The Australian Signals Directorate has confirmed it is replacing the ASD Essential Eight with a new Essentials series. But this is an evolution, not a demolition — and the worst response available to an Australian business is to stop work.
- The ASD is retiring the Essential Eight and replacing it with a new Essentials series; the first chapter is Essentials for enterprise IT.
- National consultation ran 15 June – 12 July 2026. Deprecation is indicated at roughly 12 months, retirement at roughly 24 months — but no retirement date has been published.
- The Essential Eight remains in force today. Nothing you have implemented is wasted — the controls carry across.
- The shift is from prescriptive controls on a fixed maturity ladder to outcome-focused, threat-informed controls that work across cloud, SaaS and operational technology.
What the ASD has actually announced
The Australian Signals Directorate intends to retire the Essential Eight cyber security framework and replace it with the Essentials series. The first chapter is Essentials for enterprise IT, and it was the subject of national consultation through the Australian Cyber Security Centre.
The Australian Cyber Security Centre has indicated deprecation begins in roughly 12 months and retirement in roughly 24 months. Treat those as indications given to media, not gazetted dates — the transition is expected to run concurrently, with the Essential Eight and the first Essentials chapter overlapping rather than switching over on a single day. No firm retirement date has been published.
ASD opens national consultation on the evolution of the Essential Eight. cyber.gov.au
Consultation closes. cyber.gov.au
ASD begins deprecating the Essential Eight. ACSC via iTnews
Essential Eight retired. iTnews; Australian Cyber Security Magazine
The ASD has not published a fixed retirement date. Any post that gives you one is guessing.
What is changing in the cyber security framework
The Essential Eight was built for a world of on-premises enterprise IT. As a cyber security framework it has aged well, but the ground has shifted: cloud adoption, SaaS environments and shared responsibility models do not map cleanly onto a fixed maturity ladder, and threat tradecraft has moved well beyond conventional malware. A cyber security framework designed around eight on-premises controls struggles to describe a business that runs half its operations in someone else’s data centre.
The new guidance is intended to be threat-informed and adaptable across distinct security domains, released chapter by chapter and grounded in the ASD Information Security Manual. Enterprise IT is first; cloud, operational technology and potentially agentic artificial intelligence are flagged as future chapters.
The Essential Eight
- Eight prescriptive controls
- Four maturity levels (ML0–ML3)
- Anchored to on-premises enterprise IT
- Fixed compliance ladder
The Essentials series
- Outcome-focused, threat-informed controls
- Chapter-based by domain
- Cloud, OT and AI in scope over time
- Grounded in the Information Security Manual
What is not changing (and why you should not pause)
This is the part that matters commercially. The Essential Eight remains in force, and its maturity levels still apply. Every one of the eight mitigation strategies remains good security and is expected to align closely with the new framework:
Your maturity level still stands
Whether you are working toward maturity level one, two or three, that maturity level remains a valid target until the new guidance publishes. The effort you spend reaching a maturity level now is the same effort the Essentials series will recognise — the measure may be re-expressed, but the security work behind each maturity level does not evaporate.
| Essential Eight control | Survives the transition? |
|---|---|
| Patch applications | Persists expressed as an outcome |
| Patch operating systems | Persists |
| Multi-factor authentication | Persists |
| Restrict administrative privileges | Persists |
| Application control | Persists |
| Restrict Microsoft Office macros | Persists |
| User application hardening | Persists |
| Regular backups | Persists |
| Maturity levels (ML0–ML3) | Uncertain how they map to outcome statements is not yet defined |
If your organisation is mid-flight on an uplift, keep going. Contracts, tenders and cyber insurance policies still reference the Essential Eight today, so an Essential Eight maturity assessment done now is not wasted — it is the baseline you will carry into the new guidance.
What Australian businesses should do
Practical, non-alarmist steps — none of which involve re-tooling for guidance that does not exist yet:
- Continue your current uplift. The controls carry across, so progress now is progress later.
- Document controls as outcomes, not just maturity levels. This is the single highest-value preparation step — it is how the new framework will express compliance.
- Watch the ACSC partner portal and cyber.gov.au for the first published chapter of the Essentials series.
- Review any contract, tender or insurance clause that names the Essential Eight, so you know your exposure when the wording changes. These are your cyber security compliance obligations.
- Do not re-platform in anticipation. No new framework has been published; buying ahead of it is buying blind.
The best preparation for the Essentials series is a well-documented Essential Eight posture. An independent security audit captures exactly where you stand today, in language that maps to whatever comes next.
A steady hand through the change
PIP assesses Essential Eight maturity for Sydney businesses and builds uplift plans designed to carry into the new guidance rather than be redone under it. Our position on the transition is simple: keep improving your security posture, document it well, and don’t let a framework change from the Australian Signals Directorate become an excuse to stall. The businesses that come through a framework change well are the ones that treated security as an ongoing practice, not a certificate to collect once.
“When we assess Essential Eight maturity, the level a business believes it holds and the level its configuration actually demonstrates are often two different things — usually because a control was switched on once and never verified again.”— PIP, from Essential Eight assessments
Common questions
Is the Essential Eight being retired?
What are the ASD Essentials for Enterprise IT?
Should we stop our Essential Eight programme?
Will the new framework affect cyber insurance?
Not sure where your Essential Eight maturity actually sits?
PIP assesses Essential Eight maturity for Sydney businesses and builds the uplift plan that carries into the new Essentials guidance.
Get a maturity assessment →
