The Australian Signals Directorate publishes a new release of the Information Security Manual every quarter. The June 2026 release is a clean point-release: roughly 20 new controls added, none removed, with a clear editorial theme of strengthening cyber-threat-intelligence expectations. It is already live inside the CyberSentien engine as versioned catalogue v2026.06.18, carrying 1,150 controls. This page explains what the release means in practice, how to run a delta review against it, and why any assessment pinned to the March 2026 ISM is now quietly out of date.
An ISM assessment is a snapshot. Whether it is an IRAP assessment, an internal security review or a self-assessment for a supplier questionnaire, the document you produce is written against one specific ISM version. The moment ASD publishes the next quarterly release, every statement of applicability written against the old version is out of date, and nothing tells you. There is no notification pipeline from cyber.gov.au into your compliance register. The staleness is silent.
Your assessment does not degrade visibly. It says the same thing it said in March. What changed is the yardstick, and the gap only surfaces when someone checks the current ISM against your pinned version.
New controls change the denominator. If your coverage number was calculated against the March catalogue, the same evidence now covers a smaller fraction of the current ISM. A percentage that has not moved can still be wrong.
The worst place to discover a quarterly delta is inside an assessment engagement, when an assessor working from the current release asks about controls your team has never seen. A routine delta review each quarter costs hours. Discovering the gap mid-engagement costs weeks.
Four releases a year means four of these silent breakpoints. Most organisations handle one or two well and let the others slide, which is how an "assessed against the ISM" claim gradually stops being true without anyone deciding to let it lapse.
At the level we can verify from the release itself, the June 2026 update is about as friendly as an ISM release gets:
| Release fact | June 2026 |
|---|---|
| In-engine catalogue version | v2026.06.18 |
| Controls in catalogue | 1,150 |
| Controls added | Roughly 20 |
| Controls removed | None |
| Character of the release | Clean, additive point-release |
The headline theme of the release is a strengthening of cyber-threat-intelligence expectations. If your organisation consumes, produces or shares threat intelligence, the new controls are worth reading closely, because they raise the bar on what "having a CTI capability" means in ISM terms.
We are deliberately not listing individual control identifiers or paraphrasing per-control wording here. The authoritative, control-by-control list is ASD's own changes document, published alongside each release on the ISM page at cyber.gov.au. Read that document for the letter of each control; use this page for what the release means operationally.
ASD publishes the ISM in machine-readable OSCAL form alongside the human-readable editions. In OSCAL terms, each quarterly release is a new versioned catalogue document. That framing matters, because it tells you precisely what can and cannot have broken in your own artefacts:
A clean point-release adds new control entries to the catalogue and revises text where needed. Nothing you previously referenced has been withdrawn, so this quarter there are no dangling references to chase.
Because no controls were removed in June 2026, references in your system security plan, statement of applicability and evidence mappings against existing controls remain resolvable. Your prior work is not invalidated, it is incomplete.
The catalogue now holds 1,150 controls. Applicability has to be decided for each addition. "Not applicable" is a legitimate answer, but it is a decision that has to be made and recorded, not a default you get for free by ignoring the release.
The practical upshot: a clean point-release is the cheapest kind of quarterly update to absorb, provided you actually absorb it. The whole job reduces to triaging the additions. Releases that remove or restructure controls are far more expensive, which is another reason to stay current release by release rather than batching several quarters into one painful catch-up.
Here is the delta-review process we would run as assessors, and the one the engine automates. It works whether you are an agency security team, a consultancy running assessments for clients, or an internal risk function keeping a register honest.
For a clean additive release of roughly 20 controls, this is a bounded piece of work. The trap is not the size of the job, it is nobody being tasked with starting it.
The CyberSentien engine materialises every ISM point-release as a versioned catalogue. The June 2026 release is live in-engine now as v2026.06.18 with its 1,150 controls, sitting alongside the prior versions rather than overwriting them. That version-pinned design is what makes re-assessment mechanical instead of archaeological:
Because both the old and new catalogues exist in the engine as first-class versions, the difference between them is a computed fact, not a research task. You see exactly which controls are new against your pinned baseline.
Re-assessing against the new catalogue carries your existing responses and evidence forward where controls are unchanged, and surfaces the additions as open items. You answer what is genuinely new. You do not re-key a year of work.
Every assessment and report in the engine states the catalogue version it was run against. When someone asks "assessed against which ISM?", the answer is on the document, not in someone's memory.
And a standing commitment: we publish this changes analysis for every ISM release, because the engine ingests every release. When ASD ships the next quarterly update, there will be a page like this one for it, and a versioned catalogue behind it. That is only possible because keeping the catalogue current is an engineering process here, not a quarterly scramble.
The ISM is one of several Australian frameworks the engine covers; see the ISM framework page for the full picture, the platform overview for how assessment, evidence and reporting fit together, and our sovereignty page for where your data lives while you do it. Pricing is on the pricing page, with no surprises.
See the June 2026 catalogue on the live demo Talk to us about a delta review
No. Based on the release as materialised in-engine, roughly 20 controls were added and none were removed, making it a clean, additive point-release. For the authoritative control-by-control list, use ASD's changes document on the ISM page at cyber.gov.au.
The headline change is strengthened expectations around cyber threat intelligence. If your environment consumes, produces or shares CTI, prioritise those additions in your delta review. As always, read ASD's own wording rather than relying on any summary.
Not formally, but it dates it. Your assessment remains a true statement about your posture against the version it names. What it stops being is a statement about the current ISM. A delta review closes that gap; how often you commission a full re-assessment is a risk decision for you, your assessor and your executive, and nothing on this page is advice on that question.
A release that adds controls and revises text without removing or renumbering anything you might already reference. In OSCAL terms it is a new versioned catalogue with a purely additive control delta, so existing references in your SSP and statement of applicability keep resolving. The work it creates is triage of the additions, nothing more.
Yes. It is live in-engine as versioned catalogue v2026.06.18 with 1,150 controls, alongside the prior releases. Existing assessments stay pinned to their original version until you choose to re-assess, and the engine shows you the delta before you commit.
ASD publishes a changes document with each ISM release on the ISM page at cyber.gov.au. That document is the authoritative record; treat every third-party summary, including this one, as a map rather than the territory.
Every capability referenced on this page is live on the CyberSentien engine — see it on the always-live gated demo. Nothing on this page is legal advice.