Feature · Updated September 2026
The Essential Eight is being replaced. Here’s what comes next.
The Australian Signals Directorate (ASD) is consulting on a new Essentials series. Its first chapter evolves today’s Essential Eight, and ASD has spoken of further chapters for operational technology, cloud and possibly agentic AI. Here is what has been announced, what changes and what to do in the meantime.
The short version
- Keep your Essential Eight work going ASD expects both documents to stay live during the transition, with strong alignment to existing controls.
- A two-year plan, no fixed dates yet ASD has advertised a two-year plan to retire the Essential Eight in favour of the Essentials series. It hasn’t set dates.
- More flexibility in how you comply ASD says the series gives organisations greater flexibility in how they implement cyber security.
Timeline
From Top Four to Essentials.
Where the Essential Eight came from, and where ASD says it is heading next.
-
2010
Strategies to mitigate
ASD first publishes its prioritised mitigation strategies. The four at the top become known as the Top Four.
-
2017
Essential Eight published
Expanded to eight essential strategies in February, with the maturity model following in June.
-
Consultation
Essentials for enterprise IT
ASD consults its partners on the first chapter of the Essentials series.
-
Now
Transition
ASD expects the Essential Eight and the Essentials to both be live documents.
-
Within two years
Retirement planned
ASD has advertised a two-year plan to retire the Essential Eight in favour of the Essentials series. No fixed dates yet.
Why ASD is changing it
Built for a network that no longer exists.
The Essential Eight has served Australian organisations well since 2017. ASD has been candid about where it no longer fits.
-
It predates the cloud
ASD has said the Essential Eight started before cloud was a big thing. Most businesses now run on SaaS and shared-responsibility models the controls weren’t written for.
-
The goalposts kept moving
New attacker techniques were folded into existing maturity levels. ASD has acknowledged organisations could appear to go backwards without their security getting any worse.
-
Too tied to specific technology
Controls such as Office macro settings name particular products. ASD promises more flexibility in how you implement the guidance, so you can use the tools that fit your environment.
The Essentials series
One framework, several chapters.
ASD grounds the series in the Information Security Manual (ISM), influenced by its Modern Defensible Architecture. Each chapter gives prioritised, threat-informed mitigations for a distinct environment.
-
Chapter 1 · First
Essentials for enterprise IT
The evolution of today’s Essential Eight, and the first chapter ASD has taken to consultation with its partners.
-
Planned
Operational technology
Industrial control systems and connected plant. Relevant to mining services, manufacturing and utilities.
-
Planned
Cloud
Clearer guidance on your shared responsibility with a cloud provider, and cloud-native controls on-premises can’t offer.
-
Possible
Agentic AI
Identity and access for AI agents and other non-person entities, and defences against prompt injection.
What changes, what doesn’t
Evolution, not a restart.
-
What’s changing
- Outcomes and intent in place of product-specific settings
- Separate chapters for enterprise IT, operational technology and cloud
- More emphasis on defence in depth and on protecting your most critical systems and data
- Practical tools and implementation guidance alongside the controls
-
What’s staying
- A prioritised baseline from ASD, grounded in the Information Security Manual (ISM)
- Strong alignment with existing Essential Eight controls and investments
- MFA, patching, admin privileges, application control, hardening and backups as fundamentals
- A clear path to strong cyber resilience
“The investment you’ve made under the Essential Eight will still be relevant under the Essentials.”
What to do now
Keep going, and prepare for outcomes.
Nothing about the transition makes today’s controls less useful. A few steps now will make the move to the Essentials straightforward.
- 01
Keep building Essential Eight maturity
Insurers, clients and contracts still ask for it, and the work maps across. Start with the eight controls. - 02
Record evidence by outcome
Document what each control achieves, not only which setting is ticked. Outcome-based guidance will ask for exactly that. - 03
Map your cloud responsibilities
For Microsoft 365 and each key SaaS platform, write down what the provider secures and what you do. - 04
Identify your crown jewels
List the systems and data you can’t afford to lose. Protection in depth starts with knowing what matters most.
FAQ
Transition questions.
Is the Essential Eight still valid?
When will the Essential Eight be retired?
Will our Essential Eight work be wasted?
What is Essentials for enterprise IT?
Should we wait for the new framework before starting?
Sources
- ASD, “Consultation on evolution of Essential Eight”, 15 June 2026
- iTnews, “ASD to retire Essential Eight cyber security framework within next two years”, interview with Chris Horlyck, ASD, 24 June 2026
- ASD, Strategies to mitigate cyber security incidents (first published February 2010)
- ASD, Essential Eight explained (first published February 2017) and Essential Eight maturity model (June 2017)
Get ready for the Essentials without losing momentum.
Book a free review with a Perth engineer. We check your Essential Eight maturity today and how that maps to the new Essentials series. The report is yours to keep either way.
Or call (08) 9467 2269