Essential EightOctober 20269 min read

Essential Eight to Essentials: What ASD Is Changing and What Melbourne Businesses Should Do Now (2026)

In June 2026 the Australian Signals Directorate (ASD) announced plans to evolve the Essential Eight into a broader “Essentials” series. The Essential Eight is not being switched off: the November 2023 maturity model is still the standard for assessments, tenders and cyber insurance. Here’s what has been confirmed, what is still speculation, and why Melbourne businesses should keep their security work moving.

MS
Melbit Services
Melbourne Managed IT & Cybersecurity · Essential Eight Assessors
Nov 2023
Current maturity model, still in force
15 Jun 2026
ASD opens consultation on “Essentials”
~2 yrs
Signalled transition period (indicative)
ML2
Sensible target for most Melbourne SMBs

What ASD Actually Announced

On 15 June 2026, ASD’s Australian Cyber Security Centre (ACSC) published a consultation notice proposing that the Essential Eight evolve into a new Essentials series. The aim, in ASD’s words, is to give organisations “greater flexibility” in how they implement cyber security while keeping a clear path to strong cyber resilience, and to make sure the guidance keeps pace with emerging threats and advances in defensive technology.

The key points from the announcement:

📚
A series, not a single list

Rather than one list of eight strategies, ASD plans a set of chapters, each covering a different type of technology environment. The guidance will be grounded in the Information Security Manual (ISM), the detailed rulebook ASD already publishes for government.

💻
Chapter one: “Essentials for enterprise IT”

The evolved Essential Eight becomes the first chapter. It covers the environment most businesses actually run: Windows computers, Microsoft 365, servers and business applications. Industry commentary expects later chapters to cover operational technology and cloud, and possibly AI agents, but ASD hasn’t named them yet.

📅
Consultation closed on 12 July 2026

ASD consulted government, industry, regulators and current Essential Eight users. As of early October 2026, no draft or final version of Essentials for enterprise IT has been published.

ASD has also said that organisations already using the Essential Eight should see “strong alignment” between the new guidance and the controls they have already invested in. That is the most important line in the announcement for business owners.

Confirmed vs Speculation

Since the announcement, plenty of articles have published firm-sounding retirement dates. Most of these come from conference talks and interviews, not from ASD itself. Here’s where things actually stand:

ClaimStatus
ASD is developing an “Essentials” series to succeed the Essential EightConfirmed by ASD
The first chapter is “Essentials for enterprise IT”Confirmed by ASD
The November 2023 Essential Eight maturity model still applies todayConfirmed — nothing has replaced it
Existing Essential Eight controls will carry forwardStrongly signalled by ASD
Roughly a two-year transition, with both frameworks running side by sideIndicated by ACSC officials, not yet published
A specific retirement date for the Essential EightNot announced
The final control list, maturity levels and assessment methodNot published

What Still Applies Today

Until ASD publishes something new, the November 2023 Essential Eight Maturity Model is the benchmark. Assessments, government tenders, contracts and cyber insurance questionnaires all point to it. A quick refresher on how it works:

  • There are four maturity levels: Maturity Level Zero (not aligned) through to Maturity Level Three.
  • You only reach a level when all eight strategies meet it. Strong backups don’t make up for missing MFA.
  • For most Melbourne businesses outside government, Maturity Level Two is the sensible target. If you aren’t at Level One yet, start there.

The November 2023 update also brought in three changes that many small businesses still haven’t caught up with. If your last review was before 2024, it probably missed these:

🔑
Phishing-resistant MFA is now a Level Two expectation

SMS codes and “approve this sign-in” push notifications can be phished or bypassed. Phishing-resistant methods like passkeys, FIDO2 security keys and Windows Hello for Business are now expected at Level Two, not just Level Three. This is the most common gap we find in Microsoft 365 environments.

⏱
48-hour patching for exposed systems under active attack

Internet-facing systems such as firewalls, VPNs and remote access gateways need patching within 48 hours when a vulnerability is rated critical by the vendor or a working exploit exists. A monthly patch window is no longer enough for these devices.

🛡
The stricter hardening guidance wins

Where ASD’s hardening guidance and a vendor’s (for example, Microsoft’s) disagree, the more restrictive setting applies. “We used the vendor defaults” is no longer a complete answer.

Why You Shouldn’t Pause Your Essential Eight Work

Some businesses are treating the announcement as a reason to wait until the new framework lands. We think that’s a mistake, for four reasons:

01

The controls aren’t going anywhere

Patching, MFA, application control, restricting admin rights, macro settings, application hardening and tested backups still stop the attacks that hit Australian businesses every day. ASD has said existing investments will align with the new series. Whatever the new chapter is called, these controls will be in it.

02

Attackers don’t wait for frameworks

Ransomware crews and email fraudsters aren’t waiting for ASD’s publication schedule. A year spent waiting is a year with known gaps left open.

03

Insurers and clients are asking now

Cyber insurance renewals, enterprise supplier questionnaires and government tenders still ask about Essential Eight maturity today. “We’re waiting for Essentials” is not an answer an underwriter will accept.

04

Stalled programs lose budget

Security uplift that gets paused tends to lose its budget, its momentum and the staff who understood it. Restarting in 12 months will cost more than continuing now.

Check Your Contracts, Tenders and Insurance Forms

This is the part of the change most businesses haven’t thought about. Many contracts, panel agreements and insurance policies name the Essential Eight directly, for example “the supplier must maintain Essential Eight Maturity Level Two”. Once ASD deprecates the Essential Eight, wording like that can become unclear: does it still bind you? Does it automatically mean the new Essentials chapter?

📝
A simple fix at renewal timeWhen contracts or policies come up for renewal, ask whether the security clause should refer to “ASD’s current guidance for enterprise IT (currently the Essential Eight)” rather than naming one framework permanently. We’re not lawyers, so get your solicitor or broker to confirm the wording. Flagging it early avoids an awkward dispute later.

If you’re a supplier to government or a larger enterprise, keep an eye on your clients’ requirements too. They will likely update their supplier questionnaires once ASD publishes the new chapter.

What to Do Now: A Practical Plan

Here’s the approach we’re recommending to Melbourne clients while ASD finalises the new framework:

1
Get an honest assessment against the current model: the November 2023 version, not an older checklist. Know which maturity level you’re genuinely at across all eight strategies.
2
Close the November 2023 gaps first: move to phishing-resistant MFA, set up a 48-hour patch process for your firewall and remote access, and check your hardening settings against ASD’s guidance.
3
Remove standing admin rights: nobody should browse the web or read email with an administrator account. In Microsoft 365, tools like Privileged Identity Management and Windows LAPS make this practical.
4
Prove your backups work: a backup you’ve never restored from is a hope, not a control. Schedule and document a test restore.
5
Make someone responsible for watching ASD: your IT provider or an internal owner should track the Essentials publication and tell you what (if anything) needs to change when the draft lands.

We’ll update this article when ASD publishes the draft of Essentials for enterprise IT. For the detail on each of the current eight strategies, see our Essential Eight compliance checklist. If Microsoft 365 is at the centre of your business, our Microsoft 365 security checklist covers the settings that matter most.

Frequently Asked Questions

Is the Essential Eight being replaced?

Not yet. In June 2026 ASD opened consultation on evolving the Essential Eight into a broader Essentials series, starting with a chapter called Essentials for enterprise IT. Until ASD publishes and adopts the new guidance, the November 2023 Essential Eight Maturity Model remains the standard that assessments, tenders and cyber insurers use.

When will the Essential Eight be retired?

ASD has not published a retirement date. ACSC officials have indicated a transition of around two years, with both frameworks likely running side by side, but this is an indicative expectation rather than an official schedule. Treat any specific date you see quoted with caution.

Should my business pause its Essential Eight project until the new framework is released?

No. ASD has said existing Essential Eight investments should align strongly with the new Essentials series. Controls like patching, MFA, application control, restricting admin rights and tested backups will remain relevant, and insurers and clients are still asking about Essential Eight maturity today.

What changed in the November 2023 Essential Eight update?

Three notable changes: phishing-resistant MFA is now expected at Maturity Level Two rather than only Level Three; internet-facing services must be patched within 48 hours when a vulnerability is critical or a working exploit exists; and where ASD and vendor hardening guidance differ, the more restrictive setting applies.

What maturity level should a Melbourne small business aim for?

For most Melbourne businesses outside government, Maturity Level Two is the sensible target. If you have not yet reached Maturity Level One across all eight strategies, start there. Businesses handling sensitive health, financial or legal information should prioritise reaching Level Two.

At Melbits, our team includes Essential Eight assessors trained through Victoria University. We help Melbourne businesses work out where they stand today and build a plan that will hold up under the new framework. Contact us to book an assessment.

Supporting Melbourne Businesses Since 2007

Ready to Simplify Your IT?

Join 200+ Melbourne businesses who've upgraded their IT experience with Melbits. Book a free consultation and get a clear picture of where your technology stands — no jargon, no pressure.

100% Australian Support
No Lock-In Contracts
Fast Response Guaranteed
Call Us