For nearly a decade, the Australian Signals Directorate's Essential Eight has been the default starting point for cybersecurity in Australia. It shaped how organisations thought about baseline security, how boards measured cyber posture, and how tenders and contracts defined minimum expectations.
That framework is now being retired.
On 24 June 2026, the ASD confirmed what the cybersecurity community had long been advocating for: the Essential Eight will be retired within the next two years and replaced by a new "Essentials series." Consultation on the first chapter, Essentials for Enterprise IT, closed on 12 July 2026. Cyber News Centre
At ASE Tech, we welcome this change. Not because the Essential Eight was a failure, but because the threat landscape has moved faster than any fixed eight-control checklist could follow, and Australian organisations defending critical infrastructure deserve a framework that keeps pace.
Key takeaways
- The ASD confirmed on 24 June 2026 that the Essential Eight will be retired within two years and replaced by a broader framework called the Essentials Series
- The Essential Eight remains the active, supported framework today. Your compliance obligations have not changed and nothing needs to be abandoned
- The first chapter of the Essentials Series, Essentials for Enterprise IT, was open for public consultation until 12 July 2026
- Future chapters will cover Operational Technology (OT), Cloud, and Agentic AI: the first time Australia will have purpose built national cybersecurity guidance for OT environments
- Existing Essential Eight controls, evidence, and maturity work will map directly across to the new framework. Your investment is not wasted
- The shift is from prescriptive, technology specific controls to outcomes and principles based guidance, giving organisations more flexibility across modern environments including cloud, hybrid, and OT
- The Essential Eight is expected to begin deprecating around mid-2027 and be fully retired around mid-2028
- For critical infrastructure operators, this change intersects directly with SOCI Act CIRMP obligations. The OT chapter in particular will shape how cybersecurity requirements are assessed in regulated sectors
What exactly is changing with the Essential Eight?
The Essential Eight is not disappearing overnight. It stays live and fully supported for roughly the next 12 months, begins deprecating around mid-2027, and is retired around mid-2028, replaced by a broader body of guidance called the Essentials series.
The first chapter of the series covers Essentials for Enterprise IT, with more chapters set to follow, including for areas such as operational technology. Cloud environments and agentic AI are also flagged as likely future chapters.
Importantly, the Essential Eight remains the current, supported framework today, and it is still what tenders, contracts and regulators reference. Nothing needs to be abandoned. The transition is measured and deliberate — not a sudden disruption.
Why did the Essential Eight need to evolve?
Because it was built for a world that no longer exists. The Essential Eight was first published in 2017 for an on-premises, Windows-centred, perimeter-based environment, and most organisations do not operate that way anymore.
The Essential Eight was first published in 2017, evolving from the earlier Top Four, and it was designed for an on-premises, Windows-centred, perimeter-based environment. Most organisations no longer operate that way. Cloud platforms, software as a service, operational technology and mobile endpoints do not map cleanly onto controls written for a shared responsibility model that did not yet exist.
That structural limitation has been felt acutely in critical infrastructure environments. Energy operators running SCADA systems, water utilities with industrial control networks, and telecommunications providers managing distributed OT assets have always found themselves trying to apply IT-centric controls to fundamentally different technology environments. The Essential Eight was never really designed for them.
There's a second problem the change is designed to fix. Because ASD absorbed new attacker tradecraft into the existing maturity levels over time, organisations could appear to go backwards on their maturity score without their actual security posture deteriorating at all. The Essentials series decouples threat-informed controls from a fixed maturity ladder, so the bar stops shifting under your feet.
For any organisation that has experienced the frustration of an apparently declining maturity score despite maintaining the same controls, this is a meaningful improvement.
Why did AI-powered threats make this change urgent?
Because a static, eight-control checklist was never going to hold up against an adversary using machine learning to automate attacks. AI-powered threats have changed what baseline security needs to look like, and the security vendor community has been direct that the previous Essential Eight is a mismatch against a 2026 threat environment.
Given the large and fast-moving threat posed by genAI, the ASD's overhaul of the Essential Eight is long overdue. The security vendor community has been increasingly direct about this: in complex 2026 environments the previous Essential Eight is a "mismatch in terms of efficacy against a 2026 threat environment."
AI-powered attacks have changed what baseline security needs to look like. Adversaries are now using machine learning to automate reconnaissance, accelerate phishing campaigns, identify vulnerabilities faster than patch cycles can respond, and generate convincing social engineering at scale. A static set of eight controls written for a pre-AI threat environment was always going to struggle against this pace.
The shift marks a move from checklist maturity to defensible cyber architectures built for modern attack conditions in Australia today. That framing, defensive architecture rather than compliance checklist, is exactly the right way to think about cybersecurity in 2026. Cyber Wyze
The Essentials series is designed around four core principles: flexibility, threat-informed insights, prioritisation and risk management, and compatibility with what organisations already have in place. "The framework adopts principle-based guidance to achieve cyber security outcomes. It also helps you make the most of what you already have while allowing modern and emerging technologies to be applied as your environments are upgraded," ASD technical expert Jayden Cooke confirmed when announcing the changes. Idm
Why is the new OT chapter significant for critical infrastructure operators?
Because it is the first purpose-built national cybersecurity guidance Australia has ever had for operational technology. For critical infrastructure operators, the most significant announcement within the Essentials series is not the Enterprise IT chapter, it is what comes next: a dedicated chapter for SCADA systems, industrial control systems, PLCs, and the distributed OT environments underpinning energy, water, transport, and telecommunications.
A dedicated chapter for Operational Technology means that, for the first time, Australia will have purpose-built national cybersecurity guidance for SCADA systems, industrial control systems, PLCs, and the distributed OT environments that underpin energy, water, transport, and telecommunications infrastructure.
This matters enormously. OT security has always required a fundamentally different approach from IT security. Availability constraints, decades-long asset lifecycles, legacy systems that cannot be patched, and the physical safety consequences of a cyber event all mean that IT-centric controls applied to OT environments create as many problems as they solve. The existing Essential Eight was never designed for these environments, and applying it literally to OT has led to compliance theatre rather than genuine operational resilience.
A dedicated OT chapter, built on ASD's direct experience supporting critical infrastructure operators through incidents and uplift activities, has the potential to become the most practically useful cybersecurity guidance ever produced for Australian critical infrastructure. Combined with the existing AESCSF framework for energy sector operators and the SOCI Act CIRMP obligations, it will give responsible entities a clearer, more coherent picture of what good looks like across both their IT and OT environments.
What should your organisation do about the Essential Eight transition right now?
Keep going. The Essential Eight remains the active framework today, is likely to be deprecated around mid-2027, and fully retired around mid-2028, and the guidance below depends on where your organisation sits in that timeline.
If you haven't started your Essential Eight uplift, start now. The framework remains live, and tenders, contracts and regulators are measuring against it right now, and will keep doing so through the transition. Delaying on the basis of the incoming change is the wrong call — the controls that underpin Essential Eight compliance will map directly across to the Essentials series.
If you're mid-uplift, keep going. The organisations that will look strongest in mid 2027, when deprecation begins, are the ones who kept moving in mid 2026. Keep executing. Do not pause, do not de-scope, and do not shift budget out of the current uplift cycle on the basis of this announcement. The controls, the evidence and the operational capability all remain valid.
If you're at ML2 or above, focus on evidence quality. Frame evidence around control outcomes and risk reduction, not just maturity level attainment. Evidence written this way carries forward into the Essentials series without rework. Agilient
Update your board reporting language. Start shifting executive and board conversations from "Essential Eight Maturity Level" as the headline metric toward control coverage, outcomes, and residual risk, with framework alignment as a reference layer underneath. This positions your organisation well for the transition regardless of when formal deprecation occurs.
For critical infrastructure operators, there's an additional consideration. Government, critical infrastructure and financial services organisations should follow how the transition interacts with their obligations under the PSPF, the SOCI Act and APRA's standards. The SOCI Act CIRMP obligations reference designated cybersecurity frameworks — monitoring how the Essentials series is formally recognised within that regulatory context is important. ASE Tech will be tracking this closely and updating clients as the picture becomes clearer.
Is the shift from the Essential Eight to the Essentials series the right move?
Yes, and it comes at the right time. The Essential Eight served Australian organisations well for nearly a decade, creating a common language for cybersecurity and a measurable starting point for boards, but a framework written in 2017 for Windows-based, on-premises environments was always going to struggle against AI-powered attacks, complex hybrid cloud architectures, and critical infrastructure OT environments.
The Essentials series is the right response. A principles-based approach gives organisations the flexibility to implement security in ways that actually fit their architecture. Domain-specific chapters for enterprise IT, OT, and cloud acknowledge that different environments have genuinely different requirements. And building on ASD's direct incident response experience means the guidance reflects real Australian threat intelligence — not theoretical frameworks.
For organisations that treat cybersecurity as a strategic capability rather than a compliance checklist, this change is an opportunity rather than a disruption. The organisations best positioned when the Essentials series matures are the ones investing in genuine security outcomes today — not just maturity level scores.
ASE Tech's cybersecurity services are designed around exactly this approach — building defensible security architectures that hold up against modern threats and carry forward across framework changes. If you'd like to understand how the Essential Eight transition affects your organisation and what you should be doing now, contact our team for an initial conversation.
.png)