The Essential Eight Is Being Retired

Here's what's replacing it, and what it means for you.

For nearly a decade, the Essential Eight has been the shorthand for “are we doing the cyber basics right?” in Australia. If you've ever been asked for a maturity level in a tender, a grant application, or an insurance renewal, you've met it.

So here's some news worth a calm read. The Australian Signals Directorate (ASD) intends to retire the Essential Eight within the next two years and replace it with a broader, more flexible framework called the Essentials series.

If you're partway through an Essential Eight uplift, take a breath. Nothing changes overnight, and the work you've already done isn't wasted. Below is the plain-English version of what's happening, when, and what you actually need to do.

Key takeaways

  • ASD is retiring the Essential Eight over roughly two years, replacing it with a new, broader framework called the Essentials series.
  • Deprecation begins at around 12 months, full retirement at around 24 months. The Essential Eight stays live and supported until then.
  • Your existing Essential Eight investment carries over. This is an evolution, not a reset.
  • Only 22% of federal entities reached Maturity Level 2 in 2025, up from 15% in 2024, showing how much ground most organisations still have to cover under the current framework, let alone the next one.
  • For SMBs, SMB1001 (2026 edition) offers a lighter-weight, tiered path to a documented security posture, self-attested at Bronze through Gold, independently audited at Platinum and Diamond.

What ASD actually announced

Speaking to iTnews, Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre (ACSC) within ASD, set out the plan. Both the Essential Eight and the new Essentials guidance will run as live, supported documents during a transition period. After that, ASD expects to begin deprecating the Essential Eight at around the 12-month mark, with full retirement following at around 24 months.

ASD has also been direct about what happens to the work already done. Organisations “can expect strong alignment with their existing controls and investments,” meaning multi-factor authentication, patching, application control, backups, and restricted admin privileges all carry straight across into the new framework rather than being thrown out.

Why the change, and why now

The Essential Eight was published in 2017, built for a world of on-premises servers, before cloud was so widely adopted. Its controls don't provide as effective cover for cloud, SaaS, and shared-responsibility environments, and they weren't written with AI-era threats, like prompt injection against AI agents, in mind.

The scale of the gap is part of the story too. ASD's own data shows just 22% of federal entities reached overall Maturity Level 2 in 2025, up from 15% the year before, but still below the 25% recorded back in 2023. That dip and recovery reflects ASD tightening the ML2 bar over time, not organisations getting less secure. It's the exact “moving goalposts” problem the Essentials series is designed to fix, by separating threat-informed controls from a single, shifting maturity ladder.

The new Essentials series shifts the emphasis away from prescriptive, technology-specific controls and towards outcomes and intent. That gives organisations more flexibility to meet the guidance with whatever tools suit their environment. It's grounded in the Information Security Manual (ISM) and rolls out in chapters, starting with enterprise IT, followed by operational technology and cloud, with agentic AI flagged as a possible future chapter.

The part that matters most: your investment carries over

This is the line to hold onto. ASD has been explicit that work already done under the Essential Eight is not made redundant. The fundamentals you've invested in, multi-factor authentication, patching, application control, backups, and restricting admin privileges, map straight across to the new framework. It's an evolution, not a reset.

So what should your organisation do right now?

Honestly, nothing urgent. The Essential Eight remains the live, supported framework, and the deprecation clock hasn't started ticking yet. Walking away from current Essential Eight work now would leave you exposed.

That said, this is a good moment to make sure your baseline is genuinely in place and provable, because whatever it ends up being called, the direction of travel is clear: Australia is moving towards flexible, risk-based, evidence-led security.

For small and medium organisations, especially in the not-for-profit, care, health, and education sectors we work with, there's a practical readiness path worth knowing about called SMB1001. It's a tiered Australian certification, Bronze through Diamond, built specifically for SMBs, with the current SMB1001:2026 edition (released September 2025) mapping directly to Essential Eight controls. It's a lighter-weight alternative to ISO 27001, and it's increasingly what clients, funders, and insurers are asking for.

Worth knowing before you commit to a tier: Bronze, Silver, and Gold are self-attested by a director, which is what makes them fast and accessible. Platinum and Diamond add independent third-party audit, for organisations that need that stronger form of external proof. Most SMBs in our sectors sit comfortably at Silver or Gold, and even self-attested certification is still a documented, recognised standard to hand to a funder or insurer, just not an externally audited one.

Put simply, getting your fundamentals certified now, at whichever tier suits your organisation, positions you well no matter what the framework is called in two years' time.

The short version

  • The Essential Eight is being retired within about two years and replaced by ASD's new Essentials series.
  • Expect deprecation at around 12 months and full retirement at around 24 months.
  • The new framework is principles-based, ISM-grounded, and built for cloud, OT, and AI-era realities.
  • Your existing Essential Eight investment carries over.
  • For SMBs, SMB1001 is a practical, tiered way to get a documented security posture now.

FAQ

Is the Essential Eight being scrapped?

Not immediately. ASD plans to retire it over about two years and replace it with the Essentials series. During the transition, the Essential Eight remains live and supported.

What is replacing the Essential Eight?

A new, broader Essentials series, grounded in the ISM. It starts with “Essentials for enterprise IT” and expands to operational technology, cloud, and potentially agentic AI.

Will my Essential Eight work be wasted?

No. ASD says existing controls and investments will align strongly with the new framework.

What should SMBs do now?

Confirm your fundamentals are in place and provable. SMB1001 offers a tiered, affordable certification (Bronze through Diamond) that maps to the Essential Eight and shows your posture to clients, funders, and insurers, self-attested at the lower tiers, externally audited at Platinum and Diamond.

Is SMB1001 independently verified?

Only at the top two tiers. Bronze, Silver, and Gold are self-attested by a company director. Platinum and Diamond require external audit, for organisations that need independently verified proof.

A final word, and where we fit

Frameworks evolve. Good security habits don't. At The Virtual IT Department, we spend our time watching shifts like this one so you don't have to, then we turn them into simple, practical steps for the organisations we look after across the care, not-for-profit, health, and education sectors.

If you'd like to understand how these changes affect your environment, and what a straightforward readiness path looks like, we're always happy to talk it through. Take what's useful, and if you want to talk through the rest, we're here.

Talk to our team

Contact us

Let's talk
IT Department tech staff helping client with computer
Learn more about

IT Consulting

We exist to leverage technology to unleash business possibilities. Whether you’re looking for systems auditing, strategic advice or right-fit tool assessments, we can help you with the insight and strategy needed to make the right decisions for your business.
Learn more

Keep reading

Need help with your IT services?

See all Services