Call IT Assessment

The Essential Eight Is Being Retired: What ASD’s New Essentials Series Means for Your Business

Published: 24 July 2026 | Last updated: 24 July 2026 | Reading time: 13 minutes | Author: AyeTech Cyber Security Team

Key Takeaways

  • What happened: On 15 June 2026, the Australian Signals Directorate (ASD) announced the Essential Eight will evolve into a new Essentials series, starting with a chapter called Essentials for enterprise IT
  • Timeline: National consultation closed on 12 July 2026; industry reporting indicates the Essential Eight will be retired within roughly two years
  • Your investment is safe: ASD has confirmed organisations already using the Essential Eight “can expect strong alignment with their existing controls and investments”
  • Nothing changes today: The Essential Eight remains ASD’s current published baseline — keep implementing it
  • Why it matters: ASD received 84,700+ cybercrime reports in 2024–25 (one every 6 minutes), with small businesses self-reporting an average cost of $56,600 per cybercrime report

What Did ASD Announce?

On 15 June 2026, ASD published a consultation on the evolution of the Essential Eight — the framework that has defined baseline cyber security in Australia since 2017. The Essential Eight will become the first chapter of a broader Essentials series, named Essentials for enterprise IT, with additional chapters to follow.

If your business has been working towards Essential Eight compliance — perhaps using our Essential 8 compliance guide for small business — the immediate answer is: don’t panic, and don’t stop. ASD has been explicit that existing Essential Eight controls and investments will carry over.

The consultation ran through the ASD Cyber Security Partnership Program and closed on 12 July 2026. Government, industry, regulators, and organisations currently using the Essential Eight were all invited to provide feedback. The timeline comes from ACSC’s head of cyber security resilience, Chris Horlyck, who told iTnews ASD will “probably in 12 months, start to deprecate the Essential Eight, and then in 24 months we’ll retire the Essential Eight as a whole.”

This is the biggest change to Australia’s baseline cyber security guidance since the Essential Eight replaced the “Top 4” strategies in 2017. It will eventually touch every government contract, cyber insurance questionnaire, and supply chain security requirement that names the Essential Eight today.

Why Is the Essential Eight Being Replaced?

The short answer: the technology environment the Essential Eight was designed for no longer exists. Published in 2017, the framework assumed on-premises servers, Windows desktops, and conventional malware. Most Australian businesses now run on cloud platforms like Microsoft 365, and attackers have moved with them — towards identity theft, OAuth abuse, and AI-assisted attacks that the original eight strategies were never built to address.

The threat numbers keep climbing. ASD’s Annual Cyber Threat Report 2024–25 recorded over 84,700 cybercrime reports — one every six minutes — with the average self-reported cost of cybercrime for a small business rising 14% to $56,600 per report.

Attack patterns have shifted too. We’ve covered several this year that the Essential Eight’s controls don’t squarely address: device code phishing that bypasses MFA, and the Vercel breach via a compromised OAuth app. These are identity and cloud-configuration attacks — exactly the “contemporary technology environments” ASD says the new guidance will target.

There’s also a structural criticism ASD is responding to: the Essential Eight’s maturity model became a rigid compliance ladder. Organisations chased maturity levels as a box-ticking exercise rather than managing their actual risk. The new series takes a more flexible, principles-based approach — giving organisations, in ASD’s words, “greater flexibility in how they implement cyber security, while still providing a clear path to achieving strong cyber resilience.”

What Is the New Essentials Series?

The Essentials series is ASD’s planned successor to the Essential Eight: a set of prioritised, threat-informed mitigations for modern technology environments, published in chapters. The first chapter, Essentials for enterprise IT, evolves the current Essential Eight. Additional chapters — expected to cover environments such as operational technology and cloud — will follow.

Based on ASD’s announcement, the new guidance will be:

  • Grounded in the Information Security Manual (ISM) — the same control catalogue that underpins Australian government security, so the Essentials series sits inside an established framework rather than starting from scratch
  • Threat-informed and prioritised — mitigations ranked by what actually stops current attacks, not a static checklist written in 2017
  • Built for contemporary environments — cloud platforms, SaaS, identity systems, and AI-era threats, not just on-premises Windows networks
  • Supported by practical tools — ASD has flagged implementation guidance and tooling, not just a list of controls
  • Backwards-compatible — organisations using the Essential Eight “can expect strong alignment with their existing controls and investments”

What we don’t know yet: how maturity levels will be assessed under the new model, exactly when each chapter lands, and how quickly government procurement and insurers will move their requirements across. Those details will emerge now that the consultation has closed.

Is Your Essential Eight Investment Wasted?

No. ASD has directly addressed this: organisations already using the Essential Eight can expect strong alignment between their existing controls and the new Essentials guidance. The eight strategies — application control, patching, macro settings, hardening, admin privilege restriction, OS patching, MFA, and backups — are foundational controls that any successor framework will still require.

Think of it this way: the Essential Eight was never arbitrary. ASD assessed that its original Top 4 strategies alone would mitigate at least 85% of the targeted cyber intrusions it responded to, and in 2017 declared the expanded eight strategies the new cyber security baseline for all organisations. Those attack techniques haven’t vanished — ransomware alone continues to hit Australian SMEs harder each year. The new framework adds coverage for what’s changed; it doesn’t discard what still works.

If anything, businesses that have done the Essential Eight work are the best-positioned for the transition. You already have the disciplines the new framework will assume: an asset inventory, a patching cadence, MFA rollout, restricted admin access, and tested backups. The gap analysis when Essentials for enterprise IT is published will be a short exercise, not a rebuild.

Not Sure Where Your Business Stands on the Essential Eight?

AyeTech runs Essential Eight assessments for Australian small businesses — and we’ll map your controls to the new Essentials series as ASD publishes it.

Book an Essential Eight Assessment

Timeline: What Happens When

The transition is phased over roughly two years. Nothing is being switched off today — the Essential Eight remains ASD’s current published guidance while the Essentials series is developed. Here’s the picture as of July 2026:

Date Milestone What It Means for You
2017 Essential Eight published, expanding the earlier “Top 4” The baseline Australian businesses have worked to for 9 years
15 June 2026 ASD announces the Essentials series and opens consultation Change is official — but current guidance stays in force
12 July 2026 Consultation on Essentials for enterprise IT closes ASD now incorporates industry feedback into the framework
Late 2026–2027 (expected) Essentials for enterprise IT published; further chapters follow Gap analysis against your current controls; contracts begin updating
~2028 (reported) Essential Eight formally retired Essentials series becomes the reference in contracts and insurance

Treat the dates beyond July 2026 as provisional — ASD has not published a formal release schedule. We’ll update this post as milestones are confirmed.

What Should Your Business Do Now?

The worst response to this announcement is to pause your security program and “wait for the new framework.” The controls are carrying over, the threats aren’t waiting, and businesses that keep building now will transition fastest later. Here’s the practical checklist:

  1. Keep implementing the Essential Eight. It remains ASD’s current baseline, and every control maps into the successor. If you haven’t started, our step-by-step Essential 8 guide is the place to begin.
  2. Document your current state. Record which strategies you’ve implemented and to what maturity level. When Essentials for enterprise IT is published, this becomes your gap-analysis baseline — and your evidence for insurers and clients during the transition.
  3. Check what references the Essential Eight in your paperwork. Cyber insurance policies, government and enterprise contracts, and supplier security questionnaires often name the framework and maturity levels explicitly. Know which documents will need updating so renewal conversations don’t catch you out.
  4. Extend your thinking to cloud and identity now. The new series is being built for cloud and identity-based threats. Controls like OAuth app governance, Conditional Access policies, and blocking legacy authentication in Microsoft 365 are near-certain inclusions — implementing them early is a head start, not a gamble.
  5. Ask your IT provider for their transition plan. A good provider should be tracking the consultation outcome, mapping your controls to the new guidance as it lands, and updating your roadmap without being prompted. If yours doesn’t know the Essential Eight is being replaced, that tells you something.

Frequently Asked Questions

Is the Essential Eight being scrapped?

Not scrapped — evolved. ASD announced on 15 June 2026 that the Essential Eight will become the first chapter of a new Essentials series, called Essentials for enterprise IT. Industry reporting indicates the Essential Eight brand will be retired within roughly two years. Until the new guidance is published, the Essential Eight remains ASD’s current baseline recommendation, and everything you’ve implemented under it continues to protect your business.

What is Essentials for enterprise IT?

It’s the first chapter of ASD’s new Essentials series — the planned successor to the Essential Eight. ASD describes it as prioritised, threat-informed mitigations for contemporary technology environments, grounded in the Information Security Manual and supported by practical tools and implementation guidance. It went through national consultation that closed on 12 July 2026, with additional chapters expected to follow.

Do I still need to comply with the Essential Eight in 2026?

Yes. The Essential Eight is still ASD’s published baseline and remains the framework referenced in government contracts, cyber insurance questionnaires, and supply chain requirements. ASD has confirmed existing Essential Eight controls will align strongly with the new guidance, so continuing your implementation is both the compliant choice today and the best preparation for the transition.

We just spent months and real money reaching Maturity Level 2. Was that wasted?

No. ASD has stated that organisations using the Essential Eight can expect strong alignment with their existing controls and investments. The technical work that earned your maturity level — application control, patching regimes, MFA, restricted admin privileges, tested backups — maps directly into the new guidance. Contracts and insurance policies that reference maturity levels will take years to update, so the assessment you paid for keeps doing its job right through the transition.

Why is ASD replacing the Essential Eight?

The framework was published in 2017 for on-premises, Windows-centric environments facing conventional malware. Australian businesses have since moved to cloud and SaaS platforms, and attackers have shifted to identity-based and AI-assisted techniques. ASD says the new series will offer threat-informed mitigations for contemporary environments with more flexibility than the current maturity-level ladder.

When will the new Essentials guidance be released?

ASD hasn’t announced a firm date. Consultation closed on 12 July 2026, and industry reporting points to the Essential Eight being retired within roughly two years — suggesting a phased rollout between late 2026 and 2028. The Essential Eight remains current guidance until ASD formally publishes its replacement.

My cyber insurance renewal asks about Essential Eight controls. What do I say now?

Answer it exactly as you would have last year — the Essential Eight is still the current framework, and your documented controls and maturity assessment are still the evidence insurers want. Over the transition period insurers will migrate their questionnaires to the new Essentials language. Keeping documented evidence of your current controls means you can answer either version confidently — and avoid coverage disputes about whether you met the security conditions in your policy.

I run an accounting firm that just came under the new AML-CTF rules. Does this change my compliance work too?

They are separate obligations, but they meet in the middle. The AML-CTF expansion — and the Privacy Act coverage it triggers — tells you what you must protect and report; the Essential Eight tells you how to secure the systems holding that client data. The framework transition does not change your AML-CTF or privacy duties. Implementing the Essential Eight, and its successor, is the practical way to demonstrate the reasonable steps to secure personal information that the Privacy Act now expects of newly regulated firms.

What will replace the Essential Eight in Australia?

The Essentials series — chaptered, threat-informed cyber security guidance from ASD, grounded in the Information Security Manual. The first chapter, Essentials for enterprise IT, evolves the current Essential Eight. Later chapters are reported to cover operational technology and cloud. The series keeps the Essential Eight’s core controls while adding flexibility and coverage for modern cloud and identity-based threats.

What are the eight strategies of the Essential Eight?

Application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. The eight strategies are grouped into three objectives: preventing attacks, limiting the extent of incidents, and ensuring data recovery. All eight are expected to carry into the new Essentials framework — see our Essential 8 compliance guide for implementation detail.

Is the Essential Eight mandatory in Australia?

It is mandatory for federal government non-corporate Commonwealth entities and strongly recommended by ASD for all other Australian organisations. It is not legislated for private businesses, but Essential Eight maturity is increasingly written into government procurement, enterprise supply chain requirements, and cyber insurance conditions — which makes it effectively required for many SMBs that sell to government or larger companies.

We haven’t started the Essential Eight yet. Should we start now or wait for the new framework?

Start now. ASD has confirmed organisations using the Essential Eight can expect strong alignment with their existing controls and investments under the new framework, so nothing you implement now is wasted. Meanwhile, the threats these controls address are active today — ASD received a cybercrime report every six minutes in 2024–25. Waiting leaves you exposed now and gives you no advantage later.

Will maturity levels ML1, ML2 and ML3 still exist under the Essentials series?

Not confirmed. ASD has not published the assessment model for the Essentials series. ACSC’s Chris Horlyck has indicated the new guidance decouples controls from a fixed maturity ladder in favour of a more flexible, principles-based approach. Until the new model is published, Essential Eight maturity levels remain the standard reference in Australian contracts, security questionnaires, and insurance paperwork.

My business runs entirely on Microsoft 365. Will the new framework actually cover us?

Yes — that is the point of the change. ASD says the new guidance targets contemporary technology environments, and reporting indicates dedicated operational technology and cloud chapters will follow Essentials for enterprise IT. Expect identity and cloud-configuration controls — the areas behind attacks like device code phishing and OAuth app abuse — to feature far more prominently than in the 2017-era Essential Eight. Until then, the current Essential Eight still applies to cloud-first businesses: patching, MFA, restricted admin privileges, and backups all have direct Microsoft 365 equivalents.

ASD says the new framework is grounded in the ISM. What does that mean in plain English?

The Information Security Manual (ISM) is ASD’s master catalogue of cyber security controls, used across Australian government and industry. Grounded in the ISM means the new Essentials guidance selects and prioritises controls from that established catalogue rather than inventing new ones. For a small business, the practical effect is continuity: the controls your IT provider implements trace back to the same source government agencies use, which strengthens your answers in tenders and security questionnaires.

How much does Essential Eight compliance cost for an Australian small business?

A typical small business (10–30 staff) can reach Maturity Level 1 for roughly $5,000–$15,000 with MSP support, over about 4–8 weeks. Costs scale with maturity level, business complexity, and how much of the tooling you already own — many controls use features already included in Microsoft 365 Business Premium licences.

A client asked if we’re ISO 27001 certified. Is the Essential Eight enough instead?

For most Australian clients, yes — they solve different problems. The Essential Eight is a free, Australian, prioritised baseline of technical controls; ISO 27001 is an international, certifiable standard for a full information security management system covering governance, risk, and process. Many Australian SMBs implement the Essential Eight first for practical protection, then pursue ISO 27001 certification when enterprise or overseas customers demand it. The Essentials series does not change that relationship.

A government tender asks for Essential Eight Maturity Level 2. Does that still apply?

Yes — a requirement written into a tender or contract stands until the document itself is updated, regardless of ASD’s roadmap. The Essential Eight remains ASD’s published baseline today, so assessors will keep scoring against maturity levels well into the transition. Keep your maturity assessment current and documented; when procurement language migrates to the Essentials series, ASD has confirmed existing Essential Eight controls will map across.

What should my business actually do in the next 90 days?

Keep implementing the Essential Eight, document your current maturity as a baseline for the future gap analysis, list every contract and policy that references the Essential Eight, and start strengthening cloud and identity controls — OAuth app governance, Conditional Access, blocking legacy authentication — which the new framework is expected to emphasise. An IT provider tracking the transition can handle the re-mapping as each chapter is published.

Where can I read ASD’s official announcement about the Essential Eight changes?

On cyber.gov.au: ASD’s news item titled Consultation on evolution of Essential Eight, published 15 June 2026. Detailed transition commentary, including the two-year retirement timeline, comes from ACSC officials’ interviews with industry press. AyeTech will keep this article updated as ASD publishes the Essentials chapters and confirms retirement dates.

Stay Ahead of the Essentials Transition

AyeTech tracks ASD guidance so you don’t have to. We’ll assess your business against the Essential Eight today, and re-map your controls to the Essentials series as each chapter is published — no rework, no surprises at contract or insurance renewal.

Get in Touch Learn About Our Cyber Security Services

Or call us on 02 9188 8000 to speak with a security specialist today.

About AyeTech

AyeTech is a Sydney-based managed IT services provider specialising in cyber security, Essential Eight implementation, and IT infrastructure for Australian small and medium businesses. We help businesses build security programs that hold up to frameworks, insurers, and real-world attackers alike.

Contact Information:

  • Phone: 02 9188 8000
  • Email: [email protected]
  • Address: Suite 203, Level 8, 99 Walker St, North Sydney, NSW 2060
  • Service Areas: Sydney, Melbourne, Brisbane, Perth, Adelaide

Related Resources: