What does it actually take for a supplier org to achieve ML2 for practice rules twelve
Practice Twelve incident response planning and testing is one of the most misunderstood Essential Eight strategies for supplier organisations. Many teams assume a documented plan is enough. Assessors are looking for evidence that the plan works in practice.
Why supplier orgs stall at ML1
At Maturity Level 1, having an incident response plan on paper satisfies the baseline. Moving to ML2 requires demonstrable implementation: defined roles, tested procedures, and evidence that lessons learned feed back into the program.
Supplier organisations often struggle because:
- Incident response is treated as an IT-only function
- Tabletop exercises are infrequent or not documented
- Playbooks exist but are not aligned to actual systems and data flows
What ML2 evidence looks like
Assessors typically expect to see:
- Assigned ownership: named roles for detection, containment, eradication, and recovery
- Tested playbooks: evidence of exercises within the last 12 months, with outcomes recorded
- Integration with backup and logging: response procedures reference the controls you already operate
- Supplier-specific scenarios: exercises that reflect your actual client data, integrations, and obligations