Here's what actually changes, and what doesn't
On 24 June 2026, the Australian Signals Directorate confirmed something I'd been hearing rumblings about for a while: the Essential 8 is being retired. Not tweaked, not versioned up. Retired, and replaced by a broader body of guidance ASD is calling the Essentials series.
If you're mid-implementation, or you've just had a client or insurer ask about your Essential 8 maturity level, that headline is alarming. It shouldn't be. Here's what's actually happening and what I'd do about it.
What ASD announced
The Essential 8 will remain a live, supported document for now. ASD's own timeline:
- Now to ~12 months: Essential 8 stays current. No change to what auditors, insurers, or tender panels expect.
- ~12 months out: Essential 8 begins to be deprecated in favour of the Essentials series.
- ~24 months out: Essential 8 is retired entirely.
The first chapter of the replacement, Essentials for Enterprise IT, is the direct evolution of the Essential 8. It was open for public consultation until 12 July 2026. Further chapters are planned for cloud and operational technology, with agentic AI flagged as a likely future addition.
The structural shift is the real story. Essential 8 was one checklist for everyone. Essentials is being built as separate domains, because "everyone" now includes SaaS-only businesses, hybrid cloud shops, OT environments, and orgs running AI agents against production systems, none of which the original eight controls were designed around.
Why ASD is doing this
Chris Horlyck, head of cyber security resilience at the ACSC, put it plainly: "Essential 8 started before cloud was really a big thing in the sector. Now, if you don't have cloud, that would be a really surprising architecture to have."
That's the crux of it. The Essential 8 was written for on-premises environments. Its controls map awkwardly onto shared-responsibility cloud models and SaaS, which is most of my client base's actual attack surface in 2026. Patch operating systems and application control matter less when half your stack is somebody else's SaaS platform. The framework was showing its age against a threat environment it wasn't built for.
What this means if you're already doing Essential 8 work
Don't stop. Horlyck also said this, and it's the part that matters most for anyone reading this mid-project: "The investment you've made under the Essential 8 will still be relevant under the Essentials."
That tracks with how the replacement is being built. Essentials for Enterprise IT is described as the direct evolution of the eight controls, not a clean-sheet rewrite. MFA, patching, admin restriction, backups, none of that stops being good practice because the framework wrapping it gets renamed. If you've done the work I laid out in the Essential 8 compliance checklist, you haven't wasted a quarter. You've built the foundation the Essentials series is going to sit on top of.
What I am telling clients right now:
- Keep going on your current maturity target. Insurers and tender panels are still asking for Essential 8 ML1/ML2 today, and will be for at least the next 12 months. Stopping now to "wait for Essentials" leaves you exposed on renewals and tenders that haven't gotten the memo yet.
- Don't over-invest in anything narrowly Essential 8-specific. If a tool or process only exists to produce an Essential 8 maturity score and nothing else, that's the one thing worth holding off on. Evidence of the underlying control (MFA is on, backups are tested) outlives the framework name.
- Watch for Essentials for Enterprise IT to land. Once it's published, expect insurers and government panels to start referencing it as a parallel or replacement acceptance criterion. I'll be tracking the consultation outcome and will post again once the first chapter is finalised.
- This is a naming and structure change, not a lowering of the bar. Nothing in ASD's announcement suggests the underlying expectations get easier. If anything, outcome-based, threat-informed guidance tends to raise the bar for orgs that were ticking boxes rather than actually reducing risk.
The bigger pattern
Essential 8 becoming Essentials for Enterprise IT, Cloud, OT, and (likely) AI isn't really about a rebrand. It's an admission that "one checklist fits all Australian organisations" stopped being true a while ago. If you're an SMB running entirely on Microsoft 365 with no on-prem footprint, a good chunk of the original eight controls were always an awkward fit. Assume the direction of travel is toward guidance that's more specific to your actual environment, and less like a form you fill in to satisfy an auditor.
That's a better outcome for the businesses actually doing the work. It's a worse outcome for anyone who was treating "Essential 8 compliant" as a badge rather than a floor.
Next steps
If you haven't baselined yourself against the current Essential 8 yet, that hasn't changed, do it now. It's still the reference point everyone (insurers, tenders, enterprise clients) is using today, and it's still the foundation the Essentials series is being built on.
Take the Essential 8 Self-Assessment
If you're already partway through an Essential 8 project and want a second opinion on whether your current work is future-proof under Essentials, book a call.
References
- ASD: Essential Eight to retire within two years
- ACSC Essential 8 Maturity Model
- The Essential 8 Compliance Checklist for Australian SMBs
I'm Josh McCarthy, Director and Lead Auditor at Your IT Managers, a Melbourne-based MSP that does ISO 27001, Essential 8, and Microsoft 365 security work for Australian SMBs across the country. I'll be following the Essentials for Enterprise IT consultation outcome closely and will update this once it's finalised.