The ASD is retiring the Essential Eight over the next two years. This page tracks every confirmed development in the transition, what remains unknown, and what Australian businesses should do at each stage. Bookmark it. We update it as the ASD moves.
Last updated: 15 August 2026. Current status: consultation on the first chapter has closed. Final guidance not yet published. The Essential Eight remains the live, supported baseline.
ASD opened consultation on evolving the Essential Eight into the Essentials series
ASD expects to begin deprecating the Essential Eight, roughly 12 months from the announcement
Essential Eight expected to be fully retired, roughly 24 months from the announcement
Enterprise IT, cloud, and operational technology flagged, with agentic AI a likely fourth
The short answer: the Essentials series, a set of domain-specific chapters grounded in the ASD’s Information Security Manual.
On 15 June 2026 the Australian Signals Directorate opened consultation on the biggest change to Australia’s baseline cyber guidance since the Essential Eight replaced the Top Four in 2017. The Essential Eight is being retired and replaced by the Essentials series: prioritised, threat-informed mitigations organised by technology domain rather than a single eight-control checklist. The first chapter is Essentials for enterprise IT, the closest successor to the current framework. Chapters for cloud and operational technology are planned to follow, and the ASD has flagged agentic AI as a likely chapter of its own.
The ACSC has been direct that the change is not a punishment for anyone who invested in the Essential Eight. Organisations using the framework today can expect their existing controls, tools, and platforms to map into the new series. Patching, MFA, application control, privileged access, and backups are not going anywhere. What changes is the packaging: domain-specific guidance built for cloud, SaaS, and AI-era environments the 2017 framework was never designed to cover. Our full analysis of the retirement announcement covers the reasoning in depth.
For Perth businesses mid-way through an Essential Eight uplift, and for the government suppliers and defence businesses we support nationally, the practical guidance on this page is the same one the ASD gives: keep going. Your rating today still decides tenders, insurance, and DISP membership tomorrow.
Plenty of commentary blurs this line. Here is exactly where it sits as of 15 August 2026.
The Essential Eight will be retired, on a staged timeline: both frameworks run side by side during transition, deprecation begins around the 12-month mark, retirement at around 24 months.
The replacement is the Essentials series, grounded in the Information Security Manual, delivered as domain chapters starting with Essentials for enterprise IT.
Consultation on the first chapter ran from 15 June to 12 July 2026 through the ASD Cyber Security Partnership Program portal.
Existing Essential Eight controls and investments are expected to align strongly with the new guidance. The ASD describes the approach as cost-conscious and building on what organisations already have.
The final control set for Essentials for enterprise IT, including whether the number eight survives at all.
Whether the current maturity model (ML0 to ML3) carries over, changes shape, or is replaced.
Assessment, evidence, and exception handling under the new series.
A publication date for the final enterprise IT chapter, and timing for the cloud, OT, and agentic AI chapters.
How the PSPF, DISP, cyber insurers, and government contracts will re-reference their Essential Eight requirements. Until they do, existing obligations stand as written.
The Essentials series is chapter-based. Here is what each planned domain covers and how we read the ASD’s direction so far.
The direct successor to the Essential Eight and the only chapter consulted on so far. Expected to carry today’s core controls forward while fixing the framework’s known blind spots around SaaS and identity. Status: consultation closed, final guidance pending.
A confirmed future chapter. Splitting cloud into its own domain lets the ASD address shared-responsibility boundaries the current framework blurs, which matters for every Microsoft 365 and Azure environment we manage. Status: announced, no draft.
A confirmed future chapter recognising that OT environments cannot be governed like enterprise IT. Most relevant to our mining, engineering, and critical infrastructure clients. Status: announced, no draft.
Flagged by the ASD as a likely chapter, on the basis that autonomous AI agents raise identity, access, and prompt-injection problems conventional controls were never designed for. The ACSC’s May 2026 guidance on AI in cyber defence previews this thinking. As Australia’s first AI-led MSP, this is the chapter we watch closest. Status: flagged, not committed.
The moment the ASD publishes the final Essentials for enterprise IT chapter, we will publish a control-by-control mapping: each current Essential Eight strategy, its equivalent in the new guidance, what carries forward unchanged, and what needs new work. The template is built and waiting. Expect it on this page within 48 hours of release.
15 August 2026. Tracker published. Consultation closed 12 July; no final chapter yet. Added analysis connecting the ACSC’s updated AI cyber defence guidance (revised 12 August) to the Essentials series direction: it is organised by the ISM’s six functions rather than the eight controls, and addresses agentic AI directly.
12 July 2026. Consultation on Essentials for enterprise IT closed via the ASD Cyber Security Partnership Program portal.
24 June 2026. ACSC confirmed the staged retirement timeline publicly: deprecation from roughly mid-2027, retirement by roughly mid-2028. Our analysis of the announcement.
18 June 2026. We published guidance on what the retirement means for DISP members: the ML2 obligation stands and carries forward.
15 June 2026. ASD opened consultation on the evolution of the Essential Eight into the Essentials series.
Yes. The ASD confirmed in June 2026 that the Essential Eight will be retired over roughly two years. Its Essential Eight replacement is the Essentials series, a set of domain-specific chapters grounded in the Information Security Manual, starting with Essentials for enterprise IT.
No. The Essential Eight remains the live, assessable standard until the transition completes, and the ASD has said existing controls and investments will align strongly with the new guidance. Insurers, government contracts, and DISP still assess against it today. Our Essential Eight implementation service continues unchanged.
The ASD has not confirmed a publication date. Consultation on the first chapter closed on 12 July 2026, and deprecation of the Essential Eight is expected to begin around mid-2027, which suggests final enterprise IT guidance before then. We update this tracker as soon as dates firm up.
Nothing changes today. ML2 remains the benchmark most government contracts, insurers, and DISP require, and the ASD has not confirmed how the maturity model translates into the new series. A documented ML2 rating is the strongest possible baseline to carry into the transition.
The ASD has flagged agentic AI as a likely future chapter of the Essentials series, and the ACSC’s 2026 guidance on AI in cyber defence already frames security around the ISM’s six functions with AI woven through them. If your business is deploying AI agents, that chapter will apply to you. Our AI governance service covers this ground today.
No. SMB1001 is a separate framework run by CyberCert, not the ASD, and it is unaffected by this change. For many smaller businesses, SMB1001 certification remains a practical starting point that feeds naturally into ASD-aligned controls.