What ASD Actually Announced
On 15 June 2026, ASD’s Australian Cyber Security Centre (ACSC) published a consultation notice proposing that the Essential Eight evolve into a new Essentials series. The aim, in ASD’s words, is to give organisations “greater flexibility” in how they implement cyber security while keeping a clear path to strong cyber resilience, and to make sure the guidance keeps pace with emerging threats and advances in defensive technology.
The key points from the announcement:
Rather than one list of eight strategies, ASD plans a set of chapters, each covering a different type of technology environment. The guidance will be grounded in the Information Security Manual (ISM), the detailed rulebook ASD already publishes for government.
The evolved Essential Eight becomes the first chapter. It covers the environment most businesses actually run: Windows computers, Microsoft 365, servers and business applications. Industry commentary expects later chapters to cover operational technology and cloud, and possibly AI agents, but ASD hasn’t named them yet.
ASD consulted government, industry, regulators and current Essential Eight users. As of early October 2026, no draft or final version of Essentials for enterprise IT has been published.
ASD has also said that organisations already using the Essential Eight should see “strong alignment” between the new guidance and the controls they have already invested in. That is the most important line in the announcement for business owners.
Confirmed vs Speculation
Since the announcement, plenty of articles have published firm-sounding retirement dates. Most of these come from conference talks and interviews, not from ASD itself. Here’s where things actually stand:
What Still Applies Today
Until ASD publishes something new, the November 2023 Essential Eight Maturity Model is the benchmark. Assessments, government tenders, contracts and cyber insurance questionnaires all point to it. A quick refresher on how it works:
- There are four maturity levels: Maturity Level Zero (not aligned) through to Maturity Level Three.
- You only reach a level when all eight strategies meet it. Strong backups don’t make up for missing MFA.
- For most Melbourne businesses outside government, Maturity Level Two is the sensible target. If you aren’t at Level One yet, start there.
The November 2023 update also brought in three changes that many small businesses still haven’t caught up with. If your last review was before 2024, it probably missed these:
SMS codes and “approve this sign-in” push notifications can be phished or bypassed. Phishing-resistant methods like passkeys, FIDO2 security keys and Windows Hello for Business are now expected at Level Two, not just Level Three. This is the most common gap we find in Microsoft 365 environments.
Internet-facing systems such as firewalls, VPNs and remote access gateways need patching within 48 hours when a vulnerability is rated critical by the vendor or a working exploit exists. A monthly patch window is no longer enough for these devices.
Where ASD’s hardening guidance and a vendor’s (for example, Microsoft’s) disagree, the more restrictive setting applies. “We used the vendor defaults” is no longer a complete answer.
Why You Shouldn’t Pause Your Essential Eight Work
Some businesses are treating the announcement as a reason to wait until the new framework lands. We think that’s a mistake, for four reasons:
The controls aren’t going anywhere
Patching, MFA, application control, restricting admin rights, macro settings, application hardening and tested backups still stop the attacks that hit Australian businesses every day. ASD has said existing investments will align with the new series. Whatever the new chapter is called, these controls will be in it.
Attackers don’t wait for frameworks
Ransomware crews and email fraudsters aren’t waiting for ASD’s publication schedule. A year spent waiting is a year with known gaps left open.
Insurers and clients are asking now
Cyber insurance renewals, enterprise supplier questionnaires and government tenders still ask about Essential Eight maturity today. “We’re waiting for Essentials” is not an answer an underwriter will accept.
Stalled programs lose budget
Security uplift that gets paused tends to lose its budget, its momentum and the staff who understood it. Restarting in 12 months will cost more than continuing now.
Check Your Contracts, Tenders and Insurance Forms
This is the part of the change most businesses haven’t thought about. Many contracts, panel agreements and insurance policies name the Essential Eight directly, for example “the supplier must maintain Essential Eight Maturity Level Two”. Once ASD deprecates the Essential Eight, wording like that can become unclear: does it still bind you? Does it automatically mean the new Essentials chapter?
If you’re a supplier to government or a larger enterprise, keep an eye on your clients’ requirements too. They will likely update their supplier questionnaires once ASD publishes the new chapter.
What to Do Now: A Practical Plan
Here’s the approach we’re recommending to Melbourne clients while ASD finalises the new framework:
We’ll update this article when ASD publishes the draft of Essentials for enterprise IT. For the detail on each of the current eight strategies, see our Essential Eight compliance checklist. If Microsoft 365 is at the centre of your business, our Microsoft 365 security checklist covers the settings that matter most.
Frequently Asked Questions
Is the Essential Eight being replaced?
Not yet. In June 2026 ASD opened consultation on evolving the Essential Eight into a broader Essentials series, starting with a chapter called Essentials for enterprise IT. Until ASD publishes and adopts the new guidance, the November 2023 Essential Eight Maturity Model remains the standard that assessments, tenders and cyber insurers use.
When will the Essential Eight be retired?
ASD has not published a retirement date. ACSC officials have indicated a transition of around two years, with both frameworks likely running side by side, but this is an indicative expectation rather than an official schedule. Treat any specific date you see quoted with caution.
Should my business pause its Essential Eight project until the new framework is released?
No. ASD has said existing Essential Eight investments should align strongly with the new Essentials series. Controls like patching, MFA, application control, restricting admin rights and tested backups will remain relevant, and insurers and clients are still asking about Essential Eight maturity today.
What changed in the November 2023 Essential Eight update?
Three notable changes: phishing-resistant MFA is now expected at Maturity Level Two rather than only Level Three; internet-facing services must be patched within 48 hours when a vulnerability is critical or a working exploit exists; and where ASD and vendor hardening guidance differ, the more restrictive setting applies.
What maturity level should a Melbourne small business aim for?
For most Melbourne businesses outside government, Maturity Level Two is the sensible target. If you have not yet reached Maturity Level One across all eight strategies, start there. Businesses handling sensitive health, financial or legal information should prioritise reaching Level Two.
At Melbits, our team includes Essential Eight assessors trained through Victoria University. We help Melbourne businesses work out where they stand today and build a plan that will hold up under the new framework. Contact us to book an assessment.