resistant methods preferred.
8. Regular backups
Important data must be backed up regularly, stored securely, and — critically at ML2 — restoration must be tested as part of incident response planning. Backups must be protected from modification and deletion by unprivileged accounts. Azure Backup and Microsoft 365 backup solutions with immutable storage satisfy this control.
The Microsoft advantage
How Microsoft 365 Business Premium covers the Essential Eight
Microsoft 365 Business Premium covers the majority of Essential Eight controls at Maturity Level 2 when properly configured — this is why Mycelium 365 uses it as the foundation for Essential Eight compliance. Most businesses already own the tooling; what they are missing is the configuration.
Two controls deserve special attention. Application control (control 1) at ML2 requires Intune-enforced allow-listing — not just Defender antivirus running in audit mode. And administrative privilege restriction (control 5) is handled through Entra ID Privileged Identity Management, with just-in-time elevation replacing standing admin rights. Both are configuration work, not new licensing.
How it works
The Mycelium 365 Essential Eight compliance service
A three-stage engagement that takes you from unknown posture to documented Maturity Level 2 — starting with a free Essential Eight baseline assessment.
Stage 1
Gap assessment
A remote, read-only review of your Microsoft 365 and Azure environment, scored against all eight ACSC controls at each maturity level. You receive a scored report showing exactly where you stand today — delivered within 5 business days, and free for Australian businesses.
Stage 2
Remediation plan
A prioritised list of the changes required to reach your target maturity level, with effort estimates and Microsoft 365 licensing requirements for each item. You see the full cost and sequence before any work begins — no surprises mid-project.
Stage 3
Implementation
Mycelium 365 configures the missing controls: Intune policy deployment, Entra ID Conditional Access hardening, Defender for Business configuration, Azure Backup setup, and administrative privilege remediation. Most businesses reach Maturity Level 2 within 90 days.
Ongoing compliance is then maintained inside the Secure Cloud managed package, which includes quarterly Essential Eight reviews, continuous patching enforcement, and 24/7 SOC monitoring — because Essential Eight is a posture to maintain, not a certificate to file away.
Essential Eight compliance for specific Australian sectors
Defence contractors
DISP membership carries an Essential Eight expectation for many suppliers in the Edinburgh, Osborne, and Williamtown precincts. Mycelium 365 configures Microsoft 365 and Azure to meet DISP-aware Essential Eight requirements and produces the evidence documentation assessors ask for. Learn more about our work with defence contractors.
Government suppliers
Federal and state government procurement increasingly requires Maturity Level 2 from ICT suppliers. Mycelium 365 provides scored assessment reports and remediation evidence suitable for government tender responses and Protective Security Policy Framework alignment.
Financial services
APRA CPS 234 and CPS 230 requirements align closely with Essential Eight controls. Mycelium 365 maps Essential Eight compliance to APRA obligations for South Australian, Victorian, and New South Wales financial services businesses — one control set, two frameworks satisfied.
Professional services
Accounting, legal, and healthcare firms handling sensitive client data are increasingly targeted by ransomware. Essential Eight ML2 is the most effective baseline defence against the attack patterns used against these sectors — and the first thing cyber insurers now ask about.
For broader regulatory and governance obligations beyond the Essential Eight, our governance and compliance readiness advisory maps your technology controls to the full compliance picture — Privacy Act, DISP, APRA CPS 234, and industry-specific requirements. And for a deeper dive into implementation detail, read our Essential Eight compliance guide.
Frequently Asked Questions
Further reading on Essential Eight compliance
Guides and assessments to help you understand and reach your target maturity level.
- Essential Eight compliance for Melbourne businessesA practical guide to the eight ACSC controls, maturity levels, and Microsoft 365 implementation.Read the article
- Microsoft 365 security and compliance guideHow to configure Microsoft 365 for security, compliance, and Essential Eight alignment.Read the article
- Zero Trust security for Microsoft 365 AustraliaHow Zero Trust architecture complements Essential Eight controls in a Microsoft environment.Read the article
What our clients say
Verbatim client reviews, grouped by responsiveness, technical expertise, security and ongoing support, sit on one page alongside the case studies and Microsoft Solutions Partner credentials behind them.
Read our client reviewsReady to simplify and secure your technology?
Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.
We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.
