The Essential Eight is 126 of the ISM’s 1,143 controls

By Greg Markowski / Sep 9, 2026 / Epic IT News

This week we pulled the September 2026 Information Security Manual apart, control by control, using the ASD’s own machine-readable data. Two numbers stood out. The ISM now contains 1,143 controls. The Essential Eight, the framework most Australian businesses treat as their entire security programme, draws on just 126 of them.

That gap is not a criticism of the Essential Eight. It was always meant to be a prioritised baseline, not the whole book. But with the ASD retiring the Essential Eight in favour of the Essentials series, and the new series grounded directly in the ISM, that other 89 per cent of the manual is about to matter a lot more. Here is what the numbers actually look like.

How many controls are in the ISM?

The September 2026 release of the ISM contains 1,143 numbered controls (the ISM-XXXX identifiers) plus 49 governing principles grouped under functions like GOVERN, IDENTIFY and PROTECT. The ASD publishes it quarterly, in March, June, September and December, and the count moves every release: June 2026 added 29 controls, September added a block of 44 new ones (ISM-2124 through ISM-2167) while amending and rescinding others.

Control numbering runs past 2160, but plenty of older IDs have been retired along the way, which is why the live count sits at 1,143 rather than the highest number on the page. The manual is published on cyber.gov.au as a PDF, a spreadsheet, and a machine-readable OSCAL dataset on the ACSC’s GitHub. We used the OSCAL version (2026.09.4, published 3 September) for every figure in this post, so you can check our counting.

How the Essential Eight maps to ISM controls

The Essential Eight has never been a separate rulebook. Each of its eight mitigation strategies is backed by a defined set of ISM controls, and the ASD tags every one of those controls with the maturity level it belongs to. Counted from the September 2026 data:

Essential Eight maturity level ISM controls required
Maturity Level 1 46
Maturity Level 2 87
Maturity Level 3 123
Unique controls across all levels 126

So a business achieving Maturity Level 2, the benchmark most government contracts and insurers ask for, is implementing 87 ISM controls. Full ML3 gets you to 123. Either way, the Essential Eight covers roughly 11 per cent of the manual it comes from.

Where the 126 controls actually live

Spread those 126 controls across the ISM’s own section structure and the shape of the Essential Eight becomes obvious. The biggest concentrations, from the September 2026 data:

ISM section E8 controls Feeds which strategy
Office productivity suites 17 Configure Microsoft Office macros
Multi-factor authentication 16 Multi-factor authentication
Mitigating known vulnerabilities 15 Patch applications and operating systems
Application control 11 Application control
Backup sections (four combined) 11 Regular backups
Vulnerability scanning 9 Patch applications and operating systems
Privileged access to systems 8 Restrict administrative privileges
Web browsers, PDF software, PowerShell 10 User application hardening

The remainder sit in supporting sections: event logging, incident reporting, privileged operating environments and credential protection, the plumbing that ML2 and ML3 demand around the headline strategies. Worth noticing: macro settings for Office, often treated as the boring strategy, is backed by the single largest block of controls.

44 new controls in September. None of them touch the Essential Eight

Here is the part we find genuinely interesting. The September ISM added 44 controls, the largest single block in recent releases. They cover AI agents (each agent gets its own identity, sits in an agent register, runs with least privilege, and needs a human in the loop before high-impact actions), OAuth application approval, risk-based access using contextual signals, vendor remote access and ransomware-resistant backups.

The number of those 44 controls tagged to any Essential Eight maturity level: zero.

That is not an oversight. It is the clearest evidence yet of why the ASD is replacing the framework. The threats the ISM is being extended to cover, agentic AI above all, do not fit inside eight strategies written in 2017. The Essentials series exists precisely to close that gap, and because it will be grounded in the ISM, the controls added this quarter are a preview of what the new chapters will ask of you. We track every development on our Essentials series transition tracker, including what the September release signals about the coming agentic AI chapter.

What this means for your compliance programme

Nothing about your current obligations changes. The Essential Eight remains the live, assessable standard, ML2 remains the contract and insurance benchmark, and the 87 controls behind it remain exactly the right place to spend your security budget today.

What changes is how you should think about the ceiling. If your security programme treats the Essential Eight as the finish line, you are working to 11 per cent of the ASD’s guidance, and the 89 per cent you are ignoring is where the manual is growing fastest. Businesses running AI tools, heavy SaaS stacks or third-party vendor access are already exposed to risks the ISM now addresses and the Essential Eight never will. For DISP members and government suppliers, the ISM has always been the underlying reference; for everyone else, it is about to become one.

What you should do now

Confirm your Essential Eight maturity rating and get it documented. The 126 mapped controls are stable because the ASD is retiring the framework rather than updating it. A dated, evidenced ML2 assessment is the baseline you will carry into the Essentials transition, and it holds its value.

Scan the September additions against your environment. If you run AI agents, Copilot-class tools, or give vendors remote access, the new control block describes your risks whether or not any framework requires it yet. An agent register and human approval for sensitive actions are cheap to stand up now and will likely be mandatory later.

Get a gap view across the wider ISM, not just the Essential Eight. We run this as part of our security assessments: your current maturity, the ISM controls relevant to how you actually operate, and what carries into the Essentials series. Contact us on 1300 EPIC IT for a free security gap analysis.

Frequently asked questions

How many controls are in the ISM?

The September 2026 Information Security Manual contains 1,143 numbered ISM controls plus 49 governing principles. The count changes quarterly as the ASD adds, amends and rescinds controls, so always check the current release on cyber.gov.au.

Is the Essential Eight part of the ISM?

Yes. Each Essential Eight strategy is a prioritised bundle of ISM controls: 46 at Maturity Level 1, 87 at ML2 and 123 at ML3, with 126 unique ISM controls across all levels. The Essential Eight is a curated shortlist of the manual, not a separate standard.

How often is the ISM updated?

Quarterly: March, June, September and December. Each release publishes a changes document listing added, amended and rescinded ISM controls. The September 2026 release added 44 new controls, mostly covering AI agents, OAuth applications and vendor access.

Do businesses need to comply with all 1,143 ISM controls?

No. The ISM is a risk-based catalogue: you select controls relevant to your systems, data sensitivity and threat exposure. Government entities and DISP members work against it directly. Most private businesses start with the Essential Eight subset and extend from there.

What is the difference between the ISM and the Essential Eight?

The ISM is the ASD’s full control catalogue, currently 1,143 ISM controls across governance, hardening, networking, personnel and more. The Essential Eight is the ASD’s shortlist of the highest-value mitigations drawn from it. The incoming Essentials series will also be built from the ISM, chapter by chapter.

Want to know where you sit against the ISM?

Our Perth-based security team maps your current Essential Eight maturity and the wider ISM controls that matter to how you operate. Book a free security gap analysis today.

Book a Free Gap Analysis

About the Author
Written by Greg Markowski, Founding Director of Epic IT, a CRN Fast50-recognised Microsoft Solutions Partner managing IT and cybersecurity for Perth businesses since 2003. Greg holds a Degree in Computer Science and a Diploma in Computer Systems Engineering from Edith Cowan University, and is ITIL certified.

Further Reading

Previous

N-able N-central attacks: is your IT provider the way in?

Return to News
Back to News
Next

Best Penetration Testing Companies in Australia: Who Does What in 2026