AccreditAZ

← All articles

Essential Eight · 8 min read · Published 20 April 2026 · Reviewed 17 August 2026

Essential Eight Maturity Level 2: What It Actually Requires

Essential Eight Maturity Level 2 is significantly more demanding than Level 1. Here's what each mitigation strategy requires at ML2, and what organisations commonly get wrong.

Most NZ government agencies and critical infrastructure operators targeting Essential Eight compliance are working toward Maturity Level 2. ML2 is the level at which the ACSC considers an organisation to have addressed a significant proportion of adversary techniques — but it's substantially more demanding than ML1, and assessors regularly find gaps in organisations that believe they're compliant.

This post covers what each of the eight mitigation strategies actually requires at ML2, and where organisations most commonly fall short.

What ML2 means structurally

At ML1, controls address commodity threats — the low-skill, opportunistic attacks that make up the bulk of incident volume. At ML2, the controls are calibrated against more targeted adversaries who will actively probe for gaps in basic defences.

The ACSC defines ML2 as: "Aligned with the intent of the mitigation strategy." That's a significantly higher bar than ML1's "partly aligned" standard. Evidence requirements are more specific, exception management is more formal, and coverage gaps that would pass an ML1 review will fail at ML2.

Application control

ML1: Prevents execution of unapproved executables in standard user locations.

ML2 requires:

The most common gap: organisations implement AppLocker or equivalent for standard executable paths but leave PowerShell and script execution unconstrained for standard users.

Patch applications

ML1: Critical patches applied within one month.

ML2 requires:

Common gap: patch coverage is good for Tier 1 applications but incomplete for third-party components (browser extensions, plugins, Java, PDF readers) that are frequently exploited.

Configure Microsoft Office macro settings

ML2 requires:

Organisations running unmanaged macro policies or allowing unsigned macros from internal shares will fail ML2 assessment on this control.

User application hardening

ML2 requires:

Restrict administrative privileges

ML1: Admin accounts separate from standard user accounts.

ML2 requires:

The PAW requirement is frequently the hardest to implement operationally and the most common ML2 gap for agencies that have addressed the simpler account separation requirement.

Patch operating systems

ML2 requirements mirror patch applications:

Multi-factor authentication

ML2 requires:

Organisations using SMS-based MFA for privileged access will not meet ML2 for this control.

Regular backups

ML2 requires:

Cloud backups that are accessible from the same credentials as the primary environment do not meet the offline/immutable requirement.

Preparing for ML2 assessment

Before engaging an assessor, review:

  1. Application control coverage — run a test to confirm script execution is blocked for standard users
  2. Patch coverage — confirm third-party application patching is included in scope
  3. Privileged access — document PAW or equivalent implementation, confirm no admin account email or internet access
  4. MFA — audit all privileged accounts and confirm SMS OTP is not the sole second factor
  5. Backup isolation — confirm backups cannot be accessed or deleted from the primary environment

The ACSC Essential Eight Maturity Model documentation is the authoritative reference. The November 2023 update made material changes to ML2 and ML3 requirements — if your gap assessment was done against an earlier version, re-run it.

AccreditAZ maps your current control implementation against the current Essential Eight maturity model, identifies gaps by control and maturity level, and generates the evidence documentation required for assessment. If you're managing Essential Eight alongside NZISM, see our guide on multi-framework compliance to avoid duplicating effort across both. Start your assessment to see where you stand against ML2.

Manage your NZISM, ISO 27001, Essential Eight and PSR compliance in one place.

Start free trial →