Essential Eight Changes and What’s Coming Next

Essential Eight Changes and What's Coming Next

Table of Contents

The Essential Eight changes announced in June 2026 mark the end of the framework as we know it. The Australian Signals Directorate (ASD) confirmed the framework will be retired within two years and replaced by a new set of guidance called the Essential series.

We’ve already covered what the Essential Eight is and how the maturity levels work. This post is about what’s changing and what comes next.

Why the Essential Eight is being replaced

The reason is structural rather than a verdict on the controls themselves. The Essential Eight was created in 2017 for on-premises, Windows-centered IT environments. Cloud platforms and SaaS tools don’t map cleanly onto controls written before shared-responsibility models existed.

There’s also a frustration most businesses working through the framework will recognise: the maturity goalposts keep moving. As ASD folds new attacker tradecraft into the existing levels, an organisation can maintain the same controls and still appear to regress against the framework. The new guidance separates threat-informed controls from a fixed maturity ladder to fix that.

What’s replacing the ASD Essential Eight

The Essentials series is a set of separate chapters, each covering a distinct technology environment. The first chapter, Essentials for enterprise IT, is the direct successor to the current Essential Eight and is what most Australian SMBs will work against.

Further chapters are planned for operational technology and cloud environments. ASD has flagged a dedicated chapter for agentic AI systems as a possibility.

The biggest shift is philosophical. The new guidance describes the security outcome your organisation needs to achieve. How you get there is up to you. The compliance checklist approach won’t carry across as cleanly as the controls themselves do.

What the Essential Eight changes mean for your business

The Essential Eight is still the active, supported framework. It’s still what tenders, contracts and cyber insurance questionnaires reference. Depreciation is expected around mid-2027, with full retirement around mid-2028.

In the meantime, here’s what to focus on:

  • If you haven’t had a formal assessment, get one before the transition. Going in without a clear picture of where you sit is harder. A baseline assessment tells you what work is left under the Essential Eight, which maps directly to what you’ll need to do under the Essentials series.

  • Start documenting your controls against outcomes rather than ticking boxes. The new framework is outcomes-based, so the evidence you’ll need to produce shifts. “We have MFA” is a checklist answer. “We enforce phishing-resistant MFA across admin accounts, remote access and backup portals, and here’s the configuration record” is an outcomes answer. The gaps between those two positions takes time to close.

  • Run a cloud and SaaS inventory. The Essentials series treats cloud as a separate domain from enterprise IT, because shared-responsibility models mean your obligations are different to an on-premises environment. Most businesses haven’t mapped which security obligations sit with them versus the vendor. The new framework will make that gap visible.

Getting to Maturity Level 2 before the transition gives you a cleaner path into the Essentials series than starting fresh when the new guidance drops.

Windstil provides cyber security consulting for Australian businesses. Our active clients enjoy a structured, ongoing approach to Essential Eight, with clear prioritisation, consistent progress and guidance to improve their maturity over time.

Subscribe to our newsletter

  Stay informed with practical IT and cyber security insights, along with company updates, announcements, and the work we’re doing with businesses like yours.