The Essential Eight backup requirements are the part of the framework most businesses assume they already meet, right up until an assessor asks them to prove it. Everyone has "a backup". Far fewer can show that it restores to a known point in time, that it survives a compromised admin account, and that someone has actually tested a recovery this year. That gap between having a backup and meeting the standard is where most maturity assessments quietly come undone.
This is a plain-English walk through what the Australian Signals Directorate actually asks of your backups at Maturity Levels One, Two and Three, which controls an assessor checks, and how the products we distribute map onto each level. Everything here is drawn from the live Essential Eight Maturity Model on cyber.gov.au, last updated in November 2023, rather than an older version doing the rounds.
What the Essential Eight backup requirements actually say
Regular Backups is one of the eight mitigation strategies, sitting alongside application control, patching, MFA and the rest. The ASD is clear that the eight are meant to work as a set: you pick a target maturity level and reach it across all eight strategies before climbing to the next one, rather than running one control at Level Three and the others at Level One.
The first thing worth clearing up is a myth. Plenty of older checklists insist Level One means "daily backups". The current model says no such thing. The wording is that backups of data, applications and settings are "performed and retained in accordance with business criticality and business continuity requirements". In other words, your backup frequency and retention are driven by your own recovery objectives, not a fixed number handed down by the ACSC. A system that can tolerate a day of data loss and one that can tolerate an hour are held to different practical standards, and both can be compliant.
That single reframe changes how you scope the work. The question stops being "are we backing up nightly?" and becomes "have we defined what each system is worth, and does our backup match it?" Assessors want to see that thinking, not just a green tick in a backup console.
In practice that means writing down a recovery point objective and a recovery time objective for each class of system (how much data you can afford to lose, and how long you can afford to be down), then showing your backup schedule and retention were built to hit them. A finance system feeding an EOFY deadline and a shared drive of old marketing assets do not warrant the same regime, and the model is comfortable with that. What it will not forgive is a business that has never made the call at all, because without a stated objective there is nothing for "in accordance with business criticality" to be measured against.
The controls auditors actually check
At Maturity Level One, the Regular Backups strategy breaks into six things an assessor looks for. Backups are performed and retained in line with business criticality. They are synchronised so you can restore multiple systems to a common point in time, which matters the moment an application and its database live on different machines. They are held in a "secure and resilient manner". Restoration to that common point in time is tested as part of disaster recovery exercises. And on the access side, unprivileged user accounts cannot reach backups belonging to other accounts, and cannot modify or delete backups at all.
Two of those six trip people up more than the rest. The testing control is not satisfied by a backup job reporting success; it wants evidence of an actual restore. And "secure and resilient" is where immutability and separation from production earn their place, because a backup a ransomware operator can encrypt or delete along with everything else is neither.
Maturity Level Two keeps all of that and tightens the account model. Now privileged user accounts, with the deliberate exception of backup administrator accounts, also cannot access other accounts' backups and cannot modify or delete them. The logic is that a standard admin login, the kind attackers work hard to steal, should not be a master key to your last line of defence.
Maturity Level Three goes further again. Unprivileged and privileged accounts cannot access even their own backups. And in the control that catches the most systems, backup administrator accounts themselves are "prevented from modifying and deleting backups during their retention period". At Level Three the retention window is effectively locked: not even the backup admin can shorten it, which is precisely the behaviour immutable and air-gapped storage is built to deliver.
Read across the three levels and the pattern is clear. The backup-and-restore mechanics barely change; what hardens at each step is who can touch the backups and whether anyone, including your most trusted account, can quietly destroy them.
Mapping the levels to real products
No single product "makes you Essential Eight compliant". Compliance is an outcome of process plus tooling. But the right platform removes most of the friction, and the portfolio maps onto these controls cleanly.
For SaaS data, Keepit covers the workloads that increasingly hold a business's crown jewels (Microsoft 365, Entra ID, and more) with an immutable, tamper-proof store that sits outside the customer's own tenant. That architecture speaks directly to the Level Three requirement that no account, backup admin included, can alter or delete data inside its retention period, and for Australian buyers it can keep that copy in a Sydney data centre. It is the kind of separation the "secure and resilient" control is really asking for.
For virtual and physical infrastructure, NAKIVO Backup & Replication handles VMware, Hyper-V, Proxmox, physical servers and Microsoft 365 from one console, with immutable local and cloud repositories and, importantly for the testing control, automated recovery verification that boots a backup and confirms it actually comes up. That is the difference between a job that says "success" and evidence you can hand an assessor.
For on-premises resilience and true air-gapping, StoneFly appliances provide immutable, WORM-capable and air-gapped backup targets. Where a control demands that a retention period cannot be shortened by any human account, dedicated storage that enforces immutability at the appliance level is the most defensible answer.
The point is not that one of these ticks every box. It is that a coherent stack does: a SaaS backup for cloud data, a virtualisation-aware platform for your servers, and immutable storage underneath both. Put together, they let you satisfy the access and resilience controls without heroics. Our backup and disaster recovery practice exists to help partners assemble that stack for a specific environment rather than guess at it.
Common failure points in assessments
A few things sink backup assessments over and over, and none of them are exotic.
The restore that was never tested is the classic. The control asks for restoration tested during disaster recovery exercises; a lot of businesses can produce a year of successful backup logs and not a single documented restore. If you do one thing after reading this, schedule and record a test recovery.
The backup an attacker can delete is the next. If your backups sit on the same domain, reachable by the same admin credentials that run production, a single compromised account takes your recovery with it. Levels Two and Three exist specifically to close that door, and immutability or air-gapping is how you close it.
Then there is the coverage gap. Teams protect their VMs diligently and forget that Microsoft 365, Entra ID and SaaS platforms are theirs to back up, not Microsoft's. The Essential Eight does not carve out cloud data, and neither should your scope.
Finally, uneven maturity. Because the ASD wants the same level across all eight strategies, a gold-plated backup regime sitting next to Level One patching still assesses at Level One overall. Backups are rarely the strategy holding an organisation back, but they should not be the one that gives a false sense of progress either.
Beyond backups: where SMB1001 fits
The Essential Eight is a maturity model, not a certificate. You self-assess or bring in an assessor, but there is no badge at the end to show a customer or an insurer. For many small and medium Australian businesses that want something certifiable and proportionate, SMB1001 is the more practical starting point, and its tiers fold sensible backup practices into a scheme you can actually be certified against. The two are complementary: SMB1001 gives smaller organisations a graded, provable path, while the Essential Eight remains the reference the ACSC, and a growing number of contracts, measure against.
Wherever you land, the backup requirements come down to the same three questions. Can you restore to a known point in time? Can anyone, including a stolen admin login, destroy your backups? And have you proven the restore works lately? Answer those honestly and the maturity level tends to sort itself out.
If you would like a hand mapping a client's environment to a maturity level, or building a backup stack that holds up under assessment, talk to the CRS team. It is the conversation we have with partners most weeks.
