

27 Jul 2026, by Micron21
For the better part of a decade, the Essential Eight has been the closest thing Australia has had to a cybersecurity baseline that everyone recognised. First published by the Australian Signals Directorate (ASD) back in 2017 – evolving from its earlier "Top Four" mandatory controls from 2012 – it gave organisations a clear, prioritised set of mitigation strategies to work through, along with a maturity model to measure how well they'd actually been implemented. For a lot of businesses and government agencies, the question "Are we Essential Eight compliant?" became shorthand for "Are we taking security seriously?".
So it may come as a bit of a surprise to hear that the Essential Eight is on its way out. The ASD and the Australian Cyber Security Centre (ACSC) have announced that the framework will be retired within the next two years and replaced with a new "Essentials" series – one designed to keep pace with a threat landscape that has changed dramatically since 2017, particularly with the rise of cloud and AI.
The good news for anyone who has invested time and money into their Essential Eight posture, is that this isn't a case of tearing everything up and starting again. The transition is being handled gradually, and the ASD has been at pains to point out that the work organisations have already done won't be wasted. There'll be a transition period where both the Essential Eight and the new Essentials guidance exist side by side, before the Essential Eight is progressively deprecated and eventually retired.
That's why this month we'll be talking about what the Essential Eight is, why it's been so important for Australian organisations, and why it's now being replaced with something new.
As the name implies, the Essential Eight is a set of eight cybersecurity mitigation strategies that the ASD deemed essential as a baseline level of protection. The idea is simple enough – make it harder for adversaries to compromise your systems by covering off the eight areas where they most commonly get in.
The eight strategies are:
Compliance with these strategies is measured through a maturity model, running from Maturity Level Zero (no meaningful protection) up to Maturity Level Three (protection against well-resourced, adaptive adversaries such as state-sponsored actors).
For a full breakdown of each strategy and what the different maturity levels actually mean, we'd recommend reading our earlier What are the Essential Eight? The strategies essential to keep your organisation secure article, which goes into far more detail than we will here.
It's still early days, so the finer details are yet to be locked in. But what we do know, is the shape of the change and the reasoning behind it...
At its core, the issue is that the Essential Eight is showing its age. It was designed for on-premises enterprise IT back at a time when cloud adoption was still in its infancy - but nowadays its controls don't translate cleanly to the shared-responsibility models and SaaS environments that most organisations now rely on. As Chris Horlyck, head of cyber security resilience at the ACSC, put it to ITnews1, "Essential Eight started before cloud was really a big thing in the sector" – and today, an architecture with no cloud component at all would be the exception rather than the rule.
Its replacement, the Essentials series, takes a different approach. Rather than a fixed list of prescriptive controls tied to specific technologies, it shifts the emphasis towards outcomes and intent – giving organisations more flexibility to meet the guidance using whatever tools suit their environment. It's being structured as a set of chapters covering distinct security domains, starting with enterprise IT, followed by operational technology and cloud, with the possibility of a dedicated chapter for agentic AI further down the track.
Another long-standing frustration the change looks to address is the "moving goalposts" problem. For years, organisations complained that the Essential Eight's maturity requirements shifted underneath them – creating the impression that they were going backwards on security even when their actual posture hadn't deteriorated. The ACSC has acknowledged this was real, attributing it to new threat tradecraft being absorbed into the existing maturity levels rather than handled separately. The Essentials series is designed to decouple threat-informed controls from a fixed maturity ladder so that the two can evolve independently.
That last point is the crux of it, and it's where the change makes the most sense. The framework needs to keep up with threats that are moving faster than a static, periodically updated control set can manage – and a lot of that acceleration is being driven by AI. We've written about this shift repeatedly over the past couple of years, and the examples aren't hard to find:
None of these threats fit neatly into a framework built around conventional malware and comparatively static conditions. The Essentials series is expected to lean on established best-practice guidance so it can respond to these faster-moving risks, while still aligning with the fundamentals the Essential Eight has always covered.
This is understandably the first question most organisations will ask – and it's the reassuring part. The ASD has been explicit that existing investment in the Essential Eight will not be made redundant. Horlyck confirmed to ITnews that "the investment you've made under the Essential Eight will still be relevant" under the Essentials series.
That's because the new controls are expected to align closely with the old ones. Patching, MFA, restricting administrative privileges, application control, hardening, and backups aren't going anywhere – they remain foundational to good security regardless of what the framework is called. What the Essentials series adds is a more flexible structure and additional measures aimed squarely at the newer threats we discussed above, particularly those involving cloud, operational technology, and AI.
It's also worth stressing that this is a gradual transition, not a hard cut-over. Both the Essential Eight and the Essentials will be maintained as live documents for a period. The ASD's intention is to keep both active initially, begin deprecating the Essential Eight at around the 12-month mark, and retire it in full at around 24 months. The first stage – a consultation on "Essentials for enterprise IT" – ran until 12 July 2026 via the ACSC Partner Portal2 & 3, with further chapters to follow.
In practice, if you've built your posture around the Essential Eight, the sensible approach is to keep maintaining it as normal, keep an eye on the Essentials guidance as each chapter is published, and treat the overlap as a running start rather than a reset.
The ASD and ACSC will begin phasing out the Essential Eight roughly over the next two years and replace it with a new Essentials series. The reasoning comes down to age – the Essential Eight was built for on-premises IT in a pre-cloud era, and it has struggled to keep up with cloud, operational technology, and fast-moving AI-enabled threats. It also suffered from a "moving goalposts" problem, where absorbing new threats into fixed maturity levels made organisations appear to go backwards even when their actual posture hadn't changed.
What's replacing it is a more flexible, outcomes-focused series organised into chapters – enterprise IT first, followed by operational technology and cloud, with agentic AI a possibility – that decouples threat-informed controls from a rigid maturity ladder. The transition is deliberately gradual, with both frameworks staying live during a handover period, with the Essential Eight beginning to be deprecated at around the 12-month mark and retired in full at around 24 months. The first stage, a consultation on "Essentials for enterprise IT", ran until 12 July 2026.
Crucially, none of this makes your existing effort redundant. The ASD has been explicit that Essential Eight investment remains relevant, with the new controls expected to align closely with the old ones while adding protections for newer threats. So the sensible thing to do now is simply to keep maintaining your Essential Eight posture, follow the Essentials chapters as they're released, and treat the alignment between the two as a head start rather than a reset.
If you have any questions about the Essential Eight, the upcoming Essentials series, or where your organisation currently stands, let us know! We're more than happy to talk through what the transition might mean for you and help you prepare.
We can work with you directly to assess your current cybersecurity posture, offer guidance on the controls that matter most, and help implement recommended changes together – and we have a range of software and services to support compliance and improve your overall maturity along the way.
You can call us on 1300 769 972 (Option #1) or reach us via email at sales@micron21.com.
1, iTnews (Juha Saarinen), "ASD to retire Essential Eight cyber security framework within next two years", <https://www.itnews.com.au/news/asd-to-retire-essential-eight-cyber-security-framework-within-next-two-years-626851>
2, Australian Signals Directorate / ACSC, "Consultation on the evolution of the Essential Eight", <https://www.cyber.gov.au/about-us/view-all-content/news/consultation-on-evolution-of-essential-eight>
3, Australian Cyber Security Magazine, "ASD to retire Essential Eight within two years, consults on replacement", <https://australiancybersecuritymagazine.com.au/asd-to-retire-essential-eight-within-two-years-consults-on-replacement/>
Simple, transparent pricing from Australia's leading cloud provider