The Australian Signals Directorate (ASD) has announced it will retire the Essential Eight cybersecurity framework within the next two years. The framework that has defined how Australian businesses approach baseline cybersecurity since 2017 is being replaced by a broader, more modern approach called the “Essentials” series, built on the principles of Modern Defensible Architecture (MDA).
If your business has been working toward Essential Eight compliance, this is not a reason to stop. It is a reason to understand where things are heading so you can plan ahead. Here is everything you need to know.
What Is the Essential Eight and Why Is It Being Retired?
The Essential Eight was introduced by the ASD’s Australian Cyber Security Centre (ACSC) in 2017 as a practical, prioritised list of mitigation strategies to help Australian organisations protect themselves against the most common cyber threats. The eight strategies cover application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups.
For nearly a decade, the Essential Eight has served as Australia’s de facto baseline for business cybersecurity. It has been mandated for Commonwealth government agencies and widely adopted by private sector organisations seeking a clear, actionable standard.
The problem is that the IT landscape has changed significantly since 2017. The Essential Eight was designed primarily for on-premises, Microsoft Windows-based network environments. It was not built for the world most Australian businesses now operate in: one dominated by cloud services, Software-as-a-Service (SaaS) platforms, hybrid work, operational technology (OT), and increasingly, artificial intelligence.
ASD has acknowledged that the Essential Eight no longer optimally fits the complexity of modern IT environments and has announced a planned transition away from it over the next two years.
What Is the Timeline?
ASD has outlined the following transition schedule starting from June 2026:
- Now to approximately June 2027: The Essential Eight remains active and organisations should continue to implement and maintain compliance. ASD has released the first chapter of the new “Essentials” series for public consultation, with feedback due by 12 July 2026.
- Approximately 12 months from June 2026: ASD plans to begin formal deprecation of the Essential Eight.
- Approximately 24 months from June 2026 (around mid-2028): The Essential Eight will be fully retired and replaced.
The consultation on the new “Essentials for Enterprise IT” chapter is open now via the ACSC Partner Portal. This is the first of several planned chapters, with subsequent releases expected to cover operational technology, cloud security, and AI.
What Replaces the Essential Eight?
The Essential Eight will be replaced by a new framework called the “Essentials” series, anchored to ASD’s Modern Defensible Architecture (MDA) principles.
The shift is significant. Where the Essential Eight provided a prescriptive list of specific controls, the new Essentials series takes an outcome-based approach. Rather than telling organisations exactly which eight things to do, it provides principles and guidance that organisations can adapt to their specific environment, technology stack, and risk profile.
The first chapter, “Essentials for Enterprise IT,” focuses on the following areas:
Centralised Identity Management
Organisations need a single, authoritative source of identity for all users and systems, rather than fragmented local accounts and siloed directories. Every access decision should be grounded in a verified, centrally managed identity.
High-Assurance Authentication
This goes beyond standard MFA to include phishing-resistant authentication methods such as hardware tokens and passkeys. Push notification-based MFA, which is vulnerable to MFA fatigue attacks, is no longer considered adequate for high-risk access.
Contextual Authorisation
Access decisions should consider not just who a person is, but the context of the access request, including device health, location, risk signals, and behaviour patterns. This is a core Zero Trust principle.
Reliable Asset Inventory
Organisations need to know exactly what devices, applications, and systems exist in their environment before they can protect them. An incomplete picture of your IT estate is one of the most common reasons breaches go undetected for extended periods.
Secure Endpoints
Endpoints must be hardened, monitored, and maintained at a known-good state, with detection capability for anomalous behaviour that goes beyond basic antivirus.
Reduced Attack Surface
Eliminating unnecessary services, ports, and applications to minimise the number of ways an attacker can gain entry. Every unused service is a potential open door.
Resilient Networks
Networks should be designed to limit lateral movement, with segmentation that contains a breach rather than allowing it to spread freely through the environment.
Secure-by-Design Software
Organisations should prioritise software vendors and cloud services that build security in from the ground up, rather than applying it as an afterthought.
Comprehensive Assurance and Governance
Security should be measurable, auditable, and demonstrably tied to business risk rather than treated as a tick-box exercise.
Continuous and Actionable Monitoring
Detection and response capability that generates alerts organisations can actually act on, not just logs that sit unreviewed.
What Does This Mean for Your Business?
If You Have Already Implemented the Essential Eight
Your compliance work remains highly relevant. The new Essentials series is explicitly designed as an evolution of the Essential Eight, not a replacement that makes your existing controls obsolete. The controls you have implemented, such as patching, MFA, application control, and backups, remain foundational and will carry forward into the new framework.
What the transition will require is a shift in mindset from checking boxes against a fixed list to building security that can adapt as your environment and the threat landscape evolve. This is a more mature and ultimately more effective approach to cybersecurity.
If You Are Still Working Toward Essential Eight Compliance
Do not stop. You have approximately 12 months before the Essential Eight begins formal deprecation, and the work you do now will directly underpin your readiness for what comes next. Reaching Maturity Level 2 or 3 on the Essential Eight remains the strongest foundation you can build for the transition to the new Essentials series.
If You Have Not Yet Started
The announcement of the Essential Eight’s retirement is not a reason to delay cybersecurity investment. The new framework is more comprehensive, not less demanding. Businesses that have not yet implemented foundational controls such as phishing-resistant MFA, consistent patching, and tested backups are exposed right now, under both the existing and the incoming frameworks.
Why the Shift to Modern Defensible Architecture Makes Sense
The core philosophy behind MDA is straightforward: design your systems and defences with the assumption that some attacks will succeed, and build the capability to detect them quickly, contain the damage, and recover reliably. This is sometimes called “assume breach” thinking.
This is a significant shift from the original Essential Eight philosophy, which focused primarily on prevention. Prevention remains important, but the threat landscape in 2026 makes it clear that prevention alone is insufficient. Ransomware groups, AI-accelerated attacks, and supply chain compromises are demonstrating every week that even well-defended organisations can be breached. The question is no longer just “how do we keep attackers out?” but “how quickly can we find them when they get in, how do we limit the damage, and how fast can we recover?”
The Five Eyes intelligence alliance, of which Australia is a member, issued a joint public warning in June 2026 that AI-powered cyberattacks are expected to become a reality within months, not years. The new Essentials framework, with its emphasis on Zero Trust, contextual access controls, continuous monitoring, and assumed breach, is designed to be resilient against exactly this type of evolved threat.
What Should Australian Businesses Do Right Now?
Keep your Essential Eight compliance on track. If you are mid-implementation, continue. Maturity Level 2 is the recommended baseline for most industries and remains the right target for the next 12 months.
Start familiarising yourself with the new Essentials framework. The “Essentials for Enterprise IT” consultation document is publicly available. Reading it now will give you a clear picture of where requirements are heading and help you identify any gaps between your current controls and the new expectations.
Review your identity and access management approach. The new framework places significantly greater emphasis on centralised identity, phishing-resistant MFA, and contextual access controls. If your organisation is still using push-based MFA and has fragmented identity management, this is the area to prioritise next.
Invest in detection and response capability. The shift to “assume breach” thinking means that endpoint detection and response (EDR), network monitoring, and security information and event management (SIEM) tools are no longer optional for organisations of any meaningful size. If you do not have visibility into what is happening in your environment, you cannot respond when something goes wrong.
Review your cloud and SaaS security posture. The Essential Eight was not designed for cloud environments. The new Essentials framework explicitly addresses cloud security as a separate domain. Organisations that have migrated significant workloads to cloud without a corresponding security posture review are carrying risk the old framework did not capture well.
Engage your IT provider in a transition planning conversation. The move from the Essential Eight to the Essentials series is an opportunity to review your security posture holistically, not just update a compliance checklist.
How Otto IT Can Help
Otto IT works with businesses across Australia to implement practical, outcome-focused cybersecurity that meets current compliance requirements and positions clients well for the frameworks coming next.
Whether your organisation is just starting its Essential Eight journey, working toward Maturity Level 2 or 3, or looking to get ahead of the transition to the new Essentials series, our managed cybersecurity services are designed to deliver the foundations that matter: phishing-resistant MFA, consistent patching, application control, tested backups, and the detection capability to catch what gets through.
The retirement of the Essential Eight is not a reason to pause. It is a signal that the bar is being raised, and the businesses that prepare now will be in a significantly stronger position than those that wait. Get in touch with the Otto IT team to discuss where your organisation sits in the transition and how to build the right roadmap forward.
Frequently Asked Questions
Is the Essential Eight being scrapped immediately?
No. The Essential Eight will remain active for approximately 12 months before formal deprecation begins, and will not be fully retired until approximately mid-2028. Organisations should continue to implement and maintain Essential Eight compliance throughout this period.
Does this mean my Essential Eight work has been wasted?
Not at all. The new Essentials series is explicitly designed as an evolution of the Essential Eight, not a replacement that makes existing controls redundant. The controls you have implemented remain foundational and will be directly applicable under the new framework.
What is Modern Defensible Architecture?
Modern Defensible Architecture (MDA) is ASD’s strategic framework for designing IT environments that can withstand and recover from modern cyber threats. It emphasises Zero Trust principles, layered defenses, secure-by-design practices, and the assumption that some attacks will succeed, making rapid detection and recovery just as important as prevention.
When does the consultation on the new framework close?
The public consultation on the first chapter, “Essentials for Enterprise IT,” closes on 12 July 2026. Feedback can be submitted via the ACSC Partner Portal.
Should I still target Maturity Level 2 if the framework is being retired?
Yes. Maturity Level 2 of the Essential Eight remains the recommended baseline for most Australian businesses for the next 12 to 18 months. The controls at Maturity Level 2, particularly around phishing-resistant MFA, patching, and application control, will remain highly relevant under the new framework.
The Essential Eight Is Evolving. Your Cybersecurity Should Too.
The retirement of the Essential Eight is not a setback for Australian cybersecurity. It is a sign that the standard is maturing to meet a more complex and more dangerous threat landscape. The new Essentials series, anchored in Modern Defensible Architecture and Zero Trust principles, will demand more from organisations but will also deliver significantly stronger protection.
Otto IT helps Australian professional services firms navigate exactly these kinds of transitions. From Essential Eight assessments and implementation through to Zero Trust planning and cloud security reviews, we help businesses build security that works today and is ready for what comes next.
Talk to the Otto IT team today to understand where your organisation sits in the transition and how to build the right roadmap forward.
This post was published on 24 June 2026 and reflects ASD’s announcement and the public consultation process open as of that date. The Essential Eight remains active and ASD’s current compliance guidance applies until formal retirement guidance is issued.
managed it support articles
Related Blog Articles
Discover more insights to optimise your business with the latest IT trends and best practices. Stay ahead of the curve by learning how to leverage cutting-edge technology for success. Explore expert advice and valuable guidance to navigate the evolving world of IT solutions