The Essential Eight is becoming the Essentials series
A plain-English guide to the ASD Essentials series — the successor to the Essential Eight. What it is, how it relates to the Essential Eight, what chapters are coming, the retirement timeline, and what Australian businesses should do between now and the final framework.
Sourced from the ASD consultation notice, the ISM and the ASD Cyber Security Partnership Program.
Multi-chapter series
Enterprise IT, cloud, OT and potentially AI
Not a reset of Essential Eight
Strong alignment with existing controls
E8 retired at ~24 months
12 to 18 months of dual-running
Where things stand
Consultation on the first chapter (Essentials for enterprise IT) closed on 12 July 2026.
ASD is now working through submissions before publishing the final framework. The Essential Eight remains current, active and supported guidance throughout the transition. Additional chapters covering cloud, OT and potentially AI are expected to follow. This page will be updated as each chapter lands.
ASD consultation noticeEssentials for enterprise IT
Chapter 1 · Consultation closed
Cloud environments
Future chapter · Expected
Operational technology
Future chapter · Expected
AI and emerging tech
Potential · Under consideration
What the Essentials series is
A multi-chapter framework grounded in the ISM, designed for modern environments.
The Essential Eight becomes the first chapter. More chapters follow.
In June 2026 the Australian Signals Directorate announced public consultation on the evolution of the Essential Eight into a broader Essentials series. Rather than a single framework for every environment, the series will span multiple chapters covering specific technology domains. The first chapter — Essentials for enterprise IT — builds directly on the Essential Eight and was open for consultation until 12 July 2026. Additional chapters covering cloud environments, operational technology and potentially AI are expected to follow.
Grounded in the ISM
ASD has confirmed the new Essentials guidance will be grounded in the Information Security Manual (ISM). This means the series inherits the ISM's threat-informed mitigation philosophy but packages it into prioritised, practical guidance for contemporary technology environments.
Source · ISM on cyber.gov.auThreat-informed and outcome-focused
The Essential Eight was built around prescriptive controls and specific technologies. The Essentials series moves toward a more outcomes-focused approach, giving organisations flexibility to achieve security objectives using the technologies and architectures that best suit their environment.
Multiple chapters, multiple domains
The first chapter is Essentials for enterprise IT. ASD has indicated future chapters will address areas such as cloud environments and operational technology. Emerging technologies including AI may also be considered in future guidance. Each chapter targets a specific technology domain rather than a one-size-fits-all model.
Practical tools and implementation guidance
ASD has stated the new Essentials guidance will offer prioritised, threat-informed mitigations supported by practical tools and clear implementation guidance. The intent is to make the framework easier to operationalise than the current maturity-level self-assessment process.
Source · ASD consultation noticeHow it relates to the Essential Eight
Strong alignment, not a reset. Your existing work carries over.
Organisations already using the Essential Eight can expect strong alignment with their existing controls and investments.
The most important message from ASD is that the Essentials series is not a restart. The eight mitigation strategies behind the Essential Eight — application control, patch applications, configure Microsoft Office macros, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups — remain the foundation. If you are mid-flight on Maturity Level 1, 2 or 3, keep going. The successor framework describes outcomes differently but the underlying security hygiene does not change.
Existing controls carry over
ASD has explicitly stated that organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. Your MFA deployment, patch management, backup strategy and application control work all remain directly relevant.
New adopters benefit too
New adopters will benefit from established best-practice guidance. The Essentials series does not raise the barrier to entry — it restructures the guidance so it is clearer and more adaptable to modern architectures.
Procurement and insurance still reference E8
Australian Government procurement, supply chain requirements and cyber insurance questionnaires will continue to reference Essential Eight maturity levels for at least 12 to 18 months after the new framework is published. Plan for both frameworks being referenced simultaneously during the transition.
SMB1001 maps cleanly
SMB1001 already maps to the Essential Eight controls and will be updated to map to the Essentials series as each chapter lands. Businesses holding or working toward SMB1001 certification are well positioned for the transition.
Source · SMB1001 certificationThe chapters and the timeline
Essentials for enterprise IT first, then cloud, OT and potentially AI.
Deprecation of the Essential Eight begins at roughly 12 months. Retirement at roughly 24.
ASD has indicated the Essentials series will roll out chapter by chapter. The Essential Eight guidance forms the first chapter — Essentials for enterprise IT. Future chapters are expected to cover cloud environments and operational technology, with AI potentially considered in future guidance. ASD expects to begin deprecating the Essential Eight at approximately 12 months after the new framework is introduced and retire it entirely at around 24 months. These timelines may evolve following the consultation outcome.
Chapter 1: Essentials for enterprise IT
The first chapter, built directly on the Essential Eight. Public consultation closed on 12 July 2026. This chapter will address enterprise-scale environments, cloud-native identity and outcome-based measurement.
Source · Read our consultation guideFuture: Cloud environments
ASD has signalled that cloud environments will be addressed in a future chapter. Today's Essential Eight assumes on-premises Active Directory and Windows server fleets in many places. A dedicated cloud chapter would acknowledge that most Australian organisations now operate Microsoft 365, Intune-managed endpoints and SaaS-first architectures.
Future: Operational technology
Operational technology (OT) — SCADA, ICS, PLCs and industrial control systems — is expected to get its own chapter. The current Essential Eight does not adequately address OT environments. A dedicated chapter would align with AS IEC 62443 and the SOCI Act obligations for critical infrastructure operators.
Source · AS IEC 62443 guidePotentially: AI and emerging tech
ASD has indicated that emerging technologies such as AI may be considered in future guidance. This aligns with ASD's separate Agentic AI Harnesses publication and the broader Australian Government approach to AI governance.
Source · Agentic AI HarnessesTimeline: 12 months to deprecation, 24 to retirement
ASD expects to begin deprecating the Essential Eight at roughly 12 months after the new framework is introduced and retire it at around 24 months. Expect at least 12 to 18 months of dual-running where both frameworks are referenced in parallel.
What Australian businesses should do now
Six practical actions while the framework settles.
Useful regardless of how the final framework lands.
Each of these actions is valuable whether the Essentials series lands in its current consultation form or evolves through the feedback process. The intent is to ensure that when the final framework is published, your organisation is in a strong position to evidence the controls already in place rather than scrambling to retrofit them.
Continue your Essential Eight programme
Do not pause MFA rollout, patching cycles, backup testing or admin privilege restriction. The mitigation strategies behind the Essential Eight remain best practice and will form the foundation of the first chapter.
Document current maturity with evidence
Have a current, written ML self-assessment with evidence per control. Most organisations have a verbal understanding of where they sit. Write it down. The successor framework will refer back to today's maturity model for transition purposes.
Source · Free security gaps trackerMove identity to the centre
Whatever the final framework says, identity will be elevated. Enforce conditional access, deploy ITDR, document privileged access procedures and rationalise admin accounts. This is the single highest-leverage area.
Build outcome evidence, not just configuration evidence
Start logging the outcomes the framework is likely to ask for: credential-stuffing attempts blocked per quarter, mean time to patch by criticality, percentage of admin actions from PAW devices, percentage of OT assets visible to your inventory.
Line up who bridges the two frameworks
Decide now who is accountable for translating between the current Essential Eight and the successor framework as it lands, so the mapping work does not stall.
Get a gap assessment
A no-obligation baseline across all eight controls tells you where you stand today, what it takes to reach your target maturity level, and which quick wins move the needle most for cyber insurance, tenders and procurement.
Source · Book a gap assessmentWhy ASD is making the change
The Essential Eight was built for on-premises enterprise IT. The threat landscape moved on.
Maturity levels kept shifting under organisations' feet. ASD heard the complaint and is fixing it.
ASD has been open about why the Essential Eight needs to evolve. In an interview with iTnews, Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre (ACSC) within ASD, explained the structural limitation: the Essential Eight was designed for on-premises enterprise IT at a time when cloud adoption was still nascent, and its controls do not translate cleanly to shared-responsibility models or SaaS environments. The Essentials series is ASD's response to that gap — and to a persistent complaint from the community.
The 'moved goalposts' problem
ASD acknowledged a complaint that has persisted for years: maturity level requirements for the Essential Eight have shifted under organisations' feet, creating the impression of organisations and agencies going backwards on cyber security without any actual deterioration in their security posture. Horlyck confirmed the phenomenon was real, attributing it to ASD absorbing new threat tradecraft into existing maturity levels rather than having a structure flexible enough to accommodate evolving controls separately. The Essentials series is designed to fix this by decoupling threat-informed controls from a fixed maturity ladder.
Source · iTnews interview with Chris Horlyck, ACSCCloud changed everything
Horlyck told iTnews: 'Essential Eight started before cloud was really a big thing in the sector. Now, if you don't have cloud, that would be a really surprising architecture to have.' The Essential Eight's controls do not translate cleanly to shared-responsibility models or SaaS environments. Separating cloud into its own chapter lets ASD give organisations clearer guidance on what their shared responsibility with a cloud provider actually looks like in practice.
Source · iTnews, 24 Jun 2026Influenced by Modern Defensible Architecture
ASD's Modern Defensible Architecture publication is a key influence on the Essentials series. The series aims for a stronger emphasis on defence in depth and protecting crown jewels rather than a thin perimeter layer around IT environments. This is a philosophical shift from prescriptive technical controls toward architectural resilience.
Source · Modern Defensible Architecture, cyber.gov.auFrom the Top Four (2012) to Essential Eight (2017) to Essentials (2026+)
The Essential Eight was first published in 2017, evolving from ASD's Top Four mandatory controls from 2012. The Essentials series is the next evolution in that lineage. Each generation has broadened the scope: four controls for government, to eight controls for enterprise IT, to a multi-chapter series for enterprise IT, cloud, OT and potentially AI.
Agentic AI may get its own chapter
Horlyck flagged that agentic AI could become a dedicated chapter, citing the distinct identity and access requirements for non-person entities operating on networks and the threat posed by prompt injection as sufficiently different from conventional controls to warrant its own treatment. This aligns with ASD's separate Agentic AI Harnesses publication.
Source · Agentic AI Harnesses guideSources referenced
- 01
Consultation on evolution of Essential Eight
Australian Signals Directorate (ASD)Published 15 Jun 2026www.cyber.gov.au - 02
ASD to retire Essential Eight within two years (interview with Chris Horlyck, ACSC)
iTnewsPublished 24 Jun 2026www.itnews.com.au - 03
ASD overhauls Essential Eight cybersecurity guidance
ACS Information AgePublished Jun 2026ia.acs.org.au - 04
Modern Defensible Architecture
ASD Cyber.gov.auwww.cyber.gov.au - 05
Essential Eight maturity model
ASD Cyber.gov.auwww.cyber.gov.au - 06
Information Security Manual (ISM)
ASD Cyber.gov.auwww.cyber.gov.au - 07
ASD Cyber Security Partnership Program
ASD Cyber.gov.auwww.cyber.gov.au
This page summarises publicly available Australian government, regulator and legal sources. It is general information, not legal advice.
The Essential Eight is being updated, not scrapped. Here is the simple plan to stay ahead of it.
You may have seen the headlines about ASD retiring the Essential Eight. It is easy to read that and worry you are about to be caught out, but there is no need to. What ASD is actually doing is evolving the framework into a new Essentials series, with the first chapter (Essentials for enterprise IT) having been through public consultation that closed on 12 July 2026. ASD expects to begin deprecating the Essential Eight at roughly the 12-month mark and retire it entirely at around 24 months, with both frameworks running concurrently in the meantime. The eight core strategies you already know (MFA, patching, backups, restricting admin rights, application control) stay right where they are. What changes is how the outcomes are described, not what good security looks like for an everyday Australian business.
So if you are wondering what to do while the framework settles, the answer is reassuringly boring: get the controls in place, write them down, and hold a certificate your customers already trust. That is exactly what SMB1001 certification is built to do, and the work carries straight over to both today's Essential Eight and the identity-first successor. You are not starting again later. You are doing the groundwork once, and staying ahead of whatever the final framework asks for.
The plan we have
SMB1001 certification, starting today.
Why this holds up either way
SMB1001 is the one certification built specifically for small and medium businesses, and it maps directly to the Essential Eight, the USA's CMMC, the UK's Cyber Essentials, and Singapore's Cyber Trustmark. It is reviewed and reissued every year, so it keeps pace rather than freezing in place.
That means the controls you put in for SMB1001 today are the same ones the successor framework is expected to lean on: identity, MFA, conditional access, tested backups and a documented response plan. You are not gambling on one framework over another. You are quietly doing the work both will ask for, and we walk through every step of it with you.
Already have a tender or insurer asking for it?
07 3114 2808Common questions
What Australian leadership teams ask about the Essentials series.
The Essentials series is the Australian Signals Directorate's successor to the Essential Eight. Rather than a single framework, the series will span multiple chapters covering specific technology domains. The first chapter — Essentials for enterprise IT — builds directly on the Essential Eight. Future chapters are expected to cover cloud environments, operational technology and potentially AI. The series is grounded in the Information Security Manual (ISM) and moves toward an outcome-focused, enterprise-adaptable approach.
Related in this cluster
Other operational and regulatory pages for Australian businesses.
Between two frameworks
The shift from 'Are you compliant?' to 'Are you protected?'
Maturity levels gave organisations false confidence — hitting ML2 became the end goal rather than the starting point. The Essentials series resets that by asking whether you are protected against the threats most likely to impact your business, not whether you ticked a box. Real Bytes delivers Essential Eight ML1 to ML3 programmes with full documentation, outcome evidence and identity-first architecture so that whatever the final Essentials series looks like, your organisation answers the real question. We will update this page as each chapter of the series is published.
This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.
Keep exploring
Related services, locations and industries
Explore how this connects across our wider offering.

Remote Support