Skip to content

Local engineers in Perth, WA. Zero offshoring.

Menu

Feature · Updated September 2026

The Essential Eight is being replaced. Here’s what comes next.

The Australian Signals Directorate (ASD) is consulting on a new Essentials series. Its first chapter evolves today’s Essential Eight, and ASD has spoken of further chapters for operational technology, cloud and possibly agentic AI. Here is what has been announced, what changes and what to do in the meantime.

The short version

  • Keep your Essential Eight work going ASD expects both documents to stay live during the transition, with strong alignment to existing controls.
  • A two-year plan, no fixed dates yet ASD has advertised a two-year plan to retire the Essential Eight in favour of the Essentials series. It hasn’t set dates.
  • More flexibility in how you comply ASD says the series gives organisations greater flexibility in how they implement cyber security.

Timeline

From Top Four to Essentials.

Where the Essential Eight came from, and where ASD says it is heading next.

  1. 2010

    Strategies to mitigate

    ASD first publishes its prioritised mitigation strategies. The four at the top become known as the Top Four.

  2. 2017

    Essential Eight published

    Expanded to eight essential strategies in February, with the maturity model following in June.

  3. Consultation

    Essentials for enterprise IT

    ASD consults its partners on the first chapter of the Essentials series.

  4. Now

    Transition

    ASD expects the Essential Eight and the Essentials to both be live documents.

  5. Within two years

    Retirement planned

    ASD has advertised a two-year plan to retire the Essential Eight in favour of the Essentials series. No fixed dates yet.

Why ASD is changing it

Built for a network that no longer exists.

The Essential Eight has served Australian organisations well since 2017. ASD has been candid about where it no longer fits.

  • It predates the cloud

    ASD has said the Essential Eight started before cloud was a big thing. Most businesses now run on SaaS and shared-responsibility models the controls weren’t written for.

  • The goalposts kept moving

    New attacker techniques were folded into existing maturity levels. ASD has acknowledged organisations could appear to go backwards without their security getting any worse.

  • Too tied to specific technology

    Controls such as Office macro settings name particular products. ASD promises more flexibility in how you implement the guidance, so you can use the tools that fit your environment.

The Essentials series

One framework, several chapters.

ASD grounds the series in the Information Security Manual (ISM), influenced by its Modern Defensible Architecture. Each chapter gives prioritised, threat-informed mitigations for a distinct environment.

  • Chapter 1 · First

    Essentials for enterprise IT

    The evolution of today’s Essential Eight, and the first chapter ASD has taken to consultation with its partners.

  • Planned

    Operational technology

    Industrial control systems and connected plant. Relevant to mining services, manufacturing and utilities.

  • Planned

    Cloud

    Clearer guidance on your shared responsibility with a cloud provider, and cloud-native controls on-premises can’t offer.

  • Possible

    Agentic AI

    Identity and access for AI agents and other non-person entities, and defences against prompt injection.

What changes, what doesn’t

Evolution, not a restart.

  • What’s changing

    • Outcomes and intent in place of product-specific settings
    • Separate chapters for enterprise IT, operational technology and cloud
    • More emphasis on defence in depth and on protecting your most critical systems and data
    • Practical tools and implementation guidance alongside the controls
  • What’s staying

    • A prioritised baseline from ASD, grounded in the Information Security Manual (ISM)
    • Strong alignment with existing Essential Eight controls and investments
    • MFA, patching, admin privileges, application control, hardening and backups as fundamentals
    • A clear path to strong cyber resilience

“The investment you’ve made under the Essential Eight will still be relevant under the Essentials.”

Chris Horlyck, Head of Cyber Security Resilience, ASD, speaking to iTnews

What to do now

Keep going, and prepare for outcomes.

Nothing about the transition makes today’s controls less useful. A few steps now will make the move to the Essentials straightforward.

  1. 01

    Keep building Essential Eight maturity

    Insurers, clients and contracts still ask for it, and the work maps across. Start with the eight controls.
  2. 02

    Record evidence by outcome

    Document what each control achieves, not only which setting is ticked. Outcome-based guidance will ask for exactly that.
  3. 03

    Map your cloud responsibilities

    For Microsoft 365 and each key SaaS platform, write down what the provider secures and what you do.
  4. 04

    Identify your crown jewels

    List the systems and data you can’t afford to lose. Protection in depth starts with knowing what matters most.
Is the Essential Eight still valid?
When will the Essential Eight be retired?
Will our Essential Eight work be wasted?
What is Essentials for enterprise IT?
Should we wait for the new framework before starting?

Get ready for the Essentials without losing momentum.

Book a free review with a Perth engineer. We check your Essential Eight maturity today and how that maps to the new Essentials series. The report is yours to keep either way.

Or call (08) 9467 2269

What’s bugging you
Staff

A Perth engineer, not a salesperson, replies within one business day.