The Essential Eight is becoming the Essentials

ASD has announced that the Essential Eight will be retired and replaced. If you are part-way through an uplift programme, the short answer is: keep going. Here is the longer one.

Printed pages of the ASD Information Security Manual on a desk

What was actually announced

On 24 June 2026 the Australian Signals Directorate announced that the Essential Eight will be replaced by a broader body of guidance called the Essentials series. The direct successor to the Essential Eight is the first chapter, Essentials for enterprise IT, with further chapters to follow covering operational technology, cloud and artificial intelligence.

ASD ran a consultation on that first chapter through the Cyber Security Partnership Program portal, which closed on 12 July 2026. On the reported timeline, the Essential Eight stays live and supported for now, begins to be deprecated around the middle of 2027, and is retired around the middle of 2028.

Two things follow from those dates, and they matter more than the announcement itself. The Essential Eight is still the current standard. And you have roughly a year before anything you have written down starts going out of date.

Why it is changing

The Essential Eight was designed for a world of conventional malware on managed Windows fleets inside a network you owned. It has aged well for what it covers and poorly for what it does not. The ACSC's own framing is blunt about it: the model started before cloud was a significant part of most environments, and an organisation with no cloud footprint today would be an unusual architecture.

That gap is real, and most people running Australian environments have felt it. Nothing in the eight strategies tells you how to configure a tenant, govern an identity provider, secure a SaaS integration, manage operational technology, or think about the data your staff are feeding into an AI assistant. Those are now the majority of the interesting risk in most environments we assess, and the framework was silent on all of them.

The second driver is rigidity. A fixed control set updated infrequently is a poor fit for threats that change quarterly. ASD's stated direction is toward prioritised, threat-informed mitigations rather than a static list.

What carries over

ASD has been explicit on this point: the investment you have made under the Essential Eight will still be relevant under the Essentials. That is not a consolation line. It reflects that the underlying controls are not controversial and are not being withdrawn.

Application control, patching applications, patching operating systems, configuring macro settings, hardening user applications, restricting administrative privileges, multi-factor authentication and regular backups do not stop being good ideas because the document containing them is renumbered. Everything you have built — the patch rings, the application control policy, the privileged access model, the restore testing schedule — continues to do its job.

What changes is the framing around them, the breadth of what else you are expected to cover, and quite possibly how you are asked to report on it.

The maturity model question

This is the part that matters most and is least settled.

Reporting on the announcement indicates ASD is decoupling threat-informed controls from a fixed maturity ladder. If that holds, Maturity Level One, Two and Three as a structure — the thing most Australian organisations have spent three years being measured against — may not survive into the Essentials in its current form.

We want to be careful here, because we have not seen ASD confirm the detail. What is published is the consultation and the chapter structure. The maturity-model position comes from statements reported at the announcement rather than from released guidance. Treat it as the direction of travel, not as settled fact.

The practical consequence is about language, not work. If your board papers, contracts, insurance responses or tender submissions commit you to "Maturity Level Two by June 2027", that sentence has a shelf life even though the underlying controls do not. Know where those sentences are written down.

What to do between now and then

  1. Do not pause an uplift programme. This is the most expensive mistake available right now. Waiting for the new framework means twelve to twenty-four months of not patching, not restricting admin rights and not testing restores, in exchange for a document that will ask you to do those things anyway.
  2. Find every place you have committed to a maturity level in writing. Cyber insurance questionnaires, government tenders, client contracts, board minutes, grant conditions. Make a list now. When the terminology changes you will want to know what you have promised and to whom, rather than discovering it at renewal.
  3. Prioritise controls that are obviously durable. Phishing-resistant MFA, tested backups, restricted administrative privileges and current patching are going to appear in any credible successor framework. Work on those is risk-free regardless of what the new chapters say.
  4. Start closing the gaps the Essential Eight never covered, because those are what the new chapters will address: tenant configuration, identity governance, SaaS integrations and third-party access, operational technology, and whatever your staff are currently doing with AI tools.
  5. Ask your provider what their transition plan is — and expect a straight answer about what changes for you commercially. If a provider sells you Essential Eight uplift as a product, they now have a product with an end date.

What nobody knows yet

It is worth being direct about the limits of what has been published, because there is already commentary treating this as more settled than it is.

  • How compliance obligations transfer. Essential Eight requirements are embedded in government policy, contracts and insurance products. Nothing published explains how those obligations move across, or on what date.
  • What replaces the maturity ladder, and whether existing assessments can be mapped forward or need redoing.
  • What the remaining chapters contain, or when they arrive. Only the enterprise IT chapter has been through consultation.
  • The exact retirement date. "Approximately twenty-four months" is a statement of intent, and intent moves.
A useful test: ask whoever owns cyber risk in your organisation to produce every document that names a specific Essential Eight maturity level, and who it was given to. If that takes longer than a day to answer, the transition is going to be harder than it needs to be — and that is true regardless of what ASD publishes next.

We will update this article as ASD releases the Essentials for enterprise IT chapter. In the meantime, the honest position is that the eight things are still the eight things, and the organisations that will handle this transition well are the ones already doing them.

Know where you stand before the framework moves

Our assessment scores you against the current Essential Eight maturity model and flags the gaps the new chapters are most likely to cover — cloud, identity and third-party access.