The Essential Eight is being retired: the ASD Essentials series

The Australian Signals Directorate has signalled that the Essential Eight, in its current maturity-model form, will be superseded by a broader ‘Essentials’ series — a set of guidance that commonly extends beyond on-premises Windows environments to cover cloud, operational technology and artificial intelligence. Treat the specifics as proposed and subject to consultation: no firm cut-over date has been published as of mid-2026. The eight mitigation strategies and their maturity levels remain the official baseline today, so the practical move is to keep executing ML1–ML3 while watching the ASD guidance closely.

By Aneis Samaan, founder of CyberSentien · Last updated July 2026

What is actually changing — and what is not

It is easy to read ‘Essential Eight retirement’ as a switch being flipped. That is not what the signals suggest. The Essential Eight remains the ASD’s recommended baseline of mitigation strategies, and the Maturity Model that grades them (Maturity Level One through Three) is still the reference organisations are measured against in 2026. What has been signalled is a direction of travel: the ASD has indicated it intends to broaden its prioritised-mitigation guidance into an ‘Essentials’ series that reflects how modern organisations actually operate. The current Essential Eight was designed around a Microsoft Windows internet-connected network; that assumption no longer fits most Australian businesses.

Until the ASD publishes finalised replacement guidance, the honest position is this: nothing you have built against the Essential Eight is wasted, and no organisation should stop applying application control, patching, MFA or backups because a successor is being discussed. The maturity model is not deprecated today. Anyone telling you the Essential Eight is already gone is ahead of the published record. You can follow the primary source directly at cyber.gov.au.

Why the ASD is moving toward an ‘Essentials’ series

The Essential Eight was built for a world of managed desktops and a defined network perimeter. Three shifts have stretched that model to breaking point, and each maps to an area the successor guidance is commonly expected to address.

Cloud & SaaS

Controls like ‘patch operating systems’ and ‘restrict administrative privileges’ were written for machines you own. Most workloads now sit in Microsoft 365, AWS, Azure or Google Cloud, where the shared-responsibility line and identity-based access change what ‘good’ looks like.

Operational technology

Manufacturing, utilities, logistics and healthcare run OT and industrial control systems that frequently cannot be patched on a Windows cadence or run application control agents. These environments have been under-served by the current eight.

Artificial intelligence

The rapid adoption of AI systems — both as attack surface and as a tool used inside the business — introduces risks the 2017-era mitigation set never contemplated. Governance of AI use is expected to feature in the broader guidance.

Read these as the problems the ASD is trying to solve, not as confirmed chapter headings. The scope, naming and structure of any Essentials series should be treated as proposed until the ASD releases it.

The current Essential Eight, for reference

Whatever succeeds it will almost certainly build on these strategies rather than discard them, so they remain the right thing to invest in now.

StrategyPrimary purposeWhere it is stretched today
Application controlPrevent unapproved code executingHard on OT and BYO devices
Patch applicationsClose known vulnerabilitiesSaaS patching sits with the vendor
Configure Office macrosBlock a common delivery pathNarrowly Microsoft-specific
User application hardeningReduce browser/plugin riskCloud-native apps differ
Restrict admin privilegesLimit blast radiusNow an identity/IAM problem
Patch operating systemsRemove OS vulnerabilitiesOT devices resist patch cycles
Multi-factor authenticationStop credential reuseBroadly still essential everywhere
Regular backupsRecover from ransomwareMust now cover SaaS data too

If you are still building your evidence base for these, our walkthrough of Maturity Level Two evidence is the most efficient place to start.

The timeline: what we know, and what is speculation

There is no published, dated deprecation schedule for the Essential Eight as of July 2026. Any ‘Essential Eight deprecation 2026’ date you see quoted should be treated with caution unless it links to an ASD source. What is reasonable to expect, based on how the ASD has handled prior guidance changes:

Our advice: assign someone to monitor cyber.gov.au for the release, and do not pause current Essential Eight work in anticipation of it.

How to prepare now without betting on unpublished detail

The strongest position going into any framework change is a well-organised, evidence-backed control environment — because good evidence is portable across frameworks. Practical steps that pay off regardless of the final shape of the Essentials series:

Keep executing ML1–ML3

Maintain and improve your current maturity. A control with real evidence behind it re-maps cleanly to whatever succeeds it.

Extend your inventory to cloud and OT

Start documenting SaaS, cloud workloads and any OT you run now. If the successor guidance formalises these, you will already have the asset picture.

Organise evidence, not screenshots

Store dated, verifiable evidence per control. This is the work that survives a framework rename — and where a false green (a control marked done with nothing behind it) hurts most.

Watch, don’t pre-build

Resist implementing speculative ‘AI controls’ against headings that do not yet exist. Prepare the capability; wait for the published requirement.

This is where CyberSentien is designed to help. We assess readiness and organise the underlying evidence for the Essential Eight today — and because our approach is evidence-led rather than checkbox-led, controls without supporting evidence read ‘manual assessment required’ rather than a misleading green. When the Essentials series is published, a clean evidence base is what makes re-mapping cheap. We provide readiness and evidence assessment; we do not certify, and no software substitutes for accredited assessment where a scheme requires it.

Try it on sample docs

What this means for small and mid-sized businesses

For most Australian SMBs, the practical takeaway is reassuring. The fundamentals the ASD has long recommended — MFA everywhere, tested backups, timely patching, least-privilege access — are exactly the controls expected to carry forward. If you are a smaller organisation weighing where to spend limited security effort, the answer does not change because a successor framework is being discussed: get the basics evidenced and repeatable. Our small-business guidance walks through doing that proportionately. Businesses also juggling a tiered small-business cyber certification should note that the same underlying evidence — MFA logs, backup records, patch reports — supports multiple frameworks at once, which is the whole point of building the evidence base rather than the checklist. When accredited certification against a small-business certification scheme is required, that certificate is issued by an accredited provider, not by CyberSentien; our role is to prepare the readiness and evidence behind it.

Frequently asked

Is the Essential Eight being retired?

ASD has signalled it will deprecate the Essential Eight over roughly 12 months and retire it over about 24 months, replacing it with a broader 'Essentials' series.

What is the ASD Essentials series?

A proposed successor framework expanding beyond the eight mitigation strategies to cover cloud, operational technology (OT) and agentic AI.

What should businesses do now?

Keep meeting the Essential Eight — it remains the current baseline — while watching the consultation. CyberSentien maps frameworks and AI governance, so evidence carries into the new series.

When will the change take effect?

ASD announced the direction in mid-2026; deprecation and retirement are staged over the following roughly two years, subject to consultation.