How this command is triggered — by the user, by Claude, or both
Slash command
/essential8:maturity-levelThe summary Claude sees in its command listing — used to decide when to auto-load this command
# Maturity Level Selection Helps determine the appropriate Essential 8 maturity level target based on organizational risk profile and requirements. ## Arguments - `$1` - Organization type (optional: government, critical-infrastructure, business, small-business) - `$2` - Risk profile (optional: high, medium, low) ## Maturity Level Decision Framework ### Maturity Level 1 (Partly Aligned) **Target Organizations**: - Small businesses with limited resources - Low-risk environments - Organizations starting cyber security journey - Non-critical systems **Threat Protection**: - Basic prote...
Helps determine the appropriate Essential 8 maturity level target based on organizational risk profile and requirements.
$1 - Organization type (optional: government, critical-infrastructure, business, small-business)$2 - Risk profile (optional: high, medium, low)Target Organizations:
Threat Protection:
Characteristics:
Implementation Time: 3-6 months typically
Target Organizations:
Threat Protection:
Characteristics:
Implementation Time: 6-12 months typically
Target Organizations:
Threat Protection:
Characteristics:
Implementation Time: 12-24 months typically
Non-corporate Commonwealth Entities (NCEs):
Corporate Commonwealth Entities (CCEs):
State/Territory Government:
Critical Infrastructure:
Costs vary significantly by organization size and current maturity
Recommended Path: ML1 → ML2 → ML3
Phase 1: Achieve ML1 (Months 1-6)
Phase 2: Progress to ML2 (Months 7-12)
Phase 3: Advance to ML3 (Months 13-24)
Benefits:
Do you handle classified information or operate critical infrastructure?
├─ YES → Target ML3
└─ NO → Continue
Are you a Commonwealth government entity?
├─ YES → ML3 (NCE) or ML2+ (CCE)
└─ NO → Continue
Are you a high-profile target or handle sensitive data at scale?
├─ YES → Target ML3
└─ NO → Continue
Do you have regulatory compliance requirements or business-critical systems?
├─ YES → Target ML2
└─ NO → Continue
Are you a small business or just starting cyber security journey?
├─ YES → Start with ML1, plan progression
└─ NO → Target ML2 as baseline
# Determine level for government agency
/essential8:maturity-level government high
# Assess appropriate level for small business
/essential8:maturity-level small-business low
# Critical infrastructure guidance
/essential8:maturity-level critical-infrastructure high
# General business assessment
/essential8:maturity-level business medium
2plugins reuse this command
First indexed Apr 26, 2026
npx claudepluginhub abnejllc/grc --plugin essential8/maturity-levelRecommends Essential 8 maturity level target (1-3) based on organization type (e.g., government, business) and risk profile (high, medium, low), with threat protection details and implementation guidance.