Skip to content
    Back to Regulatory Radar
    ImportantFramework UpdateNovember 27, 2023

    Australian Essential Eight Maturity Model Updated

    The Australian Signals Directorate's Australian Cyber Security Centre (ACSC) released an updated Essential Eight Maturity Model, refining maturity level definitions and tightening requirements across all eight mitigation strategies. Key changes include a 48-hour patching timeline for vulnerabilities in internet-facing services across Maturity Levels 1 through 3 when a vendor assesses the vulnerability as critical or a working exploit exists, weekly rather than fortnightly vulnerability scanning for critical vulnerabilities, strengthened and phishing-resistant multi-factor authentication requirements, and annual application control ruleset reviews incorporating Microsoft's recommended block rules. The Essential Eight remains the baseline security standard referenced by IRAP assessments for Australian government cloud services.

    IRAPSaaSDefense

    Key Analytics

    November 27, 2023
    Event Date
    Time Remaining
    August 1, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Organizations assessed under IRAP or seeking to maintain their Essential Eight maturity level must review the updated requirements, as controls previously meeting a given maturity level may no longer satisfy the tightened criteria. The 48-hour patching requirement for critical or actively exploited vulnerabilities in internet-facing services applies from Maturity Level 1 upward and is particularly impactful for organizations with complex change management processes. Cloud service providers targeting Australian government contracts should expect IRAP assessors to evaluate against the updated maturity model definitions immediately.

    Recommended Actions

    • Reassess current Essential Eight maturity level against the updated model definitions and identify any controls that have regressed due to tightened criteria
    • Evaluate patching workflows to determine feasibility of meeting the 48-hour timeline for critical or exploited vulnerabilities in internet-facing services, which applies at all maturity levels
    • Update MFA implementations to meet the strengthened requirements, including phishing-resistant MFA for privileged access and internet-facing authentication endpoints
    • Move vulnerability scanning for critical vulnerabilities to at least a weekly cadence

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant90-180 hours
    Key Workstreams
    • Reassessment against the tightened maturity level definitions to find regressed controls
    • Patching workflow rework to meet the 48-hour timeline for exploited internet-facing vulnerabilities
    • MFA hardening to phishing-resistant methods for privileged access
    • Vulnerability scanning cadence increase to weekly for critical vulnerabilities

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 90-180 hours
    Start cold under pressureMajor · 200-450 hours

    Roughly 110 to 270 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events