Not yet. In June 2026 the Australian Signals Directorate opened consultation on evolving the Essential Eight into a broader Essentials series, starting with a chapter called Essentials for enterprise IT. The Essential Eight and its Maturity Model remain published, current and in force. ASD has signalled a transition of roughly two years.
The consultation ran through the ASD Cyber Security Partnership Program portal and closed on 12 July 2026. What ASD put forward is a proposal for comment. The final structure of the series, its control set, its assessment method and its standing under any regulatory framework have not been published, and nothing an Australian organisation is obliged to do today has changed.
What exactly did ASD announce?
On 15 June 2026 ASD published a short notice on cyber.gov.au titled Consultation on evolution of Essential Eight. Reading it closely matters, because much of the commentary that followed compressed a proposal into a headline about retirement.
- ASD is consulting its Cyber Security Network partners on a proposed evolution that introduces a new Essentials series and expands the current framework (ASD, cyber.gov.au, 15 June 2026).
- The guidance is grounded in the Information Security Manual and described as offering prioritised, threat-informed mitigations for contemporary technology environments, supported by practical tools and clear implementation guidance (ASD).
- ASD states that organisations already using the Essential Eight can expect strong alignment with their existing controls and investments (ASD).
- Current Essential Eight guidance becomes the first chapter, Essentials for enterprise IT, with further chapters to follow (ASD).
- Consultation was national, covering government, industry, regulators and current Essential Eight users, and ran via the ASD Cyber Security Partnership Program portal until 12 July 2026 (ASD).
iTnews reporting on 24 June 2026 added detail from Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre. Three chapters are expected to open the series: enterprise IT, then operational technology, then cloud. Horlyck flagged that agentic artificial intelligence could warrant its own chapter, given the identity questions raised by non-person entities and the threat of prompt injection. ASD's Modern Defensible Architecture series is cited as an influence.
"New technologies often bring new or modify existing cybersecurity risk, requiring different controls. To defend against modern threats with modern tools, our guidance must evolve as well."
Is the Essential Eight still in force?
Yes, and the evidence is on ASD's own website. As at July 2026 the Essential Eight landing page still carries the full publication set, including the assessment process guide, the Maturity Model, the ISM mapping and the assessment course. The Maturity Model page shows a last-updated date of 27 November 2023 and no deprecation notice. Nothing has been withdrawn.
The obligations built on top of it are equally unchanged. The Protective Security Policy Framework has required non-corporate Commonwealth entities to implement all eight strategies to at least Maturity Level 2 since 1 July 2022, and that requirement remains. Government supply chain contracts, Defence industry requirements, cyber insurance questionnaires and enterprise vendor reviews continue to ask for Essential Eight maturity. Where a sector regulator or a customer contract references the Essential Eight or the ISM, that reference still binds. A consultation on future guidance does not amend a contract or a policy framework.
Try it
Score against the model that still counts
Every obligation in force today references the current Essential Eight Maturity Model, so that is the sensible thing to measure against while the Essentials series is drafted. Frontrow's assessment walks each of the eight strategies and returns a maturity picture plus the specific gaps behind it.
Score each of the 8 strategies
Where are you on the Essential Eight — honestly?
Eight strategies. Four levels each. Pick the statement closest to your reality today. We'll map it to the Microsoft 365 tooling that closes the gap.
What's your target Maturity Level?
Maturity Level 2 — most orgs' pragmatic target
- 01
Application control
Only approved applications can execute on workstations and servers.
- 02
Patch applications
Internet-facing apps, browsers, Office, PDF readers patched promptly.
- 03
Microsoft Office macros
Macros disabled unless from trusted locations and signed by a trusted publisher.
- 04
User application hardening
Web browsers and productivity apps hardened against the most common attacks.
- 05
Restrict administrative privileges
Admin accounts limited, separated and reviewed — the crown jewels of the tenant.
- 06
Patch operating systems
Operating system patches applied on a schedule that matches the risk.
- 07
Multi-factor authentication
MFA everywhere that matters — privileged accounts, remote access, important data.
- 08
Regular backups
Backups of important data, configuration and software — and restores you have actually tested.
Why is ASD revisiting the Essential Eight?
The Essential Eight maturity model was first published in June 2017, growing out of ASD's earlier Top Four mitigation strategies. It was written for managed Windows endpoints and servers an organisation owned and could see. The critique ASD has now acknowledged is structural rather than cosmetic.
"Essential Eight started before cloud was really a big thing in the sector. Now, if you don't have cloud, that would be a really surprising architecture to have."
- 1Architecture drift. The controls were designed for on-premises enterprise IT and, per Horlyck, do not translate cleanly to shared-responsibility models or software-as-a-service environments. An identity-centric cloud estate has to reason by analogy to score itself against several of the eight.
- 2Prescriptive rather than outcome-based. ASD technical expert Jayden Cooke described the Essentials design as moving away from relying only on prescriptive technical controls, towards a principles-based approach explaining the adversary techniques an organisation faces and the intent behind each mitigation (ACS Information Age, 25 June 2026).
- 3Moving goalposts. ASD has confirmed the long-standing complaint that maturity requirements shift under organisations' feet, creating the appearance of going backwards with no real decline in posture. Horlyck attributed this to absorbing new tradecraft into fixed maturity levels, and said the new series is meant to decouple threat-informed controls from that fixed ladder.
- 4Weak measured adoption. Overall maturity is set by the weakest of the eight strategies, which is unforgiving in practice.
The adoption record is worth stating plainly. Only 22 per cent of Australian federal government entities reached overall Maturity Level 2 in 2025, up from 15 per cent in 2024 but below the 25 per cent recorded in 2023, before ASD hardened the Level 2 controls (ASD, The Commonwealth Cyber Security Posture in 2025). Multi-factor authentication was the weakest strategy at 34 per cent, and 59 per cent of entities said legacy technology limited their implementation. The Australian National Audit Office has separately reported ongoing low levels of cyber resilience in non-corporate Commonwealth entities. Nine years in, the one population measured annually and legally required to comply has never had more than a quarter of entities at the mandated level.
What is confirmed, and what is still open?
This distinction separates a defensible plan from an expensive guess. Confirmed by ASD: the Essentials series exists as a proposal grounded in the ISM, its first chapter is Essentials for enterprise IT, consultation ran to 12 July 2026, and existing investments are expected to align strongly with it. Reported by credible outlets quoting named officials, but not ASD policy: the transition timing, the chapter order and the design intent around maturity levels.
Not confirmed by anyone, and treated here as unknown:
- The final content of the Essentials series. No draft control set has been published. Any article describing the specific controls in Essentials for enterprise IT is describing something it has not seen.
- How many controls the first chapter will contain, whether the count of eight survives, and whether maturity levels persist, are renamed or give way to a different assessment structure. Decoupling controls from a fixed ladder is a stated direction, not a published mechanism.
- Publication dates for the final enterprise IT chapter, or for the operational technology and cloud chapters.
- Whether agentic AI becomes a dedicated chapter. This was raised as a possibility, not a commitment.
- Whether the PSPF, prudential standards, sector regulators or Commonwealth procurement will reference the Essentials series, and when. Each instrument is owned by a different body and needs its own amendment process.
- Exact deprecation and retirement dates. The figures in circulation come from an ACSC official describing an expectation in approximate terms.
What should an organisation do in the next 12 months?
The honest answer is that very little should change, and the reasoning matters more than the conclusion. Patching, multi-factor authentication, application control, restricted administrative privilege, macro settings, application hardening and tested backups are not artefacts of a 2017 document. They address the techniques ASD sees in incident response, which is why ASD says existing investments will align strongly with the new series. Horlyck put it directly to iTnews: the investment made under the Essential Eight will still be relevant under the Essentials.
What is worth changing is how the work is framed and funded. A program justified as reaching Maturity Level 2 by a date is vulnerable to a question no one can currently answer. A program justified by risk reduction against named adversary techniques is not.
- 1Keep the current program running to its existing target. If Maturity Level 2 is required by a contract, a regulator or an insurer, that requirement is live and unamended. Finishing is the fastest route to a defensible position under either framework.
- 2Rewrite the business case around durable controls rather than the framework name. Fund phishing-resistant multi-factor authentication, patch cadence measured in days, removal of standing administrative privilege, application control and rehearsed restore testing.
- 3Get an accurate baseline now. Assessed maturity routinely lands below self-assessed maturity, and ANAO auditing has found entities claiming compliance on documented policy rather than tested controls. A gap found in 2026 is cheaper than one found in a transition year.
- 4Audit contracts and policies for framework language. Search every customer contract, supplier agreement, tender response, insurance schedule and internal policy for the phrase Essential Eight, and record who owns each document.
- 5Close the cloud and identity gaps the current model handles awkwardly. Conditional access, privileged identity management, non-person identities and software-as-a-service data governance are all areas ASD has signalled the new guidance will treat more directly.
- 6Assign an owner to track publication. One named person, a quarterly reminder and a two-line note to the board. Monitoring this costs close to nothing and removes any need to speculate.
For organisations on Microsoft 365, most of the durable control set is already licensed and can be brought forward without new procurement. Microsoft Entra ID delivers phishing-resistant multi-factor authentication and conditional access, Intune handles patch cadence and application control policy, and Defender adds detection above both. In Frontrow's experience the gap in a typical Australian tenant is configuration and operational discipline rather than missing capability, which is why the uplift transfers cleanly to whatever ASD publishes.
Who does this affect most?
Organisations part-way through an Essential Eight uplift
This group is most at risk of a poor decision, and the risk runs towards doing too little. A multi-year uplift with approved budget and a steering committee is exactly the sort of program that stalls when someone circulates a headline about retirement. A paused program loses momentum and funding, then restarts from scratch when the successor lands and the same controls turn out to be required. If re-scoping is needed, re-sequence towards the controls carrying the most risk reduction rather than the ones easiest to score.
Suppliers whose contracts name the Essential Eight
This is the concrete problem, and it belongs with legal and commercial teams well before any transition. Many Australian contracts require the supplier to maintain, or work towards, Essential Eight Maturity Level 2, sometimes with an audit right or warranty attached. Once a framework is retired, that clause references a document ASD no longer maintains.
- Static references date badly. A clause naming Essential Eight Maturity Level 2 with no version or successor provision turns ambiguous once the model stops being updated, and ambiguity in a security warranty suits neither party.
- Audit clauses can become unworkable. Where an agreement requires annual independent assessment against the Essential Eight and assessors have moved on, the obligation may be impossible to satisfy as written.
- Renewals are the cheap moment to fix it. Contracts renewing between now and 2028 can be amended in the ordinary course, with wording referencing ASD's then-current baseline guidance for enterprise IT rather than one named publication.
- Bids, tender responses, insurance schedules and broker questionnaires deserve the same review. Committing to a named maturity level across a multi-year term with no successor mechanism creates an obligation that may outlive the framework.
What would change this plan?
"We anticipate that there will be a transition period where we will keep the Essential Eight a live document and the Essentials a live document. Then we will look to, probably in 12 months, start to deprecate the Essential Eight, and then in 24 months we'll retire the Essential Eight as a whole."
That is an expectation stated in approximate terms by a named official. It is the best guidance available, it is not a published schedule, and it should be treated as indicative. Four things would justify revisiting the plan above.
- ASD publishes the final Essentials for enterprise IT chapter. The control set and assessment method become knowable, and a real mapping from an existing Essential Eight position becomes possible. This is the single event most worth watching.
- The PSPF or a sector regulator formally references the Essentials series, or sets a date for doing so. That converts guidance into obligation, and compliance timelines start driving the program.
- ASD publishes a deprecation notice or a transition mapping. A published old-to-new mapping would make re-scoping straightforward and is the natural trigger for updating contract language.
- The operational technology or cloud chapters appear. These matter disproportionately to manufacturers, utilities, logistics operators and cloud-heavy organisations, whose current Essential Eight scores least represent their real risk.
Until one of those happens the position is stable: score against the current model, invest in controls that survive any rebranding, and fix contract language early while it is a drafting task rather than a dispute.
Verified July 2026 against ASD's consultation notice of 15 June 2026, the current cyber.gov.au Essential Eight and Maturity Model pages, iTnews reporting of 24 June 2026, ACS Information Age reporting of 25 June 2026, and ASD and ANAO reporting on Commonwealth cyber posture. Statements about the Essentials series are either ASD's published proposal or officials' quoted comments, labelled as such throughout. Frontrow will update this article when ASD publishes the first chapter.