The Australian Signals Directorate has signalled that the Essential Eight, in its current maturity-model form, will be superseded by a broader ‘Essentials’ series — a set of guidance that commonly extends beyond on-premises Windows environments to cover cloud, operational technology and artificial intelligence. Treat the specifics as proposed and subject to consultation: no firm cut-over date has been published as of mid-2026. The eight mitigation strategies and their maturity levels remain the official baseline today, so the practical move is to keep executing ML1–ML3 while watching the ASD guidance closely.
By Aneis Samaan, founder of CyberSentien · Last updated July 2026
It is easy to read ‘Essential Eight retirement’ as a switch being flipped. That is not what the signals suggest. The Essential Eight remains the ASD’s recommended baseline of mitigation strategies, and the Maturity Model that grades them (Maturity Level One through Three) is still the reference organisations are measured against in 2026. What has been signalled is a direction of travel: the ASD has indicated it intends to broaden its prioritised-mitigation guidance into an ‘Essentials’ series that reflects how modern organisations actually operate. The current Essential Eight was designed around a Microsoft Windows internet-connected network; that assumption no longer fits most Australian businesses.
Until the ASD publishes finalised replacement guidance, the honest position is this: nothing you have built against the Essential Eight is wasted, and no organisation should stop applying application control, patching, MFA or backups because a successor is being discussed. The maturity model is not deprecated today. Anyone telling you the Essential Eight is already gone is ahead of the published record. You can follow the primary source directly at cyber.gov.au.
The Essential Eight was built for a world of managed desktops and a defined network perimeter. Three shifts have stretched that model to breaking point, and each maps to an area the successor guidance is commonly expected to address.
Controls like ‘patch operating systems’ and ‘restrict administrative privileges’ were written for machines you own. Most workloads now sit in Microsoft 365, AWS, Azure or Google Cloud, where the shared-responsibility line and identity-based access change what ‘good’ looks like.
Manufacturing, utilities, logistics and healthcare run OT and industrial control systems that frequently cannot be patched on a Windows cadence or run application control agents. These environments have been under-served by the current eight.
The rapid adoption of AI systems — both as attack surface and as a tool used inside the business — introduces risks the 2017-era mitigation set never contemplated. Governance of AI use is expected to feature in the broader guidance.
Read these as the problems the ASD is trying to solve, not as confirmed chapter headings. The scope, naming and structure of any Essentials series should be treated as proposed until the ASD releases it.
Whatever succeeds it will almost certainly build on these strategies rather than discard them, so they remain the right thing to invest in now.
| Strategy | Primary purpose | Where it is stretched today |
|---|---|---|
| Application control | Prevent unapproved code executing | Hard on OT and BYO devices |
| Patch applications | Close known vulnerabilities | SaaS patching sits with the vendor |
| Configure Office macros | Block a common delivery path | Narrowly Microsoft-specific |
| User application hardening | Reduce browser/plugin risk | Cloud-native apps differ |
| Restrict admin privileges | Limit blast radius | Now an identity/IAM problem |
| Patch operating systems | Remove OS vulnerabilities | OT devices resist patch cycles |
| Multi-factor authentication | Stop credential reuse | Broadly still essential everywhere |
| Regular backups | Recover from ransomware | Must now cover SaaS data too |
If you are still building your evidence base for these, our walkthrough of Maturity Level Two evidence is the most efficient place to start.
There is no published, dated deprecation schedule for the Essential Eight as of July 2026. Any ‘Essential Eight deprecation 2026’ date you see quoted should be treated with caution unless it links to an ASD source. What is reasonable to expect, based on how the ASD has handled prior guidance changes:
Our advice: assign someone to monitor cyber.gov.au for the release, and do not pause current Essential Eight work in anticipation of it.
The strongest position going into any framework change is a well-organised, evidence-backed control environment — because good evidence is portable across frameworks. Practical steps that pay off regardless of the final shape of the Essentials series:
Maintain and improve your current maturity. A control with real evidence behind it re-maps cleanly to whatever succeeds it.
Start documenting SaaS, cloud workloads and any OT you run now. If the successor guidance formalises these, you will already have the asset picture.
Store dated, verifiable evidence per control. This is the work that survives a framework rename — and where a false green (a control marked done with nothing behind it) hurts most.
Resist implementing speculative ‘AI controls’ against headings that do not yet exist. Prepare the capability; wait for the published requirement.
This is where CyberSentien is designed to help. We assess readiness and organise the underlying evidence for the Essential Eight today — and because our approach is evidence-led rather than checkbox-led, controls without supporting evidence read ‘manual assessment required’ rather than a misleading green. When the Essentials series is published, a clean evidence base is what makes re-mapping cheap. We provide readiness and evidence assessment; we do not certify, and no software substitutes for accredited assessment where a scheme requires it.
For most Australian SMBs, the practical takeaway is reassuring. The fundamentals the ASD has long recommended — MFA everywhere, tested backups, timely patching, least-privilege access — are exactly the controls expected to carry forward. If you are a smaller organisation weighing where to spend limited security effort, the answer does not change because a successor framework is being discussed: get the basics evidenced and repeatable. Our small-business guidance walks through doing that proportionately. Businesses also juggling a tiered small-business cyber certification should note that the same underlying evidence — MFA logs, backup records, patch reports — supports multiple frameworks at once, which is the whole point of building the evidence base rather than the checklist. When accredited certification against a small-business certification scheme is required, that certificate is issued by an accredited provider, not by CyberSentien; our role is to prepare the readiness and evidence behind it.
ASD has signalled it will deprecate the Essential Eight over roughly 12 months and retire it over about 24 months, replacing it with a broader 'Essentials' series.
A proposed successor framework expanding beyond the eight mitigation strategies to cover cloud, operational technology (OT) and agentic AI.
Keep meeting the Essential Eight — it remains the current baseline — while watching the consultation. CyberSentien maps frameworks and AI governance, so evidence carries into the new series.
ASD announced the direction in mid-2026; deprecation and retirement are staged over the following roughly two years, subject to consultation.