Essential Eight Maturity Level 2 is the standard required by most Australian government procurement contracts, and increasingly by enterprise clients and cyber insurers across the private sector. It sits between the baseline controls of ML1 and the deeply embedded programme of ML3, and it represents a meaningful step up in both the consistency and evidenceability of your security controls.
This guide explains what ML2 actually requires across all eight strategies, how it differs from ML1 and ML3, and what it takes to get there for an Australian SMB. If you are new to the framework, our Essential 8 compliance guide covers the full picture: all eight controls, the maturity model, and implementation, updated for the framework transition.
One piece of context worth knowing first: the ASD has announced it will retire the Essential Eight over the next two years and replace it with the Essentials series. ML2 remains the requirement today, and because the controls carry forward into the new framework, the work in this guide stays relevant. This matters particularly for government suppliers and DISP members, whose obligations are unchanged during the transition.
| Level | What it means | Who it suits | Typical timeline to achieve |
|---|---|---|---|
| ML0 | ML1 requirements not yet met, with significant weaknesses present | Starting point where significant gaps exist | N/A |
| ML1 | All eight strategies implemented to counter commodity-level tradecraft. See our ML1 guide | The ACSC’s suggested fit for small to medium enterprises | 3–6 months from ML0 |
| ML2 | Tighter timeframes, broader scope, logged and evidenced. The PSPF baseline, required by most govt contracts | Government suppliers, regulated sectors, enterprise clients | 6–12 months from ML1 |
| ML3 | Controls deeply embedded with active monitoring and response, protecting against sophisticated targeted attacks. See our ML3 guide | Critical infrastructure, high-value government contracts, high threat environments | 12+ months from ML2 |
ML1 is not a loose version of ML2. It has its own binary requirements, and since the November 2023 model update some of them are demanding, including 48-hour patching for critical vulnerabilities in internet-facing systems. Our ML1 requirements guide covers that baseline in full. What ML2 adds is breadth and proof: the scope of each strategy expands, timeframes tighten, and controls must be logged and evidenced rather than simply in place. Your overall rating is the lowest level achieved across all eight strategies, so a single lagging control caps the lot.
Here is what that means in practice across all eight strategies:
ML1: Execution of executables, scripts, installers, and similar content is blocked from user profiles and temporary folders using file system permissions. No allowlisting product is required at this level.
ML2: A genuine application control solution enforced on all workstations and internet-facing servers, covering executables, libraries, scripts, installers, compiled HTML, and control panel applets. Microsoft’s recommended application blocklist applied, rulesets reviewed annually, and allowed and blocked execution events centrally logged.
ML1: Online services scanned for vulnerabilities daily and patched within 48 hours when a vulnerability is critical or an exploit exists, otherwise within two weeks. Office productivity suites, web browsers, email clients, PDF software, and security products scanned weekly and patched within two weeks. Unsupported versions of these applications removed.
ML2: Everything at ML1, plus vulnerability scanning extended to all remaining applications at least fortnightly, with those applications patched within one month. Patch compliance monitored and reported, not assumed.
ML1: Macros disabled for every user without a demonstrated business need. Macros in files from the internet blocked. Antivirus macro scanning enabled. Users cannot change macro settings themselves.
ML2: Macros blocked from making Win32 API calls, macros signed by untrusted publishers cannot be enabled by users, and the list of trusted publishers is reviewed annually.
ML1: Internet Explorer 11 disabled or removed, Java from the internet blocked, and web advertisements blocked. Users cannot change these settings.
ML2: Microsoft Office, web browsers, and PDF software hardened in line with ASD and vendor hardening guidance, Office blocked from creating child processes, PowerShell configured with logging enabled, and command-line and PowerShell events centrally logged.
ML1: Requests for privileged access validated when first requested. Privileged accounts separated from standard user accounts and blocked from accessing the internet, email, and web services unless explicitly authorised and strictly limited. Privileged operating environments separated from unprivileged ones.
ML2: Privileged access automatically disabled after 12 months unless revalidated, and after 45 days of inactivity. Administrative activities performed through jump servers or secure admin workstations. All privileged access events centrally logged.
ML1: Internet-facing systems patched within 48 hours when a vulnerability is critical or an exploit exists, otherwise within two weeks. Workstation and server operating systems patched within one month. Unsupported operating systems replaced.
ML2: Patching of workstation, server, and network device operating systems tightened from one month to two weeks, with at least fortnightly vulnerability scanning. End-of-life systems removed or isolated, and patch compliance tracked and reported.
ML1: MFA required for users authenticating to the organisation’s online services and to third-party services handling sensitive data, and offered to customers of customer-facing services.
ML2: MFA extended to all users authenticating to the organisation’s systems, including workstation logon using phishing-resistant methods such as smart cards, security keys, passkeys, or Windows Hello for Business. Standard push-notification approvals do not qualify. Authentication events centrally logged.
ML1: Backups of important data, software, and configuration settings performed and retained in line with business criticality and the continuity plan, with restoration tested as part of disaster recovery exercises. Unprivileged accounts cannot access backups belonging to other accounts.
ML2: Privileged accounts (other than backup administrators) also prevented from accessing backups belonging to other accounts, and unprivileged accounts prevented from modifying or deleting any backups. We recommend rehearsing restores at least quarterly so the disaster recovery evidence stays current.
Based on our Essential Eight assessments across Perth businesses, these are the controls that most frequently prevent organisations from reaching ML2:
For a business starting from ML1 with a Perth managed IT provider, reaching ML2 typically takes six to twelve months. The timeline depends heavily on your current environment. A cloud-first Microsoft 365 business with Intune-managed devices will get there faster than a business with on-premises servers and unmanaged endpoints.
The cost of moving from ML1 to ML2 for a 20–50 person business typically runs $15,000 to $40,000 in implementation work, depending on how many gaps need to close. For businesses on a managed IT agreement with Epic IT, much of this is absorbed into the monthly service.
ML2 is the mandatory baseline for federal government entities under the Protective Security Policy Framework (PSPF), and it is the level most Australian government supplier contracts reference. If your organisation is on the Australian Government’s supply chain, ML2 is the minimum you need. It is also increasingly specified by large enterprise clients and cyber insurers as a condition of engagement. Beyond ML2, Maturity Level 3 exists for critical infrastructure and high threat environments; most commercial SMBs do not need it.
If your business is not supplying to government and has no formal Essential Eight contractual obligation, SMB1001 Gold is often a more practical and achievable starting point. It builds the same foundations while delivering a formal certification you can use commercially. Read our comparison of Essential Eight vs SMB1001 for guidance on which to prioritise.
We conduct Essential Eight assessments and implementation for businesses across Perth as part of our managed security services. Our assessment gives you a clear ML rating across all eight strategies, identifies the specific gaps preventing ML2 attainment, and produces a prioritised remediation plan.
Contact us on 1300 EPIC IT for a free Essential Eight gap analysis.
Essential Eight Maturity Level 2 is the tier of the ASD maturity model designed to counter adversaries with moderate capability. It broadens the scope of every strategy, tightens patching timeframes, requires phishing-resistant MFA for workstation logon, and demands centrally logged evidence that controls are working. It is the mandatory baseline for federal government entities under the PSPF and the standard most government supplier contracts reference.
At ML2, application control extends to internet-facing servers with Microsoft’s blocklist applied, vulnerability scanning and one-month patching cover all applications, operating system patching tightens to two weeks, macros are blocked from Win32 API calls, admin access runs through secure admin workstations or jump servers with 12-month revalidation, MFA becomes phishing-resistant including workstation logon, and privileged accounts lose access to other accounts’ backups. Control events must be centrally logged.
ML1 has its own firm requirements, including 48-hour patching of critical internet-facing vulnerabilities, but ML2 expands the scope of each strategy and adds logging and evidence obligations. The jump from ML1 to ML2 is typically the hardest part of the Essential Eight journey because it requires real application control tooling, phishing-resistant MFA, privileged access lifecycle management, and the monitoring discipline to prove it all.
For most Australian SMBs working with a managed IT provider, moving from ML1 to ML2 takes six to twelve months. A cloud-first Microsoft 365 environment with Intune-managed devices will get there faster than a business with on-premises servers and legacy systems. The cost typically runs $15,000 to $40,000 in implementation work for a 20–50 person business.
ML2 is required for most Australian government supplier contracts and is increasingly expected by enterprise clients and cyber insurers. The ACSC suggests ML1 may suit small to medium enterprises with lower threat profiles, while ML3 is reserved for critical infrastructure and high threat environments. If you do not have government contracts, SMB1001 Gold may be a more practical starting point while you build toward ML2.
At minimum every 12 months, and ideally every six months for businesses actively working toward a higher maturity level. Assessments follow the ASD’s assessment process guide and must progress in order: ML1 must be demonstrated before an ML2 assessment begins. Between formal assessments, continuous monitoring matters because controls that were ML2-compliant six months ago can degrade through configuration drift, new devices, or software changes.
Our Perth-based team conducts Essential Eight gap assessments for businesses across Western Australia. We give you a clear maturity rating and a practical path to ML2.
Or call us on 1300 EPIC IT (1300 374 248)