Skip to content
All insights
RFFR

The Essential Eight and RFFR: What Maturity Level Do You Actually Need?

CHAIOS GRC Practitioner·Governance, risk & compliance
Share

Ask a provider working through RFFR what maturity level they need on the Essential Eight and you will usually get a confident answer: Maturity Level One. That answer is right, and it is also the single most expensive misunderstanding in the whole cyber security expectation.

Maturity Level One is what the Department requires you to reach. It is not what the Department asks you to aim at. Those are different questions, and RFFR asks both.

This guide covers what DEWR actually expects on the Essential Eight, what the maturity levels really measure, and the traps that turn a reasonable cyber posture into audit findings.

The Essential Eight, briefly

The Essential Eight are eight mitigation strategies published by the Australian Signals Directorate (ASD), through the Australian Cyber Security Centre (ACSC), to reduce the impact of cyber security incidents. Under RFFR they are folded in as the practical cyber baseline sitting beneath your ISO 27001 management system and the ISM control set.

The eight, as the Department lists them:

  • Application control — stop unauthorised software executing.
  • Patch applications — remediate known vulnerabilities in application software.
  • Configure Microsoft Office macro settings — block untrusted macros.
  • Application hardening — remove unneeded functionality in Office, browsers and PDF viewers.
  • Restrict administrative privileges — limit who holds the keys, and how many keys exist.
  • Patch operating systems — remediate known vulnerabilities; don't run unsupported versions.
  • Multi-factor authentication — make stolen credentials insufficient on their own.
  • Regular backups — retain, isolate and test backups so you can actually recover.

None of that is exotic. The difficulty in RFFR is almost never understanding what the eight strategies are. It is evidencing what level you are at, deciding where you should be, and proving you have a credible route between the two.

What DEWR actually asks for

This is worth reading closely, because the Department's wording contains two separate obligations that providers routinely collapse into one.

The Department requires that providers initially implement controls supporting the Essential Eight to achieve Maturity Level One on the ACSC's published maturity model.

And, separately: providers are required to determine a target maturity level for each of the Essential Eight strategies that reflects the organisation's risk profile, and develop plans to achieve those target levels over time.

Read that again. Maturity Level One is the starting obligation — the word the Department uses is "initially". The actual expectation is a risk-based target you have set yourself, per strategy, with a plan to get there.

So when an assessor asks "what's your target maturity level?", the answer "Maturity Level One, because that's what RFFR requires" is not a good answer. It tells them you have read the floor and skipped the requirement. The Department has asked you to think about your own risk profile and reach a conclusion. "One, because we were told one" is the absence of that thinking.

The corollary matters too: if your target is above Maturity Level One, you need a plan, not an aspiration. A target with no dates, no owners and no funding is a finding waiting to happen — the same problem that turns a risk register into a wish list.

What the maturity levels actually measure

Here is where the mental model usually goes wrong. Most people read the maturity levels as a report card — Level One is a pass, Level Three is an A. That is not what they describe.

ASD defines four levels, Maturity Level Zero through Three. Apart from Level Zero, the levels are based on mitigating increasing levels of tradecraft and targeting — the tools, tactics, techniques and procedures an adversary brings, and how much effort they will spend on you specifically.

  • Maturity Level Zero signifies weaknesses in the organisation's overall posture that, if exploited, could compromise the confidentiality of data or the integrity or availability of systems.
  • Maturity Level One addresses adversaries content to use commodity tradecraft that is widely available — a public exploit against something you didn't patch, or credentials that were stolen, reused, brute-forced or guessed. Crucially, these actors are looking for any victim, not a specific victim.
  • Maturity Level Two addresses a modest step up: adversaries willing to invest more time in a target and in the effectiveness of their tools, using well-known tradecraft to try to bypass controls.
  • Maturity Level Three addresses adversaries more adaptive and far less reliant on public tools.

ASD's own framing is the useful bit: organisations should consider what level of tradecraft and targeting they are aiming to mitigate, rather than which malicious actors. So the target-setting question is not "how mature do we want to be?" It is: who would bother coming after us, how hard would they try, and what happens to our participants' data if they succeed?

For an employment services provider holding Protected and sensitive personal information about job seekers, that question is worth genuinely sitting with. Maturity Level One explicitly addresses opportunistic attackers looking for any victim. Whether that is the whole of your risk is a decision the Department has deliberately left with you — which is exactly what "right fit for risk" means.

Implement across all eight, not just your favourites

The most common technical mistake is uneven maturity: Level Two on multi-factor authentication because the IT team got there anyway, Level Zero on application control because it's hard.

ASD is explicit that this is the wrong shape. Because the strategies are designed to complement each other and cover different threats, organisations should plan to achieve the same maturity level across all eight strategies before moving on to higher levels. The guidance is to identify a target, then progressively implement each maturity level until you reach it.

A jagged profile — one strategy at Level Two, another at Level Zero — does not average out to Level One. It is a Level Zero posture with a good story attached, because the adversary simply walks through the gap. Under RFFR's Statement of Applicability, that gap has to be stated, and stated honestly.

Where the Essential Eight stops

Two boundaries are worth being clear about, because providers over-rely on the Essential Eight in both directions.

It is not the whole of DEWR's cyber expectation. The Department's cyber security core expectations require the Essential Eight plus information security risk management, information security monitoring (vulnerability and change management), a formal approach to managing cyber security incidents that addresses ISM guidance — including reporting incidents to external stakeholders, the Department among them — and restricted access controls. The Essential Eight is one of five things in that list, not a substitute for the other four. The core expectations cover the rest.

And it is not the ceiling. ASD is clear that Maturity Level Three is not the end of the road: adversaries exist beyond it, and additional mitigation strategies and controls need to be considered — including those from the ISM. Under RFFR that is not optional advice, because ISM controls are already in your Statement of Applicability regardless.

How this lands in your audit

One detail catches providers out. ASD states there is no requirement to have your Essential Eight implementation certified by an independent partyhowever, it may need to be assessed by one where that is required by a government directive or policy, by a regulatory authority, or as part of contractual arrangements.

RFFR is a contractual arrangement. So the general "you don't need this independently assessed" position is precisely the sentence that does not apply to you. Your Essential Eight posture will be looked at, and it needs the same evidentiary backbone as everything else in your ISMS: a current assessment of where you actually are, a documented target with reasoning that traces to your risk profile, and a treatment plan with owners and dates for the gap between them.

If you are still mapping out where this sits in the wider programme, the accreditation journey sets out the milestones this evidence has to be ready for.

One eye on the horizon: the Essentials series

Anything written about the Essential Eight in 2026 needs a caveat attached, because the framework is changing.

In June 2026 ASD opened consultation on what it calls the evolution of the Essential Eight. The proposal introduces a new Essentials series, expanding the current framework to give organisations "greater flexibility in how they implement cyber security, while still providing a clear path to achieving strong cyber resilience". The evolution of today's Essential Eight guidance becomes the first chapter — Essentials for enterprise IT — with further chapters to follow, reported as covering operational technology and cloud, and with agentic AI flagged as a possible chapter of its own. Consultation ran through ASD's Cyber Security Partnership Program portal and closed on 12 July 2026.

Worth being precise about the language here, because the reporting and the source differ in tone. ASD's own announcement frames this as an evolution. The sharper framing — that the Essential Eight will be deprecated at around 12 months and fully retired within 24 — comes from Chris Horlyck, head of cyber security resilience at the ACSC, speaking to iTnews. Both remain live through the transition. On the timeline reported, that puts deprecation around mid-2027 and retirement around mid-2028.

The reason is not that the Essential Eight failed. It was first published in 2017 for an on-premises, Windows-centred, perimeter-based world, and the emphasis is shifting from prescriptive, technology-specific controls toward outcomes and intent — which is what cloud, SaaS and shared-responsibility models actually require.

So what does this mean for RFFR? Today, nothing. Your obligation is contractual: it changes when the Department changes its published requirements, not when ASD publishes guidance. Maturity Level One and a risk-based target remain the expectation until DEWR says otherwise, and its resources are the place that will say so.

But two things are worth noting if you are planning beyond this milestone.

The direction of travel favours you. ASD states the new guidance is "grounded in the Information Security Manual" — and RFFR already mandates ISM-sourced controls in your Statement of Applicability. The two halves of RFFR's technical baseline are converging, not drifting apart. A provider who has built a defensible, current ISM control set is already standing where the new guidance is heading.

And none of this is a reason to wait. ASD is explicit that organisations already using the Essential Eight "can expect strong alignment with their existing controls and investments" — Horlyck's version being that the investment made under the Essential Eight "will still be relevant under the Essentials". Patching, multi-factor authentication, backups and administrative privilege are not about to stop mattering. Deferring work until the new series lands would mean failing your current contractual obligation in order to prepare for one that does not exist yet.

The one thing genuinely worth watching is the maturity model itself. Today's requirement is expressed as a level on a defined ladder. A shift toward prioritised, threat-informed, outcome-based mitigations may not carry that ladder across unchanged — and since RFFR's requirement is written in terms of "Maturity Level One on ACSC's published maturity model", the Department will have to say how it picks up the new series. Until it does, the current wording stands.

The bottom line

Maturity Level One is the Department's floor, not your finish line. The requirement that carries real weight is the one providers skim past: set a target maturity level for each of the eight strategies based on your own risk profile, and build a credible plan to reach it.

Get to Level One first — it is the baseline and there is no argument to be had about it. But bring a target you can defend, evidence for where you actually stand today, and a plan with names and dates on it. That is the difference between reciting the requirement and meeting it.

It is also, conveniently, the part that survives the transition to the Essentials series. Whatever the guidance ends up being called, an organisation that knows where it stands, has decided where it needs to be, and can show the plan between the two will be asked the same question in a different vocabulary — and will already have the answer.

References & sources

External sources are provided for reference and are maintained by their respective bodies. Always confirm current requirements against the official source.

About the author

CHAIOS GRC PractitionerGovernance, risk & compliance

Written by a governance, risk and compliance practitioner on the CHAIOS team who has run RFFR and ISO 27001 programmes end to end — from risk registers and Statements of Applicability to DEWR accreditation. These guides come from hands-on experience, not theory.