What does Essential Eight Maturity Level 1 involve?

Maturity Level 1 is the baseline tier of the ASD Essential Eight, aimed at opportunistic attackers using commodity tools and techniques rather than a targeted campaign. It requires all eight mitigation strategies, application control included, not a subset of them. Blue Arc IT Solutions treats ML1 as the floor for every managed IT agreement, whether or not a client has a formal reason to be assessed against it.

The eight controls at ML1

Patch applications: vulnerability scanners run daily against internet-facing services and at least weekly against office productivity suites, browsers, email clients, PDF software and security products, with automated asset discovery at least fortnightly. Critical vulnerabilities with a working exploit are patched within 48 hours; everything else in scope within two weeks. Software no longer supported by its vendor is removed.

Patch operating systems: the same scanning and 48-hour critical window applies to internet-facing servers and network devices; workstations and non-internet-facing systems get a one-month patch window. Unsupported operating system versions are replaced, not left running.

Multi-factor authentication: required for users signing in to your organisation's online services that handle sensitive data, and for customers signing in to online customer services handling sensitive customer data.

Restrict administrative privileges: privileged access requests are validated when first made, privileged users get a dedicated account used only for privileged duties, and that account is blocked from general internet, email and web access unless specifically authorised.

Application control: implemented on workstations, applied to user profiles and the temporary folders used by the operating system, browsers and email clients, restricting execution of executables, scripts, installers and similar to an organisation-approved set. This is the control most commonly assumed to start at ML2. It does not.

Restrict Microsoft Office macros: macros are disabled for anyone without a demonstrated business need, macros arriving from the internet are blocked outright, antivirus scanning covers macros, and users cannot change the settings themselves.

User application hardening: Internet Explorer 11 is removed, browsers are blocked from running Java or displaying web advertisements sourced from the internet, and browser security settings are locked from user changes.

Regular backups: performed and retained according to business continuity needs, synchronised to a common restore point, kept securely and resiliently, and tested as part of disaster recovery exercises. Unprivileged accounts cannot access other users' backups or modify and delete backups.

For the authoritative, current wording, see ASD's Essential Eight maturity model, Appendix A.

What actually changes at ML2

The step from ML1 to ML2 is mostly about scope and rigour, not new controls. Application control extends from workstations to internet-facing servers and to every execution location, plus Microsoft's recommended blocklist, annual ruleset reviews and logging of allowed and blocked events. Patch applications extends the same 48-hour critical window and vulnerability scanning to every application, not just the office suites, browsers, email clients, PDF readers and security products ML1 covers. Multi-factor authentication extends to system logons, with a phishing-resistance requirement. See our guide to what Essential Eight Maturity Level 2 involves for the full detail.

Who should target ML1, and who needs more

ML1 is a sensible baseline for most small and mid-sized Australian businesses: it stops opportunistic, commodity attacks, which is the overwhelming majority of what actually hits SMBs. It is not enough on its own for DISP membership, which requires the full Essential Eight at ML2 for every membership level, or for most government and Defence-related tenders. If Defence-industry work, government contracts or a regulator's expectations are in play, plan for ML2 from the outset rather than treating ML1 as a resting point; see our guide to DISP IT support in Canberra.

How Blue Arc IT Solutions helps

We run a gap assessment against ML1 as standard, implement and maintain the eight controls, and produce the evidence to prove it, application control included, which is usually the control clients most underestimate. Where a client needs to move to ML2, that is a scoped uplift project on top of the ML1 baseline. See our Essential Eight compliance overview, managed services, or get in touch.

Last reviewed: 11 August 2026, against ASD's Essential Eight maturity model, Appendix A.

Frequently asked questions

Does Maturity Level 1 include application control?

Yes. Application control on workstations is an ML1 requirement, not an ML2 addition. ML2 extends it to internet-facing servers, adds Microsoft's recommended blocklist, annual ruleset reviews and logging, but the control itself starts at ML1.

Is Maturity Level 1 enough for DISP membership?

No. DISP requires the full Essential Eight at Maturity Level 2 for every membership level. ML1 is a sensible baseline to build from, but Defence-industry businesses need to plan for ML2.

Is Maturity Level 1 the same as having antivirus and a firewall?

No. ML1 is eight coordinated strategies covering patching, MFA, administrative access, macros, browser hardening, application control and backups, assessed against specific timeframes and coverage. Antivirus and a firewall are a small part of a much broader baseline.