Our Services / Managed Security Services (MSSP)

Essential Eight replacement tracker: the move to the Essentials series

The ASD is retiring the Essential Eight over the next two years. This page tracks every confirmed development in the transition, what remains unknown, and what Australian businesses should do at each stage. Bookmark it. We update it as the ASD moves.

Book a Transition Assessment

Last updated: 15 August 2026. Current status: consultation on the first chapter has closed. Final guidance not yet published. The Essential Eight remains the live, supported baseline.

15 June 2026

ASD opened consultation on evolving the Essential Eight into the Essentials series

~Mid 2027

ASD expects to begin deprecating the Essential Eight, roughly 12 months from the announcement

~Mid 2028

Essential Eight expected to be fully retired, roughly 24 months from the announcement

4 Chapters

Enterprise IT, cloud, and operational technology flagged, with agentic AI a likely fourth

What is replacing the Essential Eight?

The short answer: the Essentials series, a set of domain-specific chapters grounded in the ASD’s Information Security Manual.

On 15 June 2026 the Australian Signals Directorate opened consultation on the biggest change to Australia’s baseline cyber guidance since the Essential Eight replaced the Top Four in 2017. The Essential Eight is being retired and replaced by the Essentials series: prioritised, threat-informed mitigations organised by technology domain rather than a single eight-control checklist. The first chapter is Essentials for enterprise IT, the closest successor to the current framework. Chapters for cloud and operational technology are planned to follow, and the ASD has flagged agentic AI as a likely chapter of its own.

The ACSC has been direct that the change is not a punishment for anyone who invested in the Essential Eight. Organisations using the framework today can expect their existing controls, tools, and platforms to map into the new series. Patching, MFA, application control, privileged access, and backups are not going anywhere. What changes is the packaging: domain-specific guidance built for cloud, SaaS, and AI-era environments the 2017 framework was never designed to cover. Our full analysis of the retirement announcement covers the reasoning in depth.

For Perth businesses mid-way through an Essential Eight uplift, and for the government suppliers and defence businesses we support nationally, the practical guidance on this page is the same one the ASD gives: keep going. Your rating today still decides tenders, insurance, and DISP membership tomorrow.

Confirmed vs not yet confirmed

Plenty of commentary blurs this line. Here is exactly where it sits as of 15 August 2026.

Confirmed by the ASD

The Essential Eight will be retired, on a staged timeline: both frameworks run side by side during transition, deprecation begins around the 12-month mark, retirement at around 24 months.

The replacement is the Essentials series, grounded in the Information Security Manual, delivered as domain chapters starting with Essentials for enterprise IT.

Consultation on the first chapter ran from 15 June to 12 July 2026 through the ASD Cyber Security Partnership Program portal.

Existing Essential Eight controls and investments are expected to align strongly with the new guidance. The ASD describes the approach as cost-conscious and building on what organisations already have.

Not yet confirmed

The final control set for Essentials for enterprise IT, including whether the number eight survives at all.

Whether the current maturity model (ML0 to ML3) carries over, changes shape, or is replaced.

Assessment, evidence, and exception handling under the new series.

A publication date for the final enterprise IT chapter, and timing for the cloud, OT, and agentic AI chapters.

How the PSPF, DISP, cyber insurers, and government contracts will re-reference their Essential Eight requirements. Until they do, existing obligations stand as written.

The transition timeline

  1. 15 June 2026: consultation opens. The ASD announces the evolution of the Essential Eight and opens consultation on Essentials for enterprise IT through its Partnership Program portal.
  2. 24 June 2026: retirement confirmed. The ACSC’s head of cyber security resilience confirms the staged timeline publicly: deprecation from roughly 12 months, retirement at roughly 24 months.
  3. 12 July 2026: consultation closes. Feedback from government, industry, regulators, and Essential Eight users goes into drafting the first chapter.
  4. Now to mid-2027: parallel running. The Essential Eight remains the live, assessable baseline. This is the window to lock in your current maturity rating as the baseline for the coming gap analysis.
  5. ~Mid-2027: deprecation begins. Expect final Essentials for enterprise IT guidance and the start of formal transition. We will publish our control-by-control mapping within 48 hours of the final chapter landing.
  6. ~Mid-2028: retirement. The Essential Eight ceases to be ASD guidance. Contracts, questionnaires, and policies that name it will need updated references well before this date.

Chapter watch

The Essentials series is chapter-based. Here is what each planned domain covers and how we read the ASD’s direction so far.

Essentials for enterprise IT

The direct successor to the Essential Eight and the only chapter consulted on so far. Expected to carry today’s core controls forward while fixing the framework’s known blind spots around SaaS and identity. Status: consultation closed, final guidance pending.

Essentials for cloud

A confirmed future chapter. Splitting cloud into its own domain lets the ASD address shared-responsibility boundaries the current framework blurs, which matters for every Microsoft 365 and Azure environment we manage. Status: announced, no draft.

Essentials for operational technology

A confirmed future chapter recognising that OT environments cannot be governed like enterprise IT. Most relevant to our mining, engineering, and critical infrastructure clients. Status: announced, no draft.

Essentials for agentic AI

Flagged by the ASD as a likely chapter, on the basis that autonomous AI agents raise identity, access, and prompt-injection problems conventional controls were never designed for. The ACSC’s May 2026 guidance on AI in cyber defence previews this thinking. As Australia’s first AI-led MSP, this is the chapter we watch closest. Status: flagged, not committed.

What your business should do now

  1. Keep implementing the Essential Eight. It remains the assessable standard, and the ASD has said existing work carries forward. If you are mid-uplift towards Maturity Level 2, finish it. Our Essential 8 compliance guide covers the full framework.
  2. Document your current maturity as a baseline. When the new chapter lands, the first task is a gap analysis against it. A dated, evidenced record of where you stand today makes that fast and cheap.
  3. List everything that names the Essential Eight. Contracts, insurance policies, tender responses, board papers, and security questionnaires. Each reference will need updating during the transition, and knowing where they all live now avoids a scramble later.
  4. Strengthen the areas the new series is built to cover. Cloud and identity controls, SaaS governance, and AI usage are exactly where the ASD says the old framework fell short. Uplift there pays off under both frameworks.
  5. Assign someone to watch the transition. Or let us do it. We track every ASD development, brief our managed security clients as changes land, and update this page for everyone else.

The control mapping is coming

The moment the ASD publishes the final Essentials for enterprise IT chapter, we will publish a control-by-control mapping: each current Essential Eight strategy, its equivalent in the new guidance, what carries forward unchanged, and what needs new work. The template is built and waiting. Expect it on this page within 48 hours of release.

Update log

15 August 2026. Tracker published. Consultation closed 12 July; no final chapter yet. Added analysis connecting the ACSC’s updated AI cyber defence guidance (revised 12 August) to the Essentials series direction: it is organised by the ISM’s six functions rather than the eight controls, and addresses agentic AI directly.

12 July 2026. Consultation on Essentials for enterprise IT closed via the ASD Cyber Security Partnership Program portal.

24 June 2026. ACSC confirmed the staged retirement timeline publicly: deprecation from roughly mid-2027, retirement by roughly mid-2028. Our analysis of the announcement.

18 June 2026. We published guidance on what the retirement means for DISP members: the ML2 obligation stands and carries forward.

15 June 2026. ASD opened consultation on the evolution of the Essential Eight into the Essentials series.

Want a plan for the transition?

Our Essential Eight transition assessment maps your current maturity, flags what carries forward, and gives you a dated baseline before the new framework lands.

Book a Transition Assessment

Frequently asked questions

Is the Essential Eight being replaced?

Yes. The ASD confirmed in June 2026 that the Essential Eight will be retired over roughly two years. Its Essential Eight replacement is the Essentials series, a set of domain-specific chapters grounded in the Information Security Manual, starting with Essentials for enterprise IT.

Should we stop working towards Essential Eight compliance?

No. The Essential Eight remains the live, assessable standard until the transition completes, and the ASD has said existing controls and investments will align strongly with the new guidance. Insurers, government contracts, and DISP still assess against it today. Our Essential Eight implementation service continues unchanged.

When will the Essentials series be published?

The ASD has not confirmed a publication date. Consultation on the first chapter closed on 12 July 2026, and deprecation of the Essential Eight is expected to begin around mid-2027, which suggests final enterprise IT guidance before then. We update this tracker as soon as dates firm up.

What happens to my Maturity Level 2 rating?

Nothing changes today. ML2 remains the benchmark most government contracts, insurers, and DISP require, and the ASD has not confirmed how the maturity model translates into the new series. A documented ML2 rating is the strongest possible baseline to carry into the transition.

Does the Essential Eight replacement cover AI?

The ASD has flagged agentic AI as a likely future chapter of the Essentials series, and the ACSC’s 2026 guidance on AI in cyber defence already frames security around the ISM’s six functions with AI woven through them. If your business is deploying AI agents, that chapter will apply to you. Our AI governance service covers this ground today.

Is SMB1001 affected by the Essential Eight retirement?

No. SMB1001 is a separate framework run by CyberCert, not the ASD, and it is unaffected by this change. For many smaller businesses, SMB1001 certification remains a practical starting point that feeds naturally into ASD-aligned controls.