Replacing the ASD Essential Eight: What the Essentials Series Means for Your Business

Replacing Essential Eight

The Australian Signals Directorate has confirmed it is replacing the ASD Essential Eight with a new Essentials series. But this is an evolution, not a demolition — and the worst response available to an Australian business is to stop work.

The short version
  • The ASD is retiring the Essential Eight and replacing it with a new Essentials series; the first chapter is Essentials for enterprise IT.
  • National consultation ran 15 June – 12 July 2026. Deprecation is indicated at roughly 12 months, retirement at roughly 24 months — but no retirement date has been published.
  • The Essential Eight remains in force today. Nothing you have implemented is wasted — the controls carry across.
  • The shift is from prescriptive controls on a fixed maturity ladder to outcome-focused, threat-informed controls that work across cloud, SaaS and operational technology.
The announcement

What the ASD has actually announced

The Australian Signals Directorate intends to retire the Essential Eight cyber security framework and replace it with the Essentials series. The first chapter is Essentials for enterprise IT, and it was the subject of national consultation through the Australian Cyber Security Centre.

The Australian Cyber Security Centre has indicated deprecation begins in roughly 12 months and retirement in roughly 24 months. Treat those as indications given to media, not gazetted dates — the transition is expected to run concurrently, with the Essential Eight and the first Essentials chapter overlapping rather than switching over on a single day. No firm retirement date has been published.

15 Jun 2026

ASD opens national consultation on the evolution of the Essential Eight. cyber.gov.au

12 Jul 2026

Consultation closes. cyber.gov.au

~12 monthsindication

ASD begins deprecating the Essential Eight. ACSC via iTnews

~24 monthsindication

Essential Eight retired. iTnews; Australian Cyber Security Magazine

Firm dateno published date

The ASD has not published a fixed retirement date. Any post that gives you one is guessing.

Why now

What is changing in the cyber security framework

The Essential Eight was built for a world of on-premises enterprise IT. As a cyber security framework it has aged well, but the ground has shifted: cloud adoption, SaaS environments and shared responsibility models do not map cleanly onto a fixed maturity ladder, and threat tradecraft has moved well beyond conventional malware. A cyber security framework designed around eight on-premises controls struggles to describe a business that runs half its operations in someone else’s data centre.

The new guidance is intended to be threat-informed and adaptable across distinct security domains, released chapter by chapter and grounded in the ASD Information Security Manual. Enterprise IT is first; cloud, operational technology and potentially agentic artificial intelligence are flagged as future chapters.

Today

The Essential Eight

  • Eight prescriptive controls
  • Four maturity levels (ML0–ML3)
  • Anchored to on-premises enterprise IT
  • Fixed compliance ladder
Next

The Essentials series

  • Outcome-focused, threat-informed controls
  • Chapter-based by domain
  • Cloud, OT and AI in scope over time
  • Grounded in the Information Security Manual
The important part

What is not changing (and why you should not pause)

This is the part that matters commercially. The Essential Eight remains in force, and its maturity levels still apply. Every one of the eight mitigation strategies remains good security and is expected to align closely with the new framework:

Your maturity level still stands

Whether you are working toward maturity level one, two or three, that maturity level remains a valid target until the new guidance publishes. The effort you spend reaching a maturity level now is the same effort the Essentials series will recognise — the measure may be re-expressed, but the security work behind each maturity level does not evaporate.

The eight controls — do they survive the transition?
Essential Eight controlSurvives the transition?
Patch applicationsPersists expressed as an outcome
Patch operating systemsPersists
Multi-factor authenticationPersists
Restrict administrative privilegesPersists
Application controlPersists
Restrict Microsoft Office macrosPersists
User application hardeningPersists
Regular backupsPersists
Maturity levels (ML0–ML3)Uncertain how they map to outcome statements is not yet defined

If your organisation is mid-flight on an uplift, keep going. Contracts, tenders and cyber insurance policies still reference the Essential Eight today, so an Essential Eight maturity assessment done now is not wasted — it is the baseline you will carry into the new guidance.

The transition period

What Australian businesses should do

Practical, non-alarmist steps — none of which involve re-tooling for guidance that does not exist yet:

  1. Continue your current uplift. The controls carry across, so progress now is progress later.
  2. Document controls as outcomes, not just maturity levels. This is the single highest-value preparation step — it is how the new framework will express compliance.
  3. Watch the ACSC partner portal and cyber.gov.au for the first published chapter of the Essentials series.
  4. Review any contract, tender or insurance clause that names the Essential Eight, so you know your exposure when the wording changes. These are your cyber security compliance obligations.
  5. Do not re-platform in anticipation. No new framework has been published; buying ahead of it is buying blind.

The best preparation for the Essentials series is a well-documented Essential Eight posture. An independent security audit captures exactly where you stand today, in language that maps to whatever comes next.

Where PIP sits

A steady hand through the change

PIP assesses Essential Eight maturity for Sydney businesses and builds uplift plans designed to carry into the new guidance rather than be redone under it. Our position on the transition is simple: keep improving your security posture, document it well, and don’t let a framework change from the Australian Signals Directorate become an excuse to stall. The businesses that come through a framework change well are the ones that treated security as an ongoing practice, not a certificate to collect once.

“When we assess Essential Eight maturity, the level a business believes it holds and the level its configuration actually demonstrates are often two different things — usually because a control was switched on once and never verified again.”
— PIP, from Essential Eight assessments
FAQ

Common questions

Is the Essential Eight being retired?
Yes. The ASD has confirmed it intends to retire the Essential Eight and replace it with the Essentials series, on an indicated horizon of about 24 months. No retirement date has been published.
What are the ASD Essentials for Enterprise IT?
It is the first chapter of the new Essentials series, covering enterprise IT environments. It was the subject of national consultation that closed on 12 July 2026.
Should we stop our Essential Eight programme?
No. The Essential Eight remains in force and the underlying controls are expected to carry across to the new framework.
Will the new framework affect cyber insurance?
Insurers and contracts currently reference the Essential Eight. Expect wording to be updated over the transition period; review policies and contracts as the new guidance publishes.
Essential Eight

Not sure where your Essential Eight maturity actually sits?

PIP assesses Essential Eight maturity for Sydney businesses and builds the uplift plan that carries into the new Essentials guidance.

Get a maturity assessment
Scroll to Top