Essential Eight retirement: what ASD has actually said — and what it hasn’t

The Australian Signals Directorate has published a consultation on evolving the Essential Eight into the first chapter of a broader ‘Essentials’ series, with further chapters flagged to follow; the domains most often discussed are cloud, operational technology and artificial intelligence. That consultation closed on 12 July 2026. What ASD has not published is a retirement timetable — the deprecation and retirement horizons circulating in the market trace back to a single interview remark by an ACSC official, not to ASD policy, and no firm cut-over date has been published as of July 2026. The eight mitigation strategies and their maturity levels remain the official baseline today, so the practical move is to keep executing ML1–ML3 while watching the ASD guidance closely.

By Aneis Samaan, founder of CyberSentien · Last updated July 2026

What is actually changing — and what is not

It is easy to read ‘Essential Eight retirement’ as a switch being flipped. That is not what the signals suggest. The Essential Eight remains the ASD’s recommended baseline of mitigation strategies, and the Maturity Model that grades them (Maturity Level One through Three) is still the reference organisations are measured against in 2026. What has been signalled is a direction of travel: the ASD has indicated it intends to broaden its prioritised-mitigation guidance into an ‘Essentials’ series that reflects how modern organisations actually operate. The current Essential Eight was designed around a Microsoft Windows internet-connected network; that assumption no longer fits most Australian businesses.

Until the ASD publishes finalised replacement guidance, the honest position is this: nothing you have built against the Essential Eight is wasted, and no organisation should stop applying application control, patching, MFA or backups because a successor is being discussed. The maturity model is not deprecated today. Anyone telling you the Essential Eight is already gone is ahead of the published record. You can follow the primary source directly at cyber.gov.au.

Why the ASD is moving toward an ‘Essentials’ series

The Essential Eight was built for a world of managed desktops and a defined network perimeter. Three shifts have stretched that model to breaking point, and each maps to an area the successor guidance is commonly expected to address.

Cloud & SaaS

Controls like ‘patch operating systems’ and ‘restrict administrative privileges’ were written for machines you own. Most workloads now sit in Microsoft 365, AWS, Azure or Google Cloud, where the shared-responsibility line and identity-based access change what ‘good’ looks like.

Operational technology

Manufacturing, utilities, logistics and healthcare run OT and industrial control systems that frequently cannot be patched on a Windows cadence or run application control agents. These environments have been under-served by the current eight.

Artificial intelligence

The rapid adoption of AI systems — both as attack surface and as a tool used inside the business — introduces risks the 2017-era mitigation set never contemplated. Governance of AI use is expected to feature in the broader guidance.

Read these as the problems the ASD is trying to solve, not as confirmed chapter headings. The scope, naming and structure of any Essentials series should be treated as proposed until the ASD releases it.

The current Essential Eight, for reference

Whatever succeeds it will almost certainly build on these strategies rather than discard them, so they remain the right thing to invest in now.

StrategyPrimary purposeWhere it is stretched today
Application controlPrevent unapproved code executingHard on OT and BYO devices
Patch applicationsClose known vulnerabilitiesSaaS patching sits with the vendor
Configure Office macrosBlock a common delivery pathNarrowly Microsoft-specific
User application hardeningReduce browser/plugin riskCloud-native apps differ
Restrict admin privilegesLimit blast radiusNow an identity/IAM problem
Patch operating systemsRemove OS vulnerabilitiesOT devices resist patch cycles
Multi-factor authenticationStop credential reuseBroadly still essential everywhere
Regular backupsRecover from ransomwareMust now cover SaaS data too

If you are still building your evidence base for these, our walkthrough of Maturity Level Two evidence is the most efficient place to start.

The timeline: what we know, and what is speculation

There is no published, dated deprecation schedule for the Essential Eight as of July 2026. What exists is two different kinds of statement, and they should not be conflated. ASD has published a consultation on the evolution of the Essential Eight into ‘Essentials for enterprise IT’, the proposed first chapter of the series; that consultation closed on 12 July 2026. Separately, Chris Horlyck, the ACSC’s Head of Cyber Security Resilience, told iTnews on 24 June 2026 that ASD would look to begin deprecating the Essential Eight in about 12 months and retire it as a whole in about 24 months — an intention stated in a trade interview, not a published schedule. Any ‘Essential Eight deprecation 2026’ date you see quoted should be treated with caution unless it links to an ASD source. What is reasonable to expect, based on how the ASD has handled prior guidance changes:

Our advice: assign someone to monitor cyber.gov.au for the release, and do not pause current Essential Eight work in anticipation of it.

How to prepare now without betting on unpublished detail

The strongest position going into any framework change is a well-organised, evidence-backed control environment — because good evidence is portable across frameworks. Practical steps that pay off regardless of the final shape of the Essentials series:

Keep executing ML1–ML3

Maintain and improve your current maturity. A control with real evidence behind it re-maps cleanly to whatever succeeds it.

Extend your inventory to cloud and OT

Start documenting SaaS, cloud workloads and any OT you run now. If the successor guidance formalises these, you will already have the asset picture.

Organise evidence, not screenshots

Store dated, verifiable evidence per control. This is the work that survives a framework rename — and where a false green (a control marked done with nothing behind it) hurts most.

Watch, don’t pre-build

Resist implementing speculative ‘AI controls’ against headings that do not yet exist. Prepare the capability; wait for the published requirement.

This is where CyberSentien is designed to help. We assess readiness and organise the underlying evidence for the Essential Eight today — and because our approach is evidence-led rather than checkbox-led, controls without supporting evidence read ‘manual assessment required’ rather than a misleading green. When the Essentials series is published, a clean evidence base is what makes re-mapping cheap. We provide readiness and evidence assessment; we do not certify, and no software substitutes for accredited assessment where a scheme requires it.

Try it on sample docs

What this means for small and mid-sized businesses

For most Australian SMBs, the practical takeaway is reassuring. The fundamentals the ASD has long recommended — MFA everywhere, tested backups, timely patching, least-privilege access — are exactly the controls expected to carry forward. If you are a smaller organisation weighing where to spend limited security effort, the answer does not change because a successor framework is being discussed: get the basics evidenced and repeatable. Our small-business guidance walks through doing that proportionately. Businesses also juggling a tiered small-business cyber certification should note that the same underlying evidence — MFA logs, backup records, patch reports — supports multiple frameworks at once, which is the whole point of building the evidence base rather than the checklist. When accredited certification against a small-business certification scheme is required, that certificate is issued by an accredited provider, not by CyberSentien; our role is to prepare the readiness and evidence behind it.

Frequently asked

Is the Essential Eight being retired?

Not today, and not by published policy. The Essential Eight and its Maturity Model remain ASD’s current baseline. The retirement timeline in circulation comes from one interview: Chris Horlyck, the ACSC’s Head of Cyber Security Resilience, told iTnews on 24 June 2026 that ASD would look to begin deprecating the Essential Eight in about 12 months and retire it as a whole in about 24 months. That is an intention stated by a named official in a trade interview, not published ASD policy, and ASD has published no deprecation schedule.

What is the ASD Essentials series?

A proposed successor body of guidance, structured as chapters by technology domain. ASD consulted on the first chapter, ‘Essentials for enterprise IT’, until 12 July 2026; further chapters are expected to address domains such as cloud, operational technology (OT) and artificial intelligence. Scope, naming and structure should be treated as proposed until ASD publishes the final guidance.

What should businesses do now?

Keep meeting the Essential Eight — it remains the current baseline — while watching for ASD’s published outcome from the consultation that closed on 12 July 2026. CyberSentien maps frameworks and AI governance, so evidence carries into any successor series.

When will the change take effect?

No date has been published. ASD ran a consultation on the proposed first chapter that closed on 12 July 2026, but has not published a cut-over or retirement date. The only timeline in circulation is the intention Chris Horlyck stated to iTnews on 24 June 2026 — deprecation beginning around 12 months out, retirement around 24 months out — which remains subject to consultation and to ASD publishing final guidance.