The Essential Eight is evolving and ASD wants your view
A plain-English guide to ASD's consultation on the successor to the Essential Eight, currently being referred to as Essentials for enterprise IT. Covers what is changing, what stays the same, what it means for organisations mid-flight on Essential Eight maturity, and six practical actions to take between now and the final framework.
Sourced from the ASD consultation notice and the ASD Cyber Security Partnership Program.
Closed 12 July 2026
Consultation period complete
Not a reset of Essential Eight
Mitigation strategies remain the foundation
Outcome-focused successor
Enterprise scale, cloud-native, identity-first
Consultation closed
Public consultation on Essentials for enterprise IT closed on 12 July 2026.
ASD will now work through submissions before publishing the final framework. The Essential Eight remains current guidance throughout the transition, so organisations mid-flight on ML1 to ML3 should keep going. The ASD consultation notice remains available for reference.
ASD consultation noticeWhat is being consulted on
ASD is publicly evolving the Essential Eight into a new framework.
Working title: Essentials for enterprise IT.
On the Australian Signals Directorate Cyber Security Partnership Program portal, ASD ran public consultation on a successor to the Essential Eight maturity model, currently being referred to as Essentials for enterprise IT. The consultation period closed on 12 July 2026. The intent is to give organisations clearer, more outcome-focused guidance that scales across enterprise environments, while keeping the underlying mitigation strategies recognisable to anyone who has been working through Essential Eight maturity.
Source
The consultation is published on cyber.gov.au under the news category, and the consultation pack is hosted on the ASD Cyber Security Partnership Program portal. Partnership Program members and the public could submit views until the close date.
Source · ASD consultation noticeWhy now
The current Essential Eight maturity model has not changed materially since the November 2023 release. ASD has signalled that the framework needs to evolve to address enterprise-scale environments, cloud-first identity, and the operational realities of mature organisations that already meet the controls but want clearer accountability for outcomes.
What stays the same
The eight mitigation strategies (application control, patch applications, configure Microsoft Office macros, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, regular backups) remain the foundation. Australian SMBs working toward ML1 to ML3 should continue to do so. The successor framework is not a reset.
Consultation closed 12 July 2026
ASD accepted views on enterprise scalability, cloud-native identity, OT environments, and how outcomes should be measured beyond the existing maturity levels. The consultation has now closed and ASD will work through submissions before publishing the final framework.
Source · ASD Cyber Security Partnership ProgramWhat it means for current Essential Eight work
If you are mid-flight on Essential Eight maturity, keep going.
The successor framework will be a refinement, not a restart.
We are advising clients to continue their Essential Eight programmes as planned. The mitigation strategies behind Essential Eight are sound, are reflected in the cyber insurance market, and are recognised across the Australian Government supply chain. The evolution of the framework changes how outcomes are described and measured, not what good cybersecurity hygiene looks like in practice.
ML1 to ML3 work continues to be valuable
Maturity Level 1, 2, and 3 work delivered today maps cleanly onto the practical security controls every Australian business should have in place. Cyber insurers, government procurement, and boards all continue to reference Essential Eight maturity in 2026.
Your provider should translate it for you
Whoever runs your security programme should be reading the framework as it lands and telling you what actually changes for your environment. Real Bytes will publish a Real Bytes view on transition once the consultation feedback is reflected in the final framework.
Source · Our Essential Eight consultantsProcurement language will lag the framework
Expect Australian Government and insurer procurement language to continue referencing Essential Eight ML1 to ML3 for at least 12 to 18 months after any new framework is published. Plan for both being in use simultaneously.
What to defer
Defer any net-new cybersecurity programme that depends on the new framework's specific outcome wording. Do not defer programme work on MFA, patching, backups, administrative privilege restriction, or any other Essential Eight control.
Likely structural changes
Outcome-focused, enterprise-adaptable, cloud-native.
These are likely directions, drawn from the consultation pack themes.
The consultation pack signals several likely directions for the successor framework. These are not final, and the published framework will reflect the consultation outcomes. We have summarised the themes most likely to affect Australian businesses based on the public consultation materials and ASD's published rationale for the change.
Outcome-based language
Likely shift from prescriptive maturity-level checkboxes toward outcome statements that organisations can demonstrate they have achieved. Reduces tick-box behaviour, increases the requirement for operational evidence.
Enterprise scalability
Likely additional guidance for organisations with thousands of endpoints, federated identity, multiple business units, and complex change-management environments. Today's ML2 and ML3 guidance is sometimes difficult to scale operationally.
Identity as a first-class layer
Identity (Entra ID, Okta) has become the new perimeter. The successor framework is likely to improve identity controls beyond the current MFA strategy, covering conditional access, identity threat detection and response (ITDR), and privileged access management (PAM) as core expectations.
Cloud-first operational reality
Today's Essential Eight assumes Windows server fleets and on-premises Active Directory in many places. The successor framework is likely to acknowledge that most Australian SMBs and mid-market organisations now operate Microsoft 365, Intune-managed endpoints, and SaaS-first architectures.
Measurement and reporting
Likely additional guidance on how to evidence the controls to insurers, boards and auditors. The current ML self-assessment process is not consistent across organisations and the successor framework is expected to address this.
What to do between now and the final framework
Six practical actions while the framework settles.
Useful regardless of how the final framework lands.
We are working through these six steps with our own client base. Each is useful regardless of how the final Essentials for enterprise IT framework is structured. The intent is to ensure that when the successor framework is published, your organisation is in a strong position to evidence the controls already in place rather than scrambling to retrofit them. The consultation has closed, but the transition period is only just beginning.
Consultation has closed
The public consultation on Essentials for enterprise IT closed on 12 July 2026. ASD will now work through submissions before publishing the final framework. If you missed the window, your priorities are still best captured in a written Essential Eight maturity assessment with evidence, ready for when the successor framework lands.
Document current Essential Eight maturity
Have a current, written ML self-assessment with evidence per control. Most organisations have a verbal understanding of where they sit. Write it down. The successor framework will refer back to today's maturity model for transition purposes.
Move identity to the centre
Whatever the final framework says, identity will be elevated. Enforce conditional access, deploy ITDR, document privileged access procedures, and rationalise admin accounts. This is the single highest-leverage area.
Build outcome evidence, not just configuration evidence
Start logging the outcomes the framework is likely to ask for. Examples: number of credential-stuffing attempts blocked per quarter, mean time to patch by criticality, percentage of administrative actions performed from PAW devices, percentage of OT assets visible to your asset inventory.
Clean up your backup posture
Backups remain critical. Verify the 3-2-1 minimum, test restorations quarterly, document RTO and RPO per system, and confirm Microsoft 365 backups are in place. The successor framework is likely to be stricter on testing.
Line up who bridges the two frameworks
Decide now who is accountable for translating between the current Essential Eight and the successor framework as it lands, so the mapping work does not stall. Real Bytes will publish a Real Bytes view on transition once ASD publishes the consultation outcome.
Sources referenced
- 01
Consultation on evolution of Essential Eight
Australian Signals Directorate (ASD)Closed 12 Jul 2026www.cyber.gov.au - 02
Essential Eight maturity model
ASD Cyber.gov.auwww.cyber.gov.au - 03
ASD Cyber Security Partnership Program
ASD Cyber.gov.auwww.cyber.gov.au
This page summarises publicly available Australian government, regulator and legal sources. It is general information, not legal advice.
The Essential Eight is being updated, not scrapped. Here is the simple plan to stay ahead of it.
You may have seen the headlines about ASD retiring the Essential Eight. It is easy to read that and worry you are about to be caught out, but there is no need to. What ASD is actually doing is evolving the framework into a new Essentials series, with the first chapter (Essentials for enterprise IT) having been through public consultation that closed on 12 July 2026. ASD expects to begin deprecating the Essential Eight at roughly the 12-month mark and retire it entirely at around 24 months, with both frameworks running concurrently in the meantime. The eight core strategies you already know (MFA, patching, backups, restricting admin rights, application control) stay right where they are. What changes is how the outcomes are described, not what good security looks like for an everyday Australian business.
So if you are wondering what to do while the framework settles, the answer is reassuringly boring: get the controls in place, write them down, and hold a certificate your customers already trust. That is exactly what SMB1001 certification is built to do, and the work carries straight over to both today's Essential Eight and the identity-first successor. You are not starting again later. You are doing the groundwork once, and staying ahead of whatever the final framework asks for.
The plan we have
SMB1001 certification, starting today.
Why this holds up either way
SMB1001 is the one certification built specifically for small and medium businesses, and it maps directly to the Essential Eight, the USA's CMMC, the UK's Cyber Essentials, and Singapore's Cyber Trustmark. It is reviewed and reissued every year, so it keeps pace rather than freezing in place.
That means the controls you put in for SMB1001 today are the same ones the successor framework is expected to lean on: identity, MFA, conditional access, tested backups and a documented response plan. You are not gambling on one framework over another. You are quietly doing the work both will ask for, and we walk through every step of it with you.
Already have a tender or insurer asking for it?
07 3114 2808Common questions
Questions Australian leadership teams are asking about the E8 evolution.
There is no published commencement date. ASD's consultation closed on 12 July 2026. ASD will now work through submissions, publish the final framework, and run a transition period where both Essential Eight and the successor framework are referenced in parallel. ASD expects to begin deprecating the Essential Eight at roughly the 12-month mark and retire it entirely at around 24 months, so expect at least 12 to 18 months of dual-running once the new framework is published.
Related in this cluster
Other operational and regulatory pages for Australian businesses.
Between two frameworks
The bridge between today's Essential Eight and the successor framework.
Real Bytes will publish a Real Bytes view on transition once ASD publishes the consultation outcome. In the meantime, we continue to deliver Essential Eight ML1 to ML3 programmes with full documentation, outcome evidence, and identity-first architecture so that whatever the final framework looks like, you are well positioned.
This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.
Keep exploring
Related services, locations and industries
Explore how this connects across our wider offering.

Remote Support