ISM June 2026: what moved, and who it affects

The Australian Signals Directorate publishes a new release of the Information Security Manual every quarter. The June 2026 release is a clean point-release: roughly 20 new controls added, none removed, with a clear editorial theme of strengthening cyber-threat-intelligence expectations. It is already live inside the CyberSentien engine as versioned catalogue v2026.06.18, carrying 1,150 controls. This page explains what the release means in practice, how to run a delta review against it, and why any assessment pinned to the March 2026 ISM is now quietly out of date.

Why quarterly ISM releases hurt

An ISM assessment is a snapshot. Whether it is an IRAP assessment, an internal security review or a self-assessment for a supplier questionnaire, the document you produce is written against one specific ISM version. The moment ASD publishes the next quarterly release, every statement of applicability written against the old version is out of date, and nothing tells you. There is no notification pipeline from cyber.gov.au into your compliance register. The staleness is silent.

Silent staleness

Your assessment does not degrade visibly. It says the same thing it said in March. What changed is the yardstick, and the gap only surfaces when someone checks the current ISM against your pinned version.

Scope drift

New controls change the denominator. If your coverage number was calculated against the March catalogue, the same evidence now covers a smaller fraction of the current ISM. A percentage that has not moved can still be wrong.

Audit-time surprises

The worst place to discover a quarterly delta is inside an assessment engagement, when an assessor working from the current release asks about controls your team has never seen. A routine delta review each quarter costs hours. Discovering the gap mid-engagement costs weeks.

Four releases a year means four of these silent breakpoints. Most organisations handle one or two well and let the others slide, which is how an "assessed against the ISM" claim gradually stops being true without anyone deciding to let it lapse.

What actually moved in June 2026

At the level we can verify from the release itself, the June 2026 update is about as friendly as an ISM release gets:

Release factJune 2026
In-engine catalogue versionv2026.06.18
Controls in catalogue1,150
Controls addedRoughly 20
Controls removedNone
Character of the releaseClean, additive point-release

The headline theme of the release is a strengthening of cyber-threat-intelligence expectations. If your organisation consumes, produces or shares threat intelligence, the new controls are worth reading closely, because they raise the bar on what "having a CTI capability" means in ISM terms.

We are deliberately not listing individual control identifiers or paraphrasing per-control wording here. The authoritative, control-by-control list is ASD's own changes document, published alongside each release on the ISM page at cyber.gov.au. Read that document for the letter of each control; use this page for what the release means operationally.

What a point-release means in OSCAL terms

ASD publishes the ISM in machine-readable OSCAL form alongside the human-readable editions. In OSCAL terms, each quarterly release is a new versioned catalogue document. That framing matters, because it tells you precisely what can and cannot have broken in your own artefacts:

Additive delta

A clean point-release adds new control entries to the catalogue and revises text where needed. Nothing you previously referenced has been withdrawn, so this quarter there are no dangling references to chase.

Stable references

Because no controls were removed in June 2026, references in your system security plan, statement of applicability and evidence mappings against existing controls remain resolvable. Your prior work is not invalidated, it is incomplete.

A bigger denominator

The catalogue now holds 1,150 controls. Applicability has to be decided for each addition. "Not applicable" is a legitimate answer, but it is a decision that has to be made and recorded, not a default you get for free by ignoring the release.

The practical upshot: a clean point-release is the cheapest kind of quarterly update to absorb, provided you actually absorb it. The whole job reduces to triaging the additions. Releases that remove or restructure controls are far more expensive, which is another reason to stay current release by release rather than batching several quarters into one painful catch-up.

How to run a delta review: a working method

Here is the delta-review process we would run as assessors, and the one the engine automates. It works whether you are an agency security team, a consultancy running assessments for clients, or an internal risk function keeping a register honest.

  1. Pin your baseline. Write down exactly which ISM version your last assessment used. If your assessment documents do not state a version, that is your first finding, against your own process.
  2. Get the authoritative delta. Download ASD's changes document for the June 2026 release from the ISM page. Work from that list, not from a summary, ours included.
  3. Triage additions for applicability. Run each new control through the same applicability logic you used originally: system classification, system type, whether the subject matter (this quarter, notably cyber threat intelligence) is in scope for the environment at all.
  4. Map to evidence you already hold. Some new controls will already be satisfied by practices you implemented for other reasons. Record that mapping explicitly, with the evidence attached, rather than treating every addition as a fresh gap.
  5. Raise the genuine gaps as findings. Each unmet applicable control gets an owner, a target date and a place in your existing remediation process. A delta review that ends in a spreadsheet nobody owns has not finished.
  6. Re-issue against the new version. Update the statement of applicability so it names the June 2026 release, and make the version visible wherever the assessment is cited. The point of the exercise is that the next person to read your posture knows which yardstick it was measured against.

For a clean additive release of roughly 20 controls, this is a bounded piece of work. The trap is not the size of the job, it is nobody being tasked with starting it.

How this works inside CyberSentien

The CyberSentien engine materialises every ISM point-release as a versioned catalogue. The June 2026 release is live in-engine now as v2026.06.18 with its 1,150 controls, sitting alongside the prior versions rather than overwriting them. That version-pinned design is what makes re-assessment mechanical instead of archaeological:

Explicit deltas, not silent drift

Because both the old and new catalogues exist in the engine as first-class versions, the difference between them is a computed fact, not a research task. You see exactly which controls are new against your pinned baseline.

Carry-forward re-assessment

Re-assessing against the new catalogue carries your existing responses and evidence forward where controls are unchanged, and surfaces the additions as open items. You answer what is genuinely new. You do not re-key a year of work.

Version on the record

Every assessment and report in the engine states the catalogue version it was run against. When someone asks "assessed against which ISM?", the answer is on the document, not in someone's memory.

And a standing commitment: we publish this changes analysis for every ISM release, because the engine ingests every release. When ASD ships the next quarterly update, there will be a page like this one for it, and a versioned catalogue behind it. That is only possible because keeping the catalogue current is an engineering process here, not a quarterly scramble.

The ISM is one of several Australian frameworks the engine covers; see the ISM framework page for the full picture, the platform overview for how assessment, evidence and reporting fit together, and our sovereignty page for where your data lives while you do it. Pricing is on the pricing page, with no surprises.

See the June 2026 catalogue on the live demo Talk to us about a delta review

Frequently asked questions

Did the June 2026 ISM release remove any controls?

No. Based on the release as materialised in-engine, roughly 20 controls were added and none were removed, making it a clean, additive point-release. For the authoritative control-by-control list, use ASD's changes document on the ISM page at cyber.gov.au.

What is the main theme of the June 2026 release?

The headline change is strengthened expectations around cyber threat intelligence. If your environment consumes, produces or shares CTI, prioritise those additions in your delta review. As always, read ASD's own wording rather than relying on any summary.

Does a new ISM release invalidate my existing assessment?

Not formally, but it dates it. Your assessment remains a true statement about your posture against the version it names. What it stops being is a statement about the current ISM. A delta review closes that gap; how often you commission a full re-assessment is a risk decision for you, your assessor and your executive, and nothing on this page is advice on that question.

What does "clean point-release" actually mean?

A release that adds controls and revises text without removing or renumbering anything you might already reference. In OSCAL terms it is a new versioned catalogue with a purely additive control delta, so existing references in your SSP and statement of applicability keep resolving. The work it creates is triage of the additions, nothing more.

Is the June 2026 release available in CyberSentien now?

Yes. It is live in-engine as versioned catalogue v2026.06.18 with 1,150 controls, alongside the prior releases. Existing assessments stay pinned to their original version until you choose to re-assess, and the engine shows you the delta before you commit.

Where do I find the official list of changes?

ASD publishes a changes document with each ISM release on the ISM page at cyber.gov.au. That document is the authoritative record; treat every third-party summary, including this one, as a map rather than the territory.

Every capability referenced on this page is live on the CyberSentien engine — see it on the always-live gated demo. Nothing on this page is legal advice.