Reaching Essential Eight Maturity Level 1 takes 3 to 6 months for a small Australian business that runs technical configuration and staff security awareness training at the same time, based on implementation timelines Australian IT providers publish for 2026 engagements. Moving from Maturity Level 1 to Maturity Level 2 adds another 6 to 12 months, and a 20-50 person business should plan for $15,000 to $40,000 of implementation work in that second phase.
TL;DR
- Essential Eight Maturity Level 1 takes 3-6 months for a small business running training and technical controls in parallel in 2026.
- Moving from ML1 to ML2 adds another 6-12 months and commonly costs $15,000-$40,000 for a 20-50 person team.
- Essential Eight itself is eight technical strategies; staff training is not one of them but closes the human-error gap the framework leaves open.
- Assessments must run in order: ML1 has to be demonstrated before an ML2 assessment can start.
Why this matters
The Essential Eight is the Australian Signals Directorate's set of eight technical mitigation strategies: application control, patching applications, Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication and regular backups. None of the eight is "train your staff."
Most businesses running an Essential Eight rollout in 2026 pair it with an awareness program anyway, because MFA fatigue attacks, credential phishing and social engineering target the human layer the technical controls do not cover. A cyber security gap assessment is usually the first step — it shows which of the eight strategies you already meet, at what maturity level, before you commit to a rollout date.
How long does Essential Eight take to implement?
| Maturity level | Typical timeframe | Who it suits |
|---|---|---|
| ML0 | Not applicable — starting point | Organisations with significant gaps across most of the eight strategies |
| ML1 | 3-6 months from ML0 | Small to medium businesses; the ACSC's suggested baseline fit |
| ML2 | 6-12 months after ML1 is demonstrated | Businesses facing targeted threats, government suppliers, regulated industries |
| ML3 | Case by case, typically 12+ months after ML2 | High-value targets facing sophisticated adversaries |
Non-corporate Commonwealth entities are required to reach at least Maturity Level 2 under Australian Government policy. Private businesses face no legal mandate, but cyber insurers and enterprise customers increasingly expect ML1 evidence at a minimum, according to the official Essential Eight maturity model published by the ACSC.
Maturity Level 1: 3-6 months from a standing start
ML1 covers commodity-level threats — mass-market malware and generic phishing that hits any business with an internet connection. For a business already running Microsoft 365 or Google Workspace, most of the technical configuration can be done in a few weeks. The 3-6 month window mostly accounts for staff rollout: enrolling every employee in security awareness training, running the first phishing simulation cycle, and giving people time to adjust login habits without flooding the help desk.
Verdict: budget the full 3-6 months rather than the technical minimum. Rolling out MFA in a week and skipping the training cycle is how a business ends up with high password-reset ticket volume and no drop in click rates.
Maturity Level 2: 6-12 months after ML1
ML2 is built for organisations facing deliberate, targeted attacks rather than opportunistic ones. It tightens the same eight strategies — faster patch cycles, more granular application control, stricter privileged access reviews — and needs a full ML1 assessment on record before an ML2 assessment can start. That sequencing, plus the deeper technical work, is why moving from ML1 to ML2 usually takes longer than reaching ML1 in the first place.
Verdict: treat ML2 as a second project, scoped once ML1 is signed off, not an extension of the first.
Why Essential Eight timelines vary
- Cloud versus on-premises. A Microsoft 365 or Google Workspace environment configures faster than a business running its own servers and legacy line-of-business software.
- In-house IT versus managed provider. A provider that has run the assessment before moves faster than a first-time internal attempt.
- Number of legacy applications. Every unsupported or custom application needs its own exception, and exceptions take time to document.
- Staff training completion rate. A rollout stalls when training and phishing simulation enrolment lag the technical changes — MFA goes live before people know how to use it.
- Existing assessment cadence. A business with a 12-month assessment cycle already in place moves through each level faster than one starting from zero documentation.
Does Essential Eight require staff training?
No — training is not one of the eight strategies. But MFA adoption, phishing resistance and safe handling of macro-enabled documents all depend on staff behaviour, which is exactly where a scenario-based awareness program and a regular phishing simulation cadence earn their place in the rollout plan rather than sitting outside it.
Is Essential Eight mandatory for small business?
No. Essential Eight is mandatory only for non-corporate Commonwealth entities, which must reach at least Maturity Level 2. Private businesses adopt it voluntarily, usually because a cyber insurer, government tender or enterprise customer asks for evidence of a baseline security posture.
FAQ
How long does Essential Eight take to implement?
Reaching Maturity Level 1 takes 3-6 months for a small business in 2026, and moving from ML1 to ML2 adds another 6-12 months. Timelines depend on whether the environment is cloud-based and whether staff training runs alongside the technical rollout.
Is Essential Eight mandatory for small business?
No. Only non-corporate Commonwealth entities are required to reach Maturity Level 2. Private businesses adopt it voluntarily, often because an insurer, tender or enterprise customer asks for it.
Does Essential Eight require staff training?
Training is not one of the eight strategies, but MFA adoption and phishing resistance both depend on staff behaviour, so most 2026 rollouts run an awareness program alongside the technical work.
How much does it cost to reach Essential Eight Maturity Level 2?
A 20-50 person business should budget $15,000 to $40,000 in implementation work to move from Maturity Level 1 to Maturity Level 2, based on published Australian IT provider estimates.
Can a business skip straight to Maturity Level 2?
No. Assessments must run in order — Maturity Level 1 has to be demonstrated before a Maturity Level 2 assessment can begin.
How often does Essential Eight need reassessment?
At minimum every 12 months, and every six months for businesses actively working toward a higher maturity level, since controls can drift out of compliance through configuration changes and new devices.
One last thing
Essential Eight controls degrade quietly. A business that passed its Maturity Level 2 assessment six months ago can already be non-compliant if a new device rolled out without the same application-control profile, or a handful of accounts kept admin rights past their project end date. Building a recurring review into the calendar — not just the initial rollout — is what keeps the maturity level real instead of a one-time certificate.