Essential 8 Maturity Level 2: the complete requirements and implementation guide for 2026

By Greg Markowski / Jan 5, 2026 / Cybersecurity & Compliance

Essential Eight Maturity Level 2 is the standard required by most Australian government procurement contracts, and increasingly by enterprise clients and cyber insurers across the private sector. It sits between the baseline controls of ML1 and the deeply embedded programme of ML3, and it represents a meaningful step up in both the consistency and evidenceability of your security controls.

This guide explains what ML2 actually requires across all eight strategies, how it differs from ML1 and ML3, and what it takes to get there for an Australian SMB. If you are new to the framework, our Essential 8 compliance guide covers the full picture: all eight controls, the maturity model, and implementation, updated for the framework transition.

One piece of context worth knowing first: the ASD has announced it will retire the Essential Eight over the next two years and replace it with the Essentials series. ML2 remains the requirement today, and because the controls carry forward into the new framework, the work in this guide stays relevant. This matters particularly for government suppliers and DISP members, whose obligations are unchanged during the transition.

Essential Eight maturity levels: what each one means

Level What it means Who it suits Typical timeline to achieve
ML0 ML1 requirements not yet met, with significant weaknesses present Starting point where significant gaps exist N/A
ML1 All eight strategies implemented to counter commodity-level tradecraft. See our ML1 guide The ACSC’s suggested fit for small to medium enterprises 3–6 months from ML0
ML2 Tighter timeframes, broader scope, logged and evidenced. The PSPF baseline, required by most govt contracts Government suppliers, regulated sectors, enterprise clients 6–12 months from ML1
ML3 Controls deeply embedded with active monitoring and response, protecting against sophisticated targeted attacks. See our ML3 guide Critical infrastructure, high-value government contracts, high threat environments 12+ months from ML2

What changes between ML1 and ML2?

ML1 is not a loose version of ML2. It has its own binary requirements, and since the November 2023 model update some of them are demanding, including 48-hour patching for critical vulnerabilities in internet-facing systems. Our ML1 requirements guide covers that baseline in full. What ML2 adds is breadth and proof: the scope of each strategy expands, timeframes tighten, and controls must be logged and evidenced rather than simply in place. Your overall rating is the lowest level achieved across all eight strategies, so a single lagging control caps the lot.

Here is what that means in practice across all eight strategies:

1. Application control

ML1: Execution of executables, scripts, installers, and similar content is blocked from user profiles and temporary folders using file system permissions. No allowlisting product is required at this level.
ML2: A genuine application control solution enforced on all workstations and internet-facing servers, covering executables, libraries, scripts, installers, compiled HTML, and control panel applets. Microsoft’s recommended application blocklist applied, rulesets reviewed annually, and allowed and blocked execution events centrally logged.

2. Patch applications

ML1: Online services scanned for vulnerabilities daily and patched within 48 hours when a vulnerability is critical or an exploit exists, otherwise within two weeks. Office productivity suites, web browsers, email clients, PDF software, and security products scanned weekly and patched within two weeks. Unsupported versions of these applications removed.
ML2: Everything at ML1, plus vulnerability scanning extended to all remaining applications at least fortnightly, with those applications patched within one month. Patch compliance monitored and reported, not assumed.

3. Configure Microsoft Office macro settings

ML1: Macros disabled for every user without a demonstrated business need. Macros in files from the internet blocked. Antivirus macro scanning enabled. Users cannot change macro settings themselves.
ML2: Macros blocked from making Win32 API calls, macros signed by untrusted publishers cannot be enabled by users, and the list of trusted publishers is reviewed annually.

4. User application hardening

ML1: Internet Explorer 11 disabled or removed, Java from the internet blocked, and web advertisements blocked. Users cannot change these settings.
ML2: Microsoft Office, web browsers, and PDF software hardened in line with ASD and vendor hardening guidance, Office blocked from creating child processes, PowerShell configured with logging enabled, and command-line and PowerShell events centrally logged.

5. Restrict administrative privileges

ML1: Requests for privileged access validated when first requested. Privileged accounts separated from standard user accounts and blocked from accessing the internet, email, and web services unless explicitly authorised and strictly limited. Privileged operating environments separated from unprivileged ones.
ML2: Privileged access automatically disabled after 12 months unless revalidated, and after 45 days of inactivity. Administrative activities performed through jump servers or secure admin workstations. All privileged access events centrally logged.

6. Patch operating systems

ML1: Internet-facing systems patched within 48 hours when a vulnerability is critical or an exploit exists, otherwise within two weeks. Workstation and server operating systems patched within one month. Unsupported operating systems replaced.
ML2: Patching of workstation, server, and network device operating systems tightened from one month to two weeks, with at least fortnightly vulnerability scanning. End-of-life systems removed or isolated, and patch compliance tracked and reported.

7. Multi-factor authentication

ML1: MFA required for users authenticating to the organisation’s online services and to third-party services handling sensitive data, and offered to customers of customer-facing services.
ML2: MFA extended to all users authenticating to the organisation’s systems, including workstation logon using phishing-resistant methods such as smart cards, security keys, passkeys, or Windows Hello for Business. Standard push-notification approvals do not qualify. Authentication events centrally logged.

8. Regular backups

ML1: Backups of important data, software, and configuration settings performed and retained in line with business criticality and the continuity plan, with restoration tested as part of disaster recovery exercises. Unprivileged accounts cannot access backups belonging to other accounts.
ML2: Privileged accounts (other than backup administrators) also prevented from accessing backups belonging to other accounts, and unprivileged accounts prevented from modifying or deleting any backups. We recommend rehearsing restores at least quarterly so the disaster recovery evidence stays current.

The most common gaps when moving from ML1 to ML2

Based on our Essential Eight assessments across Perth businesses, these are the controls that most frequently prevent organisations from reaching ML2:

How long does it take to reach ML2?

For a business starting from ML1 with a Perth managed IT provider, reaching ML2 typically takes six to twelve months. The timeline depends heavily on your current environment. A cloud-first Microsoft 365 business with Intune-managed devices will get there faster than a business with on-premises servers and unmanaged endpoints.

The cost of moving from ML1 to ML2 for a 20–50 person business typically runs $15,000 to $40,000 in implementation work, depending on how many gaps need to close. For businesses on a managed IT agreement with Epic IT, much of this is absorbed into the monthly service.

Does my business need ML2?

ML2 is the mandatory baseline for federal government entities under the Protective Security Policy Framework (PSPF), and it is the level most Australian government supplier contracts reference. If your organisation is on the Australian Government’s supply chain, ML2 is the minimum you need. It is also increasingly specified by large enterprise clients and cyber insurers as a condition of engagement. Beyond ML2, Maturity Level 3 exists for critical infrastructure and high threat environments; most commercial SMBs do not need it.

If your business is not supplying to government and has no formal Essential Eight contractual obligation, SMB1001 Gold is often a more practical and achievable starting point. It builds the same foundations while delivering a formal certification you can use commercially. Read our comparison of Essential Eight vs SMB1001 for guidance on which to prioritise.

How Epic IT can help

We conduct Essential Eight assessments and implementation for businesses across Perth as part of our managed security services. Our assessment gives you a clear ML rating across all eight strategies, identifies the specific gaps preventing ML2 attainment, and produces a prioritised remediation plan.

Contact us on 1300 EPIC IT for a free Essential Eight gap analysis.

Frequently asked questions

What is Essential Eight Maturity Level 2?

Essential Eight Maturity Level 2 is the tier of the ASD maturity model designed to counter adversaries with moderate capability. It broadens the scope of every strategy, tightens patching timeframes, requires phishing-resistant MFA for workstation logon, and demands centrally logged evidence that controls are working. It is the mandatory baseline for federal government entities under the PSPF and the standard most government supplier contracts reference.

What are the Essential Eight ML2 requirements?

At ML2, application control extends to internet-facing servers with Microsoft’s blocklist applied, vulnerability scanning and one-month patching cover all applications, operating system patching tightens to two weeks, macros are blocked from Win32 API calls, admin access runs through secure admin workstations or jump servers with 12-month revalidation, MFA becomes phishing-resistant including workstation logon, and privileged accounts lose access to other accounts’ backups. Control events must be centrally logged.

How is ML2 different from ML1?

ML1 has its own firm requirements, including 48-hour patching of critical internet-facing vulnerabilities, but ML2 expands the scope of each strategy and adds logging and evidence obligations. The jump from ML1 to ML2 is typically the hardest part of the Essential Eight journey because it requires real application control tooling, phishing-resistant MFA, privileged access lifecycle management, and the monitoring discipline to prove it all.

How long does it take to achieve Essential Eight ML2?

For most Australian SMBs working with a managed IT provider, moving from ML1 to ML2 takes six to twelve months. A cloud-first Microsoft 365 environment with Intune-managed devices will get there faster than a business with on-premises servers and legacy systems. The cost typically runs $15,000 to $40,000 in implementation work for a 20–50 person business.

Do I need Essential Eight ML2 or is ML1 enough?

ML2 is required for most Australian government supplier contracts and is increasingly expected by enterprise clients and cyber insurers. The ACSC suggests ML1 may suit small to medium enterprises with lower threat profiles, while ML3 is reserved for critical infrastructure and high threat environments. If you do not have government contracts, SMB1001 Gold may be a more practical starting point while you build toward ML2.

How often should Essential Eight assessments be conducted?

At minimum every 12 months, and ideally every six months for businesses actively working toward a higher maturity level. Assessments follow the ASD’s assessment process guide and must progress in order: ML1 must be demonstrated before an ML2 assessment begins. Between formal assessments, continuous monitoring matters because controls that were ML2-compliant six months ago can degrade through configuration drift, new devices, or software changes.

Want to know where you sit against Essential Eight ML2?

Our Perth-based team conducts Essential Eight gap assessments for businesses across Western Australia. We give you a clear maturity rating and a practical path to ML2.

Book a Free Assessment

Or call us on 1300 EPIC IT (1300 374 248)

About the Author
Written by Greg Markowski, Founding Director of Epic IT, a CRN Fast50-recognised Microsoft Solutions Partner managing IT and cybersecurity for Perth businesses since 2003. Greg holds a Degree in Computer Science and a Diploma in Computer Systems Engineering from Edith Cowan University, and is ITIL certified.

Further Reading

Previous

Microsoft Teams Setup Guide

Return to News
Back to News
Next

Cloud Migration Services: A Buyer's Guide for Australian Businesses