The Australian Signals Directorate consulted on a proposed evolution of the Essential Eight during June and July 2026. That consultation has closed. The proposed Essentials framework has not been finalised, and the existing Essential Eight remains current ASD guidance.
ASD's consultation announcement said feedback on the proposed Essentials for enterprise IT guidance would run until 12 July 2026 and help shape the future series. As at 9 August 2026, ASD has not published final Essentials guidance on cyber.gov.au or announced that the Essential Eight has been withdrawn.
Status as at 9 August 2026
| Area | Current position |
|---|---|
| Consultation | Closed on 12 July 2026. |
| Essential Eight | Still published by ASD as a recommended baseline, with the existing maturity model and assessment guidance remaining available. |
| Essentials | A proposed broader series. No final public guidance or formal replacement date has been announced. |
What the Existing Essential Eight Is
The Essential Eight is ASD's recommended baseline of eight mitigation strategies. Its maturity model supports graduated implementation from Maturity Level Zero to Maturity Level Three.
ASD says the Essential Eight was designed for organisations' internet-connected information technology networks. Its principles may help in other environments, but ASD notes that it was not designed specifically for enterprise mobility or operational technology.
It remains useful because the eight strategies work as a package: patching, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening and regular backups. Organisations should still select a target maturity level suited to their risk and implement the latest published requirements.
What ASD Proposed
ASD proposed an Essentials series that would expand the current framework and give organisations more flexibility in how they implement cyber security. The first proposed chapter is Essentials for enterprise IT, with further chapters intended for other technology environments.
According to ASD's consultation announcement, the proposed guidance would be:
- Grounded in the Information Security Manual. The proposal connects the Essentials series to ASD's broader control framework.
- Prioritised and threat-informed. ASD described mitigations intended for contemporary technology environments.
- Supported by practical material. ASD proposed practical tools and clear implementation guidance.
- Aligned with existing investment. ASD said organisations already using the Essential Eight could expect strong alignment with their current controls and investments.
Those points describe ASD's proposal, not a final framework. Consultation feedback was expressly intended to shape the future development of the series.
Has the Essential Eight Been Replaced?
No. Not as at 9 August 2026.
ASD described the work as a proposed evolution of the Essential Eight. It has not yet published a final Essentials for enterprise IT framework, a commencement date or transition arrangements. The current Essential Eight Maturity Model and assessment material remain available as ASD guidance.
It is therefore premature to state that the Essential Eight has been replaced. It is more accurate to say that ASD has consulted on a broader successor series and is considering feedback.
What Has Formally Changed?
The only formal change since this article was first published is the consultation status. Submissions closed on 12 July 2026.
No public ASD announcement has yet changed the eight mitigation strategies, the maturity levels, the assessment process or an organisation's existing contractual, regulatory or government policy requirements. Any requirement tied to the Essential Eight continues to depend on the wording of the relevant policy, contract or regulator.
What Remains Proposed?
- The name and structure of the broader Essentials series.
- Essentials for enterprise IT as the first chapter.
- Additional chapters for other technology environments.
- The final mitigations, implementation guidance, tools and transition arrangements.
ASD may retain, revise or stage elements after considering consultation feedback. Organisations should wait for a formal ASD publication before treating any proposed requirement as final.
What Should You Do Now?
- Continue current Essential Eight work. Do not pause an implementation, uplift or assessment because a successor framework has been proposed. Use ASD's current maturity model and assessment process.
- Keep requirements traceable. Record whether your target maturity level comes from internal risk decisions, a contract, a regulator or government policy. This will make any future transition easier to manage.
- Maintain evidence and ISM mappings. ASD already publishes an Essential Eight and ISM mapping. Good control evidence should remain useful even if the presentation of the framework changes.
- Do not limit modern environments to eight controls. For Microsoft 365, Azure, SaaS and hybrid estates, apply the Essential Eight where relevant and use additional ASD, ISM, vendor-hardening and architecture guidance to cover the wider environment.
- Monitor official ASD publications. Review the final guidance, implementation tools and transition arrangements when ASD releases them. Avoid redesigning policy or assurance programs around consultation material alone.
Practical Implications for Security Programs
The proposed direction recognises a familiar implementation problem. Many Australian organisations use cloud services, SaaS platforms, mobile devices and hybrid identity systems that extend beyond the original design scope of the Essential Eight.
That does not make the Essential Eight obsolete. It means security teams should treat it as a prioritised baseline within a broader risk and control program. An Essential Eight assessment and uplift can establish the technical baseline. Governance, risk and compliance support can connect that baseline to policy, risk and assurance obligations.
For cloud-heavy environments, a focused Microsoft 365 and Azure security review can test identity, configuration and platform controls that do not fit neatly within a narrow maturity score. Organisations that need to brief executives or plan a transition can use independent vCISO and cyber security advisory support.
Official ASD References
Current advice: keep implementing and assessing against ASD's published Essential Eight guidance. Treat the Essentials series as proposed until ASD releases final material. If you need to understand the effect on your roadmap or assurance obligations, speak with RTCS.