The Essential Eight is becoming the Essentials series: what to do before ASD changes the rules
Home/Latest Insights/Industry News
INDUSTRY NEWS

The Essential Eight is becoming the Essentials series: what to do before ASD changes the rules

CyberCorp Australia
Cybersecurity & GRC Team
29 September 20268 min read

In June 2026, the Australian Signals Directorate (ASD) announced a consultation on the "evolution" of the Essential Eight. The proposal introduces a new Essentials series, with the current Essential Eight guidance becoming its first chapter. For many organisations that have spent years working towards a maturity level target, the obvious question is whether that work is about to be wasted.

Going by what ASD has published, the answer is no. ASD's own announcement says organisations already using the Essential Eight can expect strong alignment with their existing controls and investments. What is not yet clear is how the new guidance will be structured, how it will be assessed, and when the change takes effect. This article separates what is confirmed from what is reported, and sets out practical steps that hold up whichever way the details land.

What ASD has actually announced

ASD's announcement, first published on cyber.gov.au on 15 June 2026, is short. Its main points are these:

  • ASD is consulting with its Cyber Security Network partners on the evolution of the Essential Eight cyber security framework.
  • The proposed evolution introduces a new Essentials series, which expands the current framework to give organisations greater flexibility in how they implement cyber security, while still providing a clear path to strong cyber resilience.
  • The new guidance is grounded in the Information Security Manual (ISM). It is described as offering prioritised, threat-informed mitigations for contemporary technology environments, supported by practical tools and clear implementation guidance.
  • The evolution of the current Essential Eight guidance will form the first chapter of the series, titled Essentials for enterprise IT. Additional chapters will follow.
  • Consultation ran through the ASD Cyber Security Partnership Program portal and closed on 12 July 2026.

ASD used the word "evolution" throughout, and that word matters. The announcement does not say the Essential Eight is being withdrawn, and it does not give a timeline for any change. At the time of writing, ASD's Essential Eight pages still list the Essential Eight, its maturity model, the assessment process guide and the ISM mapping as current publications, and the maturity model page shows a last update of November 2023.

What the media reported

Several outlets covered the announcement, and their reports add detail that is not in ASD's published statement. They are secondary reporting, some of it based on interviews, and should be read that way.

iTnews reported on 24 June 2026 that Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre within ASD, expects a transition period in which the Essential Eight and the Essentials remain live documents side by side. According to iTnews, he said ASD would "probably in 12 months" start to deprecate the Essential Eight, and that "in 24 months we'll retire the Essential Eight as a whole." iTnews also reported that the first three chapters would cover enterprise IT, operational technology and cloud, and that agentic AI could possibly become a dedicated chapter. Those timings came from an interview, not from ASD's announcement, and they were framed as anticipated rather than fixed. The same report quoted Horlyck saying that "the investment you've made under the Essential Eight will still be relevant under the Essentials."

Information Age (25 June 2026) quoted ASD technical expert Jayden Cooke describing a design that "moves away from relying only on prescriptive technical controls" and takes a principles-based approach. It also reported that the design is meant to remain compatible with existing Essential Eight programs. Information & Data Manager (19 June 2026) reported the consultation details and did not mention any timeline for the Essential Eight itself.

In short, the direction of travel is well supported by several reports. The dates are not. Anyone planning around a 12 or 24 month clock should treat it as an indication from one ASD official, reported by one outlet, and not as a published commitment.

What is still unknown

At the time of writing, no published draft or final version of Essentials for enterprise IT has been found, and no updated ASD statement since the consultation closed. That leaves several open questions that matter to compliance owners.

Final content and structure

The consultation was run through a partner portal, and the draft is not public. ASD has not said how much of it will change before release. Until a final chapter is published, any claim about specific controls or their wording is speculation.

Maturity levels and assessment

The current model asks organisations to pick a target maturity level and implement it across all eight strategies. iTnews reported that the Essentials series is designed to decouple threat-informed controls from a fixed maturity ladder, in response to a long-running complaint that maturity level requirements shifted under organisations' feet. ASD has not published how an Essentials-based assessment would work, whether maturity levels will survive in some form, or how existing assessment results would be treated. Anyone holding an assessment report against a maturity level target should note that this is unresolved.

Timing and transition

There is no published date for the first chapter, for the start of any deprecation, or for any retirement. The reported 12 and 24 month figures are the only timing information available, and they come from a media interview.

Regulatory and contractual standing

Government policy, regulators and private counterparties have written the Essential Eight into their requirements. No one has yet said how those references will be updated. That is a question for the bodies that own each requirement, not for ASD alone.

Principles and prescriptive controls

The reporting points to a real change in style. The current Essential Eight is a short list of specific mitigation strategies, each with detailed requirements at three maturity levels. Cooke's description, as reported by Information Age, suggests the Essentials series will lean more on principles and outcomes, with the ISM still providing the underlying controls. iTnews reported a similar shift from controls tied to specific technologies towards outcomes and intent.

For a compliance team, that could cut both ways. Flexibility helps organisations with a mixed estate of cloud services, SaaS and legacy systems that never fitted the original model cleanly. It also means more judgement. Where a prescriptive control gives an assessor something to test, an outcome needs an argument: what the risk is, what the organisation did about it, and why that is enough. Organisations that can already explain their controls in terms of the threats they address will be better placed than those that only know which boxes they ticked.

How far the principles-based approach goes is not yet known. The draft is not public, so nothing here assumes it is less rigorous than the current model.

No-regrets actions to take now

Uncertainty is not a reason to pause. The actions below make sense under the current Essential Eight, and they should also hold up under the Essentials series whatever its final shape.

  1. Keep the uplift going. Patching, multi-factor authentication, restricted administrative privileges, application control and tested backups reduce risk today. ASD has said existing investment remains relevant. A programme that stalls now will have less to show when the new guidance lands.
  2. Map your controls to the outcomes they achieve. For each Essential Eight strategy, record the threat it addresses, the systems in scope, the evidence you hold and any exceptions with their compensating controls. A control register written in terms of outcomes can be re-mapped to a new framework far faster than one written as a checklist.
  3. Do not rip and replace. Avoid large purchases or re-platforming justified only by the prospect of the Essentials series. Nothing published requires it, and ASD's announcement points to alignment with existing controls.
  4. Fix the known gaps first. If a maturity level target is not yet met, the missing controls are still worth closing. Gaps in areas such as patch timeframes, privileged access or backup testing are unlikely to become less relevant.
  5. Extend your view beyond enterprise IT. If iTnews's reporting on later chapters proves accurate, cloud services and operational technology will get their own guidance. Start by listing where your organisation relies on cloud and shared-responsibility arrangements, and where operational technology exists. That inventory helps regardless of what ASD publishes.
  6. Assign an owner. Someone should track ASD announcements and report changes to the risk or audit committee. Without a named owner, changes are usually noticed late.

Contracts, tenders, insurance and board reporting

The most immediate exposure is not technical. It is the number of documents that name the Essential Eight and will not change on ASD's schedule.

Government and enterprise tender documents often ask for an Essential Eight maturity level. Supplier agreements and customer security schedules may name it as a required standard. Cyber insurance proposal forms commonly ask whether the organisation has implemented it. Board and risk committee reports frequently track progress against a maturity level target. All of these references point at a framework that ASD is now evolving.

A sensible approach is to review these references now, without waiting for the final guidance. List the contracts, panel arrangements and insurance policies that cite the Essential Eight, note the renewal date of each, and work out who owns the conversation with the counterparty. Where a document names a specific maturity level, it is reasonable to assume it will keep meaning that level until the counterparty says otherwise. Where you are drafting new language, consider referring to "the Essential Eight, or any successor guidance published by ASD" so the wording does not go stale.

For boards, the message is continuity. Reporting against the current maturity model remains valid, and existing targets remain meaningful. Directors should expect management to explain the plan for the transition, including the owner, the inventory work and the triggers that would prompt a change in approach. They should not expect a new target to be set before ASD has published the final guidance.

What to watch for

Several signals will tell you when to move from monitoring to action:

  • Publication of Essentials for enterprise IT, in draft or final form, on cyber.gov.au.
  • Any ASD statement on how assessments will work, and whether maturity levels continue.
  • Changes to the Essential Eight maturity model, assessment process guide or ISM mapping pages.
  • An ASD or government announcement confirming, or contradicting, the transition timing reported by iTnews.
  • Updates from regulators, government procurement bodies and insurers on how they will treat Essential Eight references.
  • Publication of chapters covering cloud or operational technology, and any decision about agentic AI.

Key takeaways

  • ASD has announced an evolution of the Essential Eight into a new Essentials series. Its own announcement gives no timeline and does not say the Essential Eight is being withdrawn.
  • ASD states that organisations already using the Essential Eight can expect strong alignment with their existing controls and investments.
  • iTnews reported that an ASD official anticipates deprecation in about 12 months and retirement in about 24 months. That timing has not been published by ASD.
  • Final content, assessment approach, maturity level treatment and timing are all still unknown.
  • Keep the uplift going, map controls to the outcomes they achieve, and avoid spending driven only by the change.
  • Review the contracts, tenders, insurance forms and board reports that cite the Essential Eight, and assign someone to track ASD announcements.

CyberCorp's GRC specialists help Australian organisations turn Essential Eight investment into evidence that stands up to boards, auditors and counterparties, and prepare it for whatever ASD publishes next. To find out where you stand, Schedule a GRC Assessment, or learn more about our compliance frameworks services.

Back to Insights