Essential Eight to the Essentials Series: Where Things Stand in October 2026
10 October 2026 · Compliance365
In June 2026 ASD announced that the Essential Eight will be replaced by a new framework, the Essentials series. Consultation on its first chapter closed on 12 July 2026.
As at 10 October 2026, ASD has not published the final framework or given a release date. Here is what is known, what isn't, and what to keep doing in the meantime.
What we know
- The Essential Eight is still in force. Nothing about current Essential Eight obligations, assessments or contract requirements has changed yet.
- The Essentials series is modular. It is being published as domain chapters. The first is Essentials for enterprise IT, the closest equivalent to the Essential Eight. Cloud and operational technology chapters are expected to follow.
- It is outcome-based. The chapters describe security outcomes to achieve, rather than the prescriptive technical settings of the Essential Eight.
- There is a rough timeline. The ACSC told iTnews it expects the Essential Eight to be deprecated about 12 months after the announcement and retired about 24 months after. Those are approximate periods, not published dates.
What we don’t know yet
- When the final enterprise IT chapter will be published. ASD is reviewing consultation submissions and has not given a date.
- Whether maturity levels survive. It isn’t settled whether ML1 to ML3 carry across in the same form, or how assessments will be scored.
- How contracts and panels will switch. Government and supply-chain requirements that name the Essential Eight will need to be updated, and the timing of that is not set.
Treat any article that gives a firm release date, or a mapping of maturity levels to the new framework, with caution until ASD publishes.
What to keep doing
Don’t pause your Essential Eight work. The controls behind it (patching, application control, MFA, restricting admin privileges, backups) are not going away. The outcomes in the consultation draft still need them. Work done now carries across.
- Keep going towards your target maturity level. If a contract or insurer asks for ML2 today, that is still the requirement.
- Keep your evidence. Screenshots, configuration exports and review records show the outcome as well as the setting, which is the direction the new framework is heading.
- Map, don’t rebuild. When the enterprise IT chapter is published, map your existing controls to its outcomes before changing anything.
- Watch your contracts. Note which customers, panels or insurers name the Essential Eight, so you know who to talk to when they update their requirements.
Our full guide, The Essential Eight is being retired: what you need to know, covers the transition in more detail. You can also sign up there for one email when ASD publishes the final chapter. For an assessment against the current Essential Eight, see our Essential Eight service.
Sources
- ASD, Consultation on the evolution of the Essential Eight
- iTnews, ASD to retire Essential Eight cyber security framework within next two years
- Information Age (ACS), ASD overhauls Essential Eight cybersecurity guidance
Last reviewed 10 October 2026.
Found this useful? Get the ISO/Privacy/AI readiness checklists.
Browse resources