What is Essential Eight Maturity Level 2, and what does it involve?
Maturity Level 2 is the middle tier of the ASD Essential Eight. It is aimed at adversaries willing to invest more time and better tooling than the opportunistic attackers Maturity Level 1 addresses. It is the level most regulated Australian businesses target, and it is the minimum Defence's Defence Industry Security Program (DISP) requires across ICT corporate systems for every level of membership, from Entry Level up.
What ML2 asks of your eight controls
At ML2 the eight controls are not just present, they are applied more broadly, enforced more strictly, and backed by logging and evidence. Two controls show the shift clearly. Application control is already required on workstations at ML1; ML2 extends it to internet-facing servers and to every execution location rather than just user profiles and temporary folders, adds Microsoft's recommended application blocklist, and requires annual ruleset reviews plus logging of every allowed and blocked execution. Patching applications works similarly: the widely cited 48-hour window for critical, internet-facing vulnerabilities already applies at ML1 and does not tighten at ML2. What actually changes is scope: ML2 brings every application into fortnightly vulnerability scanning and a one-month patch window, not just the office suites, browsers, email clients, PDF readers and security products ML1 covers. Multi-factor authentication extends from online services to privileged and unprivileged system logons with phishing-resistant methods, and administrator access, event logging and incident reporting move from good practice to enforced requirements. For the authoritative, current requirements, see ASD's Essential Eight maturity model, Appendices A and B.
Who needs ML2
ML2 is not a blanket legal requirement, but it is mandatory for DISP membership and is commonly specified in government and Defence-related contracts and tenders. Defence concluded transitional cyber assessments against the old Top Four on 15 November 2025: DISP members are now required to achieve and maintain the full Essential Eight at ML2 on an ongoing basis, assessed through the DISP Cyber Security Questionnaire as part of annual assurance, not just checked once at application. If you are bidding for Defence-related work, or handling sensitive client data, ML2 is usually the sensible target. See our DISP IT support in Canberra guide for the detail.
What the move to the Essentials series means
ML2 is the target today, but ASD has announced the Essential Eight will move to a new Essentials series over the next two years. ASD has confirmed that existing ML2 work maps across, so this is a reason to build controls tied to outcomes and risk rather than to a checklist. See is the Essential Eight being retired? for the detail and timeline.
How Blue Arc IT Solutions helps
We run a gap assessment against ML2, implement and maintain the controls, and keep the evidence current. For Defence-industry businesses we deliver this through our ML2 Uplift Program. See our what Essential Eight Maturity Level 1 involves for the baseline this builds on, our Defender for Business vs Defender for Endpoint comparison for the Microsoft 365 tooling side, DISP IT support in Canberra, managed services, or get in touch.
Frequently asked questions
How is Maturity Level 2 different from Maturity Level 1?
ML1 addresses opportunistic attackers using widely available tools. ML2 steps up to adversaries willing to invest more time and better tooling, so controls are applied more broadly, enforced more strictly, and backed by logging and evidence.
Is Essential Eight ML2 mandatory?
It is not a blanket legal requirement for every business, but it is mandatory for DISP membership and is frequently specified in government and Defence-related contracts and tenders.
Does DISP require ML2?
Yes. The full Essential Eight at Maturity Level 2 is the minimum for every DISP membership level, including Entry Level, across the ICT systems used to correspond with Defence, under DSPF Principle 16, Control 16.1, Annex A. Defence concluded transitional assessments against the old Top Four on 15 November 2025; members must now achieve and maintain the full ML2 standard, not just reach it once.
Last reviewed: 11 August 2026, against ASD's Essential Eight maturity model and Defence's DISP cyber and assurance guidance.