Cybersecurity

The Essential Eight Is Being Retired. Here Is What Melbourne SMEs Should Do Now

The Australian Signals Directorate has started replacing the Essential Eight. On 15 June 2026 it opened consultation on a new “Essentials” series, beginning with a chapter called Essentials for enterprise IT. Media reporting a week later put the Essential Eight on a roughly two-year path to retirement. If your business has spent the last few years working towards Maturity Level 1 or 2, here is what has actually been announced, what has not, and what to do about it.

What ASD has announced

The primary source is short. ASD’s consultation notice says it is “consulting with Cyber Security Network partners on the evolution of the Essential Eight cyber security framework”. The replacement is an “Essentials series” of documents, grounded in the Information Security Manual (ISM). The first chapter, Essentials for enterprise IT, was released to partners in draft for comment, with the consultation closing on 12 July 2026.

The line that matters most for anyone who has already invested in the Essential Eight is this one, from ASD: “Organisations already using the Essential Eight can expect strong alignment with their existing controls and investments.”

That is the whole of what ASD has published at the time of writing. No final document, no control list, no dates.

What has been reported, but not published by ASD

On 24 June 2026 iTnews reported comments from the ACSC’s head of cyber security resilience, Chris Horlyck, that ASD expects to start deprecating the Essential Eight in about 12 months and retire it in about 24 months, keeping both frameworks live during the transition. The same reporting described the planned shape of the series: enterprise IT first, then operational technology and cloud, with agentic AI mentioned as a possible later chapter.

Horlyck’s reassurance was direct: “The investment you’ve made under the Essential Eight will still be relevant under the Essentials.”

Treat the timeline as indicative. It comes from one interview, not from an ASD publication. If a tender, insurer or board paper needs a date, the honest answer today is that ASD has not set one.

Timeline so far

  • November 2023: current Essential Eight Maturity Model published. Still in force.
  • 15 June 2026: ASD opens consultation on the Essentials series with the draft Essentials for enterprise IT chapter, via the Cyber Security Partnership Program portal.
  • 24 June 2026: iTnews reports ASD’s intent to deprecate the Essential Eight in about 12 months and retire it in about 24 months, with both frameworks running side by side in between.
  • 12 July 2026: consultation closes.
  • Next: publication of the final Essentials for enterprise IT. No date has been given. Chapters for operational technology and cloud are expected to follow.

Known and unknown, in one table

QuestionStatusSource
Is the Essential Eight being replaced?Yes, by an “Essentials” series grounded in the ISMASD, 15 June 2026
What is the first chapter?Essentials for enterprise ITASD, 15 June 2026
Will existing Essential Eight work still count?ASD says to expect “strong alignment” with existing controls and investmentsASD, 15 June 2026
When is the Essential Eight retired?No ASD date. Reported as about 24 months from June 2026, with deprecation from about 12 monthsiTnews, 24 June 2026
Do maturity levels continue?Not statedn/a
What are the final controls?Not publishedn/a
Is the current Maturity Model still current?Yescyber.gov.au

Why ASD is doing this

The Essential Eight was written for a world of on-premises servers, domain-joined Windows fleets and Office macros. Most Melbourne SMEs now run Microsoft 365 or Google Workspace, a handful of SaaS platforms and laptops that rarely see the office network. Several of the eight strategies translate awkwardly to that world. Patching “operating systems” means something different when the operating system is a cloud service you do not control. Application control on a SaaS estate is a different problem from application control on a Windows desktop.

The reported intent of the Essentials series is to move from prescriptive, technology-specific controls towards outcomes, and to give different environments (enterprise IT, OT, cloud) their own guidance rather than one list for everyone.

What it means for a Melbourne SME right now

The Essential Eight is still the benchmark today

Nothing has been retired. The Essential Eight Maturity Model remains current, and it is still what cyber insurers, government supply-chain contracts and most Australian security questionnaires reference. If you are mid-way through a Maturity Level 1 or Level 2 uplift, finish it. Stopping now would leave you exposed to the same attacks and less able to answer the questions you will be asked at renewal.

Your controls carry over

The eight strategies are not going away as controls, only as a fixed list. Patching applications and operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening and regular backups are the mitigations that stop most real-world attacks on SMEs. Any credible successor, will still expect them. ASD has said as much. What will change is how they are grouped, described and assessed.

Your evidence matters more than your label

Businesses that can show how each control is implemented and monitored will find the transition easy, whatever the new document calls things. Businesses that hold a “Maturity Level 2” statement from an assessor and nothing underneath it will find it hard. If your Essential Eight work produced a folder of evidence (Intune policies, Conditional Access rules, patch reports, restore test logs), you are in good shape.

Five things to do before the final document lands

  1. Keep your Essential Eight evidence current. Re-run your patch compliance, MFA coverage and backup restore reports. Date them. This is the evidence base you will map to the new framework.
  2. Map your controls to the ISM, not just to the Essential Eight. The Essentials series is grounded in the ISM. Every Essential Eight control already has ISM control identifiers behind it. Recording them now means you will not start the mapping from scratch later.
  3. Document your cloud and SaaS posture separately. Write down how identity, data protection, logging and backup work for Microsoft 365 or Google Workspace and your main SaaS platforms. This is where the current framework is weakest and where the first new chapter is aimed.
  4. Check the wording in contracts, tenders and insurance policies. Anything that says “Essential Eight Maturity Level X” will eventually need updating. Find those references now so nothing lapses when the language changes.
  5. Do not buy anything because of this. Vendors are already selling “Essentials-ready” tooling against a document that has not been published. There is nothing to be ready for yet that you cannot cover by doing the four steps above.

How we are handling it for managed clients

TechAssist is treating the Essentials series as an update to the same programme, not a new one. For managed clients on an Essential Eight roadmap, the plan is unchanged until ASD publishes the final Essentials for enterprise IT. When it does, we will map each client’s existing controls and evidence to the new structure and report the gaps, if any. We will update the Essential Eight guides on this site at the same time. If you are not a client and want a straight answer on where you stand today, an Essential Eight assessment is still the right starting point, because the controls it checks are the ones that will carry across.

Frequently asked questions

Is the Essential Eight still mandatory?

It was never mandatory for private businesses. It is required for many federal government entities under the Protective Security Policy Framework and is written into a lot of government contracts and insurance questionnaires. None of that has changed yet.

When exactly will the Essential Eight be retired?

ASD has not published a date. Media reporting from June 2026 quotes an ACSC official expecting deprecation to begin in around 12 months and retirement in around 24 months. Plan on the Essential Eight remaining the reference point through 2027.

Will maturity levels still exist?

Unknown. ASD has not said whether the three target maturity levels will survive in the Essentials series. Until it does, keep reporting against the current Maturity Model.

Should we pause our Essential Eight uplift?

No. The controls are the same controls that will be expected under any successor, and they are the ones that stop the attacks Melbourne SMEs actually experience.

Where can I read the ASD announcement?

The consultation notice is on cyber.gov.au under “Consultation on evolution of Essential Eight” (published 15 June 2026). The draft chapter itself was distributed through the ASD Cyber Security Partnership Program portal and has not been published publicly.

Sources

← Previous CCTV and Access Control on Your Business Network

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon, just a clear-eyed look at where you stand and what's possible.