Compliance July 20, 2026

The Essential Eight is being retired

If your roadmap has a line item that reads “get to Maturity Level 2,” read the fine print on what ASD announced in June. The Essential Eight isn’t being tweaked. It’s being retired.

KM

Kyle Murray

Vanguard Cyber

The Essential Eight is being retired

Your controls aren’t becoming obsolete. What may not survive the move to an outcomes-based framework is your evidence and your framing.

Nothing changes today, and that’s the trap

The Essential Eight is still the in-force framework. It’s still what tenders, contracts, and regulators reference, and ASD has confirmed it stays a live, supported document through the transition. On ASD’s stated timeline, deprecation begins at around 12 months and full retirement at around 24.

So no, you don’t stop what you’re doing. Your application control rollout, your move to phishing-resistant MFA, your patch cadence. None of it is wasted, and ASD has said existing tools and platforms will largely map into the new model.

The trap is subtler than “our controls are now obsolete,” because they aren’t. What may not transfer is your evidence and your framing. Picture two organisations that both hit ML2. One recorded each control as a tick against a named product. The other recorded the risk each control addressed and the outcome it was meant to produce. When the Essentials series lands, the first has a pile of tool names to re-map. The second already speaks the new language, because outcomes are what the new model is built on.

What the Essentials series actually is

ASD has been unusually candid about why. The Essential Eight was published in 2017, when a Windows fleet behind a firewall was a fair picture of “the environment.” That model creaks in 2026, against faster-moving threats (AI-enabled ones included) and against organisations whose real attack surface is spread across SaaS, cloud, and identity providers the original eight barely name.

Four things change in the replacement.

It’s outcome-based rather than product-based. The guidance states the security result you need and leaves the how to you. It’s threat-informed and prioritised, framed as mitigations ranked by what actually reduces risk rather than a fixed ladder of maturity levels. It’s split into domain chapters, with Enterprise IT first and operational technology and cloud following as their own chapters. And it’s architecture-led, drawing on ASD’s Modern Defensible Architecture work, with the emphasis on defence in depth and protecting your crown jewels rather than a hard shell around a soft centre.

The cloud split is the one to watch. Most Essential Eight programs quietly under-cover cloud and SaaS, because the original strategies were written for systems you controlled end to end. Pulling cloud into its own chapter forces the question every practitioner already knows is unanswered. Where does your responsibility stop and your provider’s start? ASD has also floated a future chapter on agentic AI, citing the identity and prompt-injection problems that come with non-person accounts acting on your network.

If you’ve read the Modern Defensible Architecture Foundations, none of this is a surprise. Zero trust, assume-breach, secure-by-design, layered over the ISM rather than bolted on beside it.

Mandated baselines don’t move when the guidance does

Here’s the mistake that will catch people. They assume the obligations move on ASD’s timeline. They don’t.

Essential Eight Maturity Level 2 is written into the Protective Security Policy Framework and is the baseline for Defence Industry Security Program membership. Those references point at the Essential Eight as it stands today. ASD retiring the framework doesn’t rewrite a contract clause, a PSPF requirement, the testing expectations in a SOCI risk management program, or an APRA prudential standard. Each of those changes only when its own owner decides to change it.

For a government agency, a critical infrastructure operator, a defence supplier, or an APRA-regulated entity, that’s the real calendar. Not ASD’s 24-month horizon, but the date each regulator or contract you’re bound by swaps its reference from the Essential Eight to the Essentials series. Those dates will land at different times, and tracking them is now part of the job.

What to do next

Five things to do, ranked by impact with the lowest effort first.

  1. Record the “why” behind every control, not just the “what.” A risk and an intended outcome per control, not a tool name and a maturity tick. Outcome-based records port straight into the Essentials model. Checklist evidence doesn’t.
  2. Map your cloud and SaaS shared responsibilities now. This is the gap the cloud chapter will expose, and it’s real work. Start before the chapter lands, not after.
  3. Keep executing your current Essential Eight uplift. It’s still the in-force baseline and the reference in live contracts. A higher maturity level now is the best possible position from which to adopt the new guidance, so don’t pause remediation to wait for it.
  4. List every obligation that cites the Essential Eight and give each one an owner. Contracts, the PSPF, your sector regulator, your cyber insurer. Someone tracks each reference for the day it transitions. Your real deadline lives in that list.
  5. If you’re an ASD partner, read the consultation material and feed the direction into your next roadmap review rather than this sprint.

There’s a dividing line running through all of this. Organisations that already treat controls as a governed, risk-based system will experience the Essentials series as an evolution. Organisations that have treated the Essential Eight as a checklist to satisfy will experience it as a rebuild. The next two years are the window to move from the second group to the first.

Talk to us about
your next assessment

Whether you are scoping a test, preparing for an audit, or building a roadmap, we keep the conversation clear, proportionate, and focused on what your teams and stakeholders need.