Back to Frameworks

ACSC Essential Eight

Australia
8 domains
24 controls

Australian Cyber Security Centre Essential Eight Maturity Model: eight prioritised mitigation strategies with three maturity levels.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (8)

Application Control

3 controls
Controls in the Application Control domain of ACSC Essential Eight3 controls
CodeTitle
E8-APP-ML1Application Control (ML1)
E8-APP-ML2Application Control (ML2)
E8-APP-ML3Application Control (ML3)

Configure Microsoft Office Macro Settings

3 controls
Controls in the Configure Microsoft Office Macro Settings domain of ACSC Essential Eight3 controls
CodeTitle
E8-MACRO-ML1Configure Microsoft Office Macro Settings (ML1)
E8-MACRO-ML2Configure Microsoft Office Macro Settings (ML2)
E8-MACRO-ML3Configure Microsoft Office Macro Settings (ML3)

Multi-factor Authentication

3 controls
Controls in the Multi-factor Authentication domain of ACSC Essential Eight3 controls
CodeTitle
E8-MFA-ML1Multi-Factor Authentication - Maturity Level 1
E8-MFA-ML2Multi-Factor Authentication - Maturity Level 2
E8-MFA-ML3Multi-Factor Authentication - Maturity Level 3

Patch Applications

3 controls
Controls in the Patch Applications domain of ACSC Essential Eight3 controls
CodeTitle
E8-PATCHAPP-ML1Patch Applications (ML1)
E8-PATCHAPP-ML2Patch Applications (ML2)
E8-PATCHAPP-ML3Patch Applications (ML3)

Patch Operating Systems

3 controls
Controls in the Patch Operating Systems domain of ACSC Essential Eight3 controls
CodeTitle
E8-PATCHOS-ML1Patch Operating Systems (ML1)
E8-PATCHOS-ML2Patch Operating Systems (ML2)
E8-PATCHOS-ML3Patch Operating Systems (ML3)

Regular Backups

3 controls
Controls in the Regular Backups domain of ACSC Essential Eight3 controls
CodeTitle
E8-BACKUP-ML1Regular Backups (ML1)
E8-BACKUP-ML2Regular Backups (ML2)
E8-BACKUP-ML3Regular Backups (ML3)

Restrict Administrative Privileges

3 controls
Controls in the Restrict Administrative Privileges domain of ACSC Essential Eight3 controls
CodeTitle
E8-ADMIN-ML1Restrict Administrative Privileges (ML1)
E8-ADMIN-ML2Restrict Administrative Privileges (ML2)
E8-ADMIN-ML3Restrict Administrative Privileges (ML3)

User Application Hardening

3 controls
Controls in the User Application Hardening domain of ACSC Essential Eight3 controls
CodeTitle
E8-UAH-ML1User Application Hardening - Maturity Level 1
E8-UAH-ML2User Application Hardening - Maturity Level 2
E8-UAH-ML3User Application Hardening - Maturity Level 3

Your Compliance Coverage

If you comply with ACSC Essential Eight, you already cover:

Maps to 36 other frameworks

24 total controls
NIST SP 800-53 Rev 5 MODERATE
24 source controls mapped|47 target controls covered
100%
FedRAMP Moderate
24 source controls mapped|62 target controls covered
100%
NIST SP 800-53 Revision 5.1 HIGH
24 source controls mapped|47 target controls covered
100%
FedRAMP High
24 source controls mapped|62 target controls covered
100%
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
24 source controls mapped|40 target controls covered
100%
Azure Security Benchmark
24 source controls mapped|39 target controls covered
100%
CIS Controls v8
24 source controls mapped|44 target controls covered
100%
ASD Strategies to Mitigate Cyber Security Incidents
24 source controls mapped|19 target controls covered
100%
NIST SP 800-53 Rev 5
24 source controls mapped|36 target controls covered
100%
NIST SP 800-53 Rev 5 LOW
22 source controls mapped|25 target controls covered
92%
CMMC 2.0
22 source controls mapped|39 target controls covered
92%
C5 (Germany)
21 source controls mapped|26 target controls covered
88%
NIST Cybersecurity Framework 2.0
20 source controls mapped|32 target controls covered
83%
ISO 27002:2022
20 source controls mapped|31 target controls covered
83%
ISO 27001:2022
20 source controls mapped|31 target controls covered
83%
NIST SP 800-171 Rev 3
20 source controls mapped|32 target controls covered
83%
SOC 2
19 source controls mapped|17 target controls covered
79%
HIPAA Security Rule
18 source controls mapped|25 target controls covered
75%
NIST SP 800-66 Rev 2
18 source controls mapped|25 target controls covered
75%
NIST SP 800-161 Rev 1
18 source controls mapped|17 target controls covered
75%
PCI DSS 4.0
18 source controls mapped|37 target controls covered
75%
Australian Information Security Manual
15 source controls mapped|57 target controls covered
63%
NIST SP 800-171
15 source controls mapped|4 target controls covered
63%
AWS Well-Architected Security Pillar
14 source controls mapped|21 target controls covered
58%
ANSSI Guide d'hygiene informatique (42 mesures, v2.0)
14 source controls mapped|20 target controls covered
58%
38%
SWIFT CSCF
9 source controls mapped|3 target controls covered
38%
Defence Industry Security Program (DISP)
8 source controls mapped|1 target controls covered
33%
ASIC Cyber Resilience Good Practices
8 source controls mapped|1 target controls covered
33%
Critical Infrastructure Risk Management Program (CIRMP) Rules 2023
7 source controls mapped|1 target controls covered
29%
Australia Consumer Data Right - Banking (CDR)
5 source controls mapped|3 target controls covered
21%
SQF Code Edition 9 - Safe Quality Food
3 source controls mapped|1 target controls covered
13%
ISO 19011
3 source controls mapped|1 target controls covered
13%
Australian Energy Sector Cyber Security Framework (AESCSF)
3 source controls mapped|2 target controls covered
13%
BRCGS Global Standard for Food Safety Issue 9
3 source controls mapped|1 target controls covered
13%
ISO 22301:2019
2 source controls mapped|6 target controls covered
8%

Frequently Asked Questions

What is ACSC Essential Eight?

ACSC Essential Eight is a compliance framework from Australia with 8 domains and 24 controls. Australian Cyber Security Centre Essential Eight Maturity Model: eight prioritised mitigation strategies with three maturity levels. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ACSC Essential Eight have?

ACSC Essential Eight has 24 controls organised across 8 domains. The largest domains are Application Control (3 controls), Configure Microsoft Office Macro Settings (3 controls), Multi-factor Authentication (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ACSC Essential Eight map to?

ACSC Essential Eight maps to 36 other compliance frameworks. The top mapping partners are NIST SP 800-53 Rev 5 MODERATE (100% coverage), FedRAMP Moderate (100% coverage), NIST SP 800-53 Revision 5.1 HIGH (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ACSC Essential Eight compliance?

Start your ACSC Essential Eight compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ACSC Essential Eight requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 24 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required