Home » Essential Eight Maturity
TRUSTED Pathway
Get to ACSC Essential Eight ML2 — with audit-ready evidence.
A Microsoft-aligned, evidence-led path to ML2 — built for State & Local Government, defence supply chain and SOCI mid-market.
Regulatory Trigger — Increased cyber insurance, customer due‑diligence, and board assurance requirements are pushing organisations to demonstrate Essential Eight ML2 with verifiable, auditable controls—not policy intent.
FAQ
Do we need an external assessor to confirm ML2?
PSPF entities and most regulated buyers expect an independent assessment. We produce ASD-format evidence packs and work with assessors of your choice; we do not self-attest.
How long to uplift to ML2 in practice?
A 180-day uplift is realistic for most AU mid-market estates already on Microsoft 365 E5. Timelines extend if application control or backup validation lag — both flagged early in the assessment.
How do you keep posture at ML2 once we get there?How do you keep posture at ML2 once we get there?
Always-On streams patch, macro and admin telemetry into Sentinel, alerts on drift, and produces a quarterly ML2 attestation with annual ML3 readiness review.
$0 customer cost when bundled with a Modern SecOps engagement.