ACSC L2 (v2022)
Overview of ACSC Essential Eight Level 2
Essential Eight Maturity Level 2 represents a significant advancement beyond the baseline Level 1 controls, providing enhanced protection against sophisticated cyber threats and targeted attacks. Released as part of the 2022 Maturity Model update, Level 2 extends security controls to servers, accelerates patching timelines, broadens multi-factor authentication coverage, and introduces automated vulnerability scanning. Organizations achieving Level 2 maturity demonstrate a robust cybersecurity posture capable of defending against advanced persistent threats, targeted intrusions, and the majority of cybercrime campaigns.
The 2022 Essential Eight Maturity Model refined Level 2 requirements to address evolving threat landscapes including widespread ransomware campaigns, supply chain compromises, and increasingly sophisticated phishing operations. Level 2 is the recommended target for most Australian organizations, particularly those in government, critical infrastructure, healthcare, financial services, and large enterprises. While Level 1 provides foundational protection, Level 2 delivers the control depth and coverage necessary for resilient cyber defense in hostile threat environments where organizations face determined adversaries using publicly available attack techniques.
Key Enhancements Over Level 1
Essential Eight Level 2 builds upon Level 1 foundations by expanding control scope, accelerating response timelines, and increasing automation. Understanding these enhancements helps organizations plan Level 2 implementations and allocate resources appropriately.
Extended Application Control to Servers
While Level 1 requires application control only on workstations, Level 2 extends this critical requirement to servers. Organizations must implement application whitelisting on internet-facing servers and servers processing or storing sensitive information. This dramatically reduces server compromise risk by preventing unauthorized code execution—a common attack vector in server breaches and ransomware campaigns. Server application control is particularly effective against web shells, backdoors, cryptocurrency miners, and malware deployed after initial compromise through vulnerability exploitation.
Accelerated Patching Timelines
Level 2 tightens patching requirements significantly compared to Level 1. Security vulnerabilities in applications must be patched within two weeks regardless of exploit status (Level 1 allows two weeks only when exploits exist), and operating system patches must be deployed within two weeks as well (Level 1 allows one month). These aggressive timelines minimize exposure windows that attackers exploit between vulnerability disclosure and organizational patching. Organizations need automated patch testing and deployment capabilities to meet Level 2 patching requirements consistently across complex environments.
Broader Multi-Factor Authentication Coverage
Level 2 mandates MFA for all users when accessing important data repositories, not just remote access scenarios. This includes cloud services, file servers, databases, customer relationship management systems, and any system storing or processing sensitive business or customer information. Organizations must identify all important data repositories through data classification exercises and ensure MFA protects access from any location—not just remote access scenarios covered by Level 1. This prevents credential-based attacks from succeeding even when attackers compromise passwords through phishing, password spraying, or credential stuffing attacks.
Automated Vulnerability Scanning
Level 2 introduces requirements for vulnerability scanning of internet-facing services at least daily (or continuously). Automated scanning identifies newly disclosed vulnerabilities rapidly, enabling prioritized remediation before attackers can weaponize and exploit them. Organizations should implement vulnerability management platforms that integrate with patch management systems to create closed-loop processes from identification through remediation verification. Daily scanning ensures organizations detect and address vulnerabilities before attackers mass-scan the internet for vulnerable systems following public vulnerability disclosures.
Enhanced Backup Testing and Verification
Beyond Level 1's backup requirements, Level 2 mandates restoration testing to verify backup integrity and usability. Organizations must test restoration processes at least once during initial implementation and after significant infrastructure changes that could impact backup functionality. Untested backups frequently fail during ransomware recovery scenarios—making restoration testing critical to business resilience. Organizations should document restoration procedures, measure recovery time objectives (RTOs) and recovery point objectives (RPOs), train personnel on restoration processes, and maintain playbooks for common recovery scenarios.
Framework Applicability and Adoption
Essential Eight Level 2 is the recommended target maturity for most Australian organizations, particularly those in government, critical infrastructure, healthcare, financial services, and large enterprises handling customer data or intellectual property. The ACSC considers Level 2 appropriate for organizations facing adversaries conducting targeted intrusions using publicly available techniques and tools. This includes most financially motivated cybercrime groups, hacktivists, and less sophisticated nation-state actors employing commodity malware and attack frameworks.
Government agencies and critical infrastructure operators should implement Level 2 at minimum, with many advancing to Level 3 for high-value systems and sensitive data. Private sector organizations handling customer data, intellectual property, financial information, or regulated data benefit significantly from Level 2 protections. Cyber insurance providers increasingly expect Level 2 implementation for preferred coverage terms, with premiums and coverage limits reflecting Essential Eight maturity levels. Organizations demonstrating Level 2 maturity often receive favorable underwriting terms recognizing reduced cyber risk exposure.
Implementation Strategies and Best Practices
Successfully advancing from Level 1 to Level 2 requires strategic planning, expanded tooling, and often additional cybersecurity resources. Organizations should approach Level 2 implementation systematically, addressing prerequisites and building necessary capabilities before full deployment across the enterprise.
Assess Current Level 1 Maturity: Ensure solid Level 1 implementation before pursuing Level 2. Gaps in Level 1 controls will complicate Level 2 deployment and reduce effectiveness of enhanced controls. Conduct honest self-assessments using ACSC evaluation methodologies to validate Level 1 achievement across all eight strategies. Organizations attempting Level 2 without mature Level 1 foundations often struggle with complexity, experience control failures, and fail to achieve meaningful security improvements. Address Level 1 gaps before committing resources to Level 2 enhancements.
Prioritize Server Application Control: Server application control represents one of the most significant Level 2 additions and typically requires substantial effort for implementation and ongoing maintenance. Begin with internet-facing servers and those processing sensitive data. Create comprehensive server application inventories, test whitelisting rules in monitor mode before enforcement to identify false positives, and establish change management processes for legitimate application updates. Consider containerization or immutable infrastructure approaches that simplify application control on servers by reducing the number of applications requiring management.
Automate Patch Management Processes: Level 2's two-week patching timeline for both applications and operating systems demands extensive automation. Implement enterprise patch management platforms that automate testing through representative test environments, approval workflows with risk-based prioritization, and phased deployment to production systems. Create representative test environments that mirror production configurations for patch validation. Establish risk-based patching prioritization that addresses critical vulnerabilities affecting internet-facing systems first while scheduling less urgent patches systematically. Organizations unable to automate patching comprehensively struggle to maintain Level 2 compliance consistently.
Expand MFA Infrastructure: Moving beyond remote access MFA to cover all important data repositories requires identity and access management (IAM) infrastructure capable of enforcing MFA across diverse systems. Consider cloud-based identity providers, single sign-on (SSO) solutions, and federated authentication that simplify MFA deployment and user experience. Inventory all systems storing or processing important data through data classification initiatives and develop phased MFA rollout plans prioritizing highest-value targets. Provide users with multiple MFA options including authenticator apps, hardware tokens, and biometrics to balance security requirements with usability considerations.
Relationship to Other Frameworks and Standards
Essential Eight Level 2 aligns closely with international cybersecurity frameworks and standards, enabling organizations to satisfy multiple compliance requirements efficiently. Level 2 controls map comprehensively to ISO 27001 Annex A controls, particularly in access control (A.9), cryptography (A.10), operations security (A.12), and communications security (A.13). Organizations pursuing ISO 27001 certification can leverage Essential Eight implementations as evidence of control effectiveness for certification audits.
The NIST Cybersecurity Framework aligns well with Level 2 requirements across Protect, Detect, and Respond functions. Essential Eight strategies map to NIST CSF subcategories including PR.AC (Identity Management and Access Control), PR.DS (Data Security), PR.IP (Information Protection Processes and Procedures), DE.CM (Security Continuous Monitoring), and RS.RP (Response Planning). Organizations using NIST CSF can demonstrate Essential Eight alignment through CSF implementation profiles and maturity assessments.
The CIS Controls share significant overlap with Essential Eight Level 2, particularly CIS Controls 2 (Inventory and Control of Software Assets), 3 (Data Protection), 4 (Secure Configuration of Enterprise Assets and Software), 5 (Account Management), 6 (Access Control Management), 7 (Continuous Vulnerability Management), and 10 (Malware Defenses). Organizations implementing CIS Controls Implementation Group 2 (IG2) have completed much of the technical work necessary for Essential Eight Level 2 compliance.
Organizations can reference related frameworks including Essential Eight Level 1 as the foundation, Essential Eight Level 3 as the advanced maturity target, NIST SP 800-53 for federal system alignment, and PCI DSS for payment card data protection requirements.
Common Challenges and Solutions
Organizations transitioning from Level 1 to Level 2 encounter predictable challenges related to expanded scope, tighter timelines, increased automation requirements, and managing user experience impacts. Proactive planning and proven approaches help overcome these obstacles and achieve sustainable Level 2 implementations.
Server Application Control Resistance: Server administrators often resist application control due to concerns about operational impact, change management overhead, and potential for service disruptions. Mitigate resistance through comprehensive testing in non-production environments, phased rollouts beginning with least critical servers, clear exception processes for legitimate business needs, and executive messaging emphasizing security benefits and regulatory drivers. Consider application control solutions designed specifically for servers that understand typical server application patterns, support common server workloads, and minimize false positives requiring exception processing.
Patch Management at Scale: Meeting two-week patching requirements across large, heterogeneous environments challenges many organizations with complex application portfolios and limited maintenance windows. Solutions include segmenting environments to isolate patching failures and limit blast radius, implementing canary deployment approaches that test patches on small populations before broader rollout, creating expedited approval processes for critical patches affecting internet-facing systems, and accepting compensating controls such as network isolation or enhanced monitoring for legacy systems that cannot be patched within required timeframes. Organizations should track patching metrics including time-to-patch and patch coverage to identify improvement opportunities.
MFA User Experience Challenges: Expanding MFA beyond remote access creates user friction that generates helpdesk calls and temporary productivity impacts. Improve user experience through passwordless authentication where possible, risk-based authentication that only prompts for MFA during high-risk activities or from unrecognized devices, persistent MFA sessions that don't require repeated authentication for trusted devices, and comprehensive user training explaining security benefits and proper usage. Select MFA solutions offering excellent user experience and multiple authentication method options to accommodate diverse user populations and use cases.
Frequently Asked Questions
What are the main differences between Level 1 and Level 2?
Level 2 expands application control from workstations to include servers, reduces patching timelines to two weeks for both applications and operating systems regardless of exploit status, extends MFA requirements to all users accessing important data repositories beyond just remote access, introduces daily vulnerability scanning requirements for internet-facing services, and mandates backup restoration testing. These enhancements provide significantly stronger protection against sophisticated threats including targeted attacks, ransomware, and advanced persistent threats compared to Level 1 baseline controls.
How long does it typically take to advance from Level 1 to Level 2?
Organizations with mature Level 1 implementations typically require 6-12 months to achieve Level 2, depending on environment complexity, organizational size, and available resources. Server application control deployment often represents the longest-duration activity requiring extensive planning, testing, and phased rollout. Organizations should plan phased implementations rather than attempting simultaneous deployment across all strategies and all systems. Progressive advancement to Level 2 over 9-12 months allows organizations to manage change effectively, address user concerns, and ensure sustainable operations without overwhelming IT and security teams.
Is Level 2 sufficient for most organizations?
Level 2 provides robust protection appropriate for most Australian organizations, including government agencies, critical infrastructure operators, healthcare providers, financial institutions, and large enterprises. The ACSC considers Level 2 effective against adversaries using publicly available techniques and tools—covering the vast majority of cybercrime threats and many nation-state actors. Organizations facing highly sophisticated adversaries, protecting classified or highly sensitive information, or operating in critical infrastructure sectors with national security implications should consider Level 3. However, Level 2 represents significant cybersecurity maturity that exceeds most adversary capabilities when implemented comprehensively and maintained consistently.
Can organizations implement Level 2 without completing Level 1 first?
While technically possible, attempting Level 2 without solid Level 1 foundations is not recommended and rarely succeeds. Level 2 assumes organizations have matured Level 1 capabilities, built necessary operational processes, developed organizational competencies, and established security culture supporting comprehensive control implementation. Organizations skipping Level 1 often struggle with Level 2 complexity, experience higher failure rates, and fail to achieve sustainable implementations. The Essential Eight is designed as a maturity progression model—each level builds upon previous level capabilities, lessons learned, and organizational maturity. Organizations should complete Level 1 comprehensively before committing to Level 2.
What resources are needed for Level 2 implementation?
Level 2 typically requires additional security personnel (1-2 FTEs for medium organizations, 3-5 FTEs for large enterprises), enhanced security tooling including enterprise application control solutions supporting servers, automated patch management platforms, vulnerability scanners capable of daily scanning, MFA infrastructure supporting diverse systems, and backup solutions with automated testing capabilities. Budget allocations typically increase from 3-5% of IT spending at Level 1 to 5-7% at Level 2, though percentages vary by industry, organizational size, and existing security investments. Consider managed security service providers (MSSPs) for capabilities like 24/7 vulnerability monitoring, patch management, and security operations that may be cost-prohibitive to develop internally.