The ASD Essentials Series: What’s Replacing the Essential Eight
If you’ve spent the last few years working toward an Essential Eight maturity level — or you’ve been asked for one in a tender — here’s news you need, delivered without the panic that some of the coverage has wrapped around it: the Essential Eight is being retired, and it’s being replaced by something called the Essentials series.
Take a breath, because the headline is more dramatic than the reality. This is a staged, two-year transition, not a switch being flipped. The work you’ve already done carries over. But it’s a genuine shift in how Australia frames its baseline cyber guidance — the most significant since the Essential Eight launched back in 2017 — and it’s worth understanding properly rather than through a vendor’s “act now” email.
I’ve written a full Essential Eight explainer elsewhere on this site covering the eight controls and the maturity model. This piece is about what’s coming next, why, and what you should actually do about it.
What was announced
On 24 June 2026, Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre (ACSC) within the ASD, confirmed in an interview with iTnews that the Essential Eight would be retired within two years and replaced by a broader Essentials series.
The key word is transition. Both frameworks will run side by side as live, supported documents for much of the next two years. The ASD’s stated plan is to begin deprecating the Essential Eight at around the 12-month mark, and to retire it entirely at around 24 months.
| Stage | Timing | What it means |
|---|---|---|
| Now (mid-2026) | Current | Essential Eight is the active, supported framework. It’s still what tenders and contracts reference. |
| Transition period | Ongoing | Both the Essential Eight and the Essentials series maintained as live documents simultaneously. |
| Deprecation begins | ~12 months (mid-2027) | ASD starts winding the Essential Eight down. |
| Full retirement | ~24 months (mid-2028) | Essential Eight retired as a whole. |
The timeline is indicative and could shift, particularly while the new framework is still out for consultation. But the direction is settled: the Essential Eight is going, and the Essentials series is taking its place.
What the Essentials series actually is
The single biggest structural change is that the Essentials series is not one universal checklist — it’s a set of separate, domain-specific chapters.
Multiple chapters for different environments. The first chapter, Essentials for Enterprise IT, is the direct successor to the Essential Eight. It’s expected to be followed by chapters for operational technology (OT) and cloud, with a dedicated chapter for agentic AI reportedly under consideration. The logic is that securing a cloud SaaS estate, an industrial control system, and a fleet of Windows laptops are genuinely different problems that were always awkward to force into the same eight controls.
A shift from prescriptive controls to outcomes and intent. Where the Essential Eight told you what to do (patch within this window, configure this setting), the Essentials series leans toward telling you what to achieve and giving you flexibility on how. ASD has described the goal as prioritised, threat-informed mitigations, with a principles-based approach rather than a fixed technology-specific control list.
A stronger architectural emphasis. The series draws heavily on ASD’s Modern Defensible Architecture work, with more weight on defence in depth and protecting your most valuable assets — your “crown jewels” — than on hardening a thin perimeter around everything equally. If that sounds familiar, it should: it’s the same thinking that underpins Zero Trust, and the overlap is not accidental. Both are responses to the collapse of the old castle-and-moat model.
Why the Essential Eight is being retired
This is the part I find most worth dwelling on, because the reasons are honest and they explain where the new framework is headed.
It was built for a world that no longer exists. The Essential Eight was designed around on-premises, Windows-heavy, internet-connected networks — the dominant enterprise setup in 2017. Today’s organisations run across cloud platforms, hybrid infrastructure, SaaS, mobile endpoints and, increasingly, AI agents. The E8 controls don’t map cleanly onto shared-responsibility cloud models, and applying them across a modern estate takes a lot of interpretation and translation.
It didn’t fit smaller organisations. A recurring criticism, and a fair one: several of the Essential Eight’s controls were pitched at large businesses with IT capabilities that a 20-person firm simply cannot match. Applying the same eight controls at the same maturity level to a small law firm and a 500-person financial services company was always a rough approximation. A more flexible, outcomes-based model may genuinely suit Australian SMBs better.
The maturity levels kept moving. This one is subtle but important. Organisations complained for years that maturity level requirements shifted under their feet — that they appeared to go backwards on cyber security without their actual posture deteriorating. ASD has acknowledged this was real: it happened because new adversary tradecraft was being absorbed into the existing maturity levels rather than accommodated by a structure flexible enough to evolve separately. The Essentials series is designed to fix this by decoupling threat-informed controls from a fixed maturity ladder.
And compliance was poor regardless. It’s hard to ignore the backdrop of successive Auditor-General findings — Commonwealth entities repeatedly assessed as only “partly effective,” with key controls falling short despite years of obligation to meet Maturity Level 2. A framework that few could actually reach was always going to invite a rethink.
What stays the same
Here’s the reassuring part, and the reason the panicked framing is misplaced.
The core controls carry over. Multi-factor authentication, patch management, application control, and regular backups remain central to the new framework. They sit inside a broader, more current structure rather than being thrown out. The fundamentals of good security haven’t changed just because the framework’s name has.
Your existing work counts. ASD has been explicit that investment made under the Essential Eight remains relevant under the Essentials series. If you’ve reached Maturity Level 1 or 2, you’re ahead — those controls map across directly. The Essential Eight forms the foundation of Essentials for Enterprise IT; think evolution, not demolition.
The Essential Eight is still the live standard today. Until deprecation begins around mid-2027, the E8 remains what’s actually in force. It’s still what tenders reference. For Defence Industry Security Program (DISP) members in particular, Essential Eight Maturity Level 2 remains the mandated baseline, assessed through the Cyber Security Questionnaire — and that questionnaire traces back to the Information Security Manual, which also grounds the new Essentials series. The continuity is deliberate.
What you should actually do now
Keep going. If you’re working toward an Essential Eight maturity level, don’t stop. Pausing because the framework is being retired is like skipping your seatbelt because crash-test standards are being updated — the standard in force today is still the Essential Eight, and walking away leaves you exposed and non-compliant against the requirement that actually applies. Your progress translates directly into the new framework.
Map your cloud and SaaS shared responsibilities now. This is where most Essential Eight programs are thin, and it’s exactly where the Essentials series will get more explicit. Getting ahead of it is time well spent regardless of the framework change.
Treat it as risk management, not a compliance box. The most common failure under the Essential Eight was running it as a tick-the-box audit exercise rather than a genuine, context-driven program to reduce risk. The Essentials series’ outcomes-based design rewards the organisations that were already doing the former. If you’ve been treating your maturity score as the goal rather than the byproduct, this is a good moment to correct course. The same discipline I outline in how to evaluate an EDR vendor applies here: focus on the security outcome, not the label.
Have your say — if you’re quick. Public consultation on the first chapter, Essentials for Enterprise IT, is open via the ASD Cyber Security Partnership Program portal and closes on 12 July 2026. If your organisation or sector has a stake in how this guidance is written, that’s the window to contribute. The final version is expected to be published after consultation closes, most likely late 2026 — which is when you’ll know precisely what Essentials for Enterprise IT requires and how your existing work maps to it.
The practitioner’s take
Broadly, this is the right move, and the industry reaction has been notably positive for something replacing a framework this entrenched. The Essential Eight was showing its age, it never fit smaller organisations well, and a principles-based, threat-informed model that can accommodate cloud, OT and AI as distinct domains is a more honest reflection of how Australian organisations actually operate in 2026.
But I’ll offer one caveat that the celebratory coverage tends to skip. Outcomes-based guidance is more adaptable, and also harder to audit and mandate. The Essential Eight’s great strength was that it was concrete — you could measure it, a board could understand it, a tender could require it. A more flexible, principles-based framework is better security philosophy, but it asks more judgement of the organisations implementing it and the assessors checking them. The risk is that “flexible” quietly becomes “vague,” and that the organisations who most needed the prescriptive checklist — the small ones without a security team — find principles harder to action than a list. ASD is clearly aware of this, given the emphasis on practical tools and clear implementation guidance. Whether the final framework delivers on that is the thing to watch when it lands.
For now, the message is simple and it’s the same one ASD is sending: the Essential Eight is still the standard, your work still counts, and the smartest thing you can do is keep building genuine resilience rather than chasing whichever label is current. Good security was never really about the framework’s name.