Nano Solutions

Essential Eight to Essentials: a transition tracker

ASD has announced an evolution of the Essential Eight into a new Essentials series, starting with Essentials for enterprise IT. This page tracks what ASD has published against what has only been reported. The difference is being lost, and it changes what you should do.

Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).

On this page 6 sections
  1. The short version
  2. What ASD has actually published
  3. What has only been reported
  4. Why an evolution was coming anyway
  5. What to do now
  6. Changelog

This page tracks one question about the Essential Eight: what ASD's proposed Essentials series changes, and when.

The short version

ASD has announced an evolution, not a retirement. ASD has published no deprecation or retirement date for the Essential Eight.

If you have read that the Essential Eight is being retired by 2028, that figure traces to a single media interview rather than to anything ASD has published. It may well prove accurate. It is not, today, a published timeline, and it does not belong in a compliance document as though it were one.

Nothing has changed operationally. The Essential Eight Maturity Model of November 2023 is still the current release, and every obligation (PSPF, DISP, SOCI, the state policies) still points at it.

What ASD has actually published

One item, on 15 June 2026: Consultation on evolution of Essential Eight. In ASD's words:

The proposed evolution introduces a new Essentials series, expanding the current framework to give organisations greater flexibility in how they implement cyber security, while still providing a clear path to achieving strong cyber resilience.

Grounded in the Information Security Manual (ISM), the new Essentials guidance will offer prioritised, threat-informed mitigations for contemporary technology environments, supported by practical tools and clear implementation guidance. Organisations already using the Essential Eight can expect strong alignment with their existing controls and investments, while new adopters will benefit from established best-practice guidance. The evolution of the current Essential Eight guidance will form the first chapter of the series – Essentials for enterprise IT – with additional chapters to follow.

Consultation ran via the ASD Cyber Security Partnership Program portal and closed on 12 July 2026.

That is the entirety of ASD's published position. The words "retire" and "deprecate" do not appear in it. Neither does any date beyond 12 July 2026.

What has only been reported

On 24 June 2026, iTnews reported comments from Chris Horlyck, Head of Cyber Security Resilience at ASD's ACSC:

Then we will look to, probably in 12 months, start to deprecate the Essential Eight, and then in 24 months we'll retire the Essential Eight as a whole.

He also described an overlap: "We anticipate that there will be a transition period where we will keep the Essential Eight a live document and the Essentials a live document."

The same reporting gives a chapter sequence: enterprise IT, then operational technology, then cloud, with agentic AI flagged as possible. None of that sequence appears on any ASD page.

This is a senior official describing intent, and it is worth planning around. It is not a publication, it carries no commencement instrument, and the difference matters if you are writing it into a risk register or a tender response.

The sourcing is thin. The most substantial trade coverage of the consultation (the Australian Computer Society's Information Age, 25 June 2026) describes ASD as having floated an update for comment and gives no deprecation or retirement dates at all. The two-year timeline appears to rest on that single iTnews interview.

Meanwhile the vendor commentary has hardened in the other direction. Pages published since June now assert the retirement as settled fact in their titles: "The Essential Eight is Being Retired", "The E8 Is Dead". If you are reading one of those, check what it cites.

Why an evolution was coming anyway

Two things in ASD's recent output point the same way.

The Essential Eight was never designed for the environment most organisations now run. ASD says so directly in the maturity model: the Essential Eight "has been designed to protect organisations' internet-connected information technology networks", and while its principles may be applied to enterprise mobility and operational technology, "it was not designed for such purposes". Cloud, SaaS and identity, where most of the risk now sits, are outside the frame the 2017 strategies were drawn in.

ASD has already published the layer above it. The Foundations for modern defensible architecture, updated October 2025, describe themselves as "a structural framework upon which to implement ASD's ISM and ASD's Essential Eight Maturity Model". There are ten foundations:

  1. Centrally managed identities
  2. High confidence authentication
  3. Contextual authorisation
  4. Asset inventory
  5. Secure endpoints
  6. Reduced attack surface
  7. Resilient networks
  8. Secure-by-Design
  9. Validation and assurance
  10. Continuous monitoring

The stack ASD is describing runs: ISM principles at the strategic layer, the MDA Foundations at the architecture layer, and ISM controls plus the Essential Eight at the practical controls layer. An ISM-grounded Essentials series is the natural next step in that structure rather than a reversal of it.

The November 2023 update already pointed this way. ASD said it had "adopted language from mapped controls within the Information security manual (ISM)" to "ensure consistency between the two publications" and to let the ISM's OSCAL baselines for the Essential Eight be ingested automatically by compliance tooling. The grounding in the ISM began with that November 2023 release, not with the 2026 consultation.

What to do now

Keep going. ASD's own line is that organisations already using the Essential Eight "can expect strong alignment with their existing controls and investments". Its architecture guidance goes further: "An organisation that works towards implementing a higher maturity level of ASD's Essential Eight will be well placed to adopt future guidance for achieving modern defensible architecture."

Do not write the 2028 date into anything binding. If a tender response, a board paper or a risk register needs a date, cite the consultation and its closing date, and attribute the deprecation timeline to the interview it came from. Anything else is asserting a timeline ASD has not set.

Expect the ISM to matter more, not less. If the Essentials series is grounded in the ISM, the organisations that already understand their ISM control coverage will have less to redo. That is doubly true if you build software, where the ISM has always carried the requirements the Essential Eight does not.

Treat "we're waiting for the new framework" as a red flag. The tradecraft the Essential Eight mitigates has not paused for the consultation. ASD's Annual Cyber Threat Report 2024–2025 records over 120 incidents involving attacks on edge devices in FY2024–25. 96% of them were successful.

Changelog

Date What happened Source
25 August 2026 Page last checked. The consultation notice is still stamped "Last updated: 15 Jun 2026" — unchanged since the day it went up — and no draft or final Essentials publication exists. The Essential Eight Maturity Model still reads November 2023. cyber.gov.au
12 July 2026 Consultation on Essentials for enterprise IT closed. ASD
24 June 2026 iTnews reports ASD intends to deprecate the Essential Eight in ~12 months and retire it in ~24 months. Media report, not an ASD publication. iTnews
15 June 2026 ASD announces consultation on the evolution of the Essential Eight into an Essentials series. ASD
27 November 2023 Essential Eight Maturity Model updated — the current release. 48-hour patching introduced, phishing-resistant MFA pulled forward to Level Two, centralised logging added at Level Two, macro execution logging removed. ASD

We check this page against cyber.gov.au and update the date at the top whether or not anything has changed, so an old date means we have stopped looking rather than that nothing has happened.

Sources

All ASD source documents →

Common questions

Has ASD retired the Essential Eight?

No. As at 25 August 2026 the Essential Eight Maturity Model of November 2023 remains the current, published framework, and every existing obligation still points at it. ASD has announced a consultation on evolving the Essential Eight into a new Essentials series, and that consultation closed on 12 July 2026. No draft or final Essentials publication has been released.

Is it true the Essential Eight will be retired by 2028?

That claim comes from a media interview, not from ASD's own publications. ASD's published language is "evolution", and ASD has published no deprecation or retirement date. In an iTnews interview on 24 June 2026, ASD's Head of Cyber Security Resilience said ASD would "probably in 12 months, start to deprecate the Essential Eight, and then in 24 months we'll retire the Essential Eight as a whole", and described a transition period where both documents stay live. That is a useful signal of intent from a senior official, but it is not a published timeline, and it should not be treated as one in a compliance document.

Should we pause our Essential Eight work until the Essentials series lands?

No. Every current obligation still references the Essential Eight, ASD says organisations already using it "can expect strong alignment with their existing controls and investments", and ASD's own architecture guidance states that an organisation working towards a higher Essential Eight maturity level "will be well placed to adopt future guidance". Pausing means carrying the risk the controls exist to mitigate, for a framework change with no published date.

What is the Essentials series?

ASD describes it as an expansion of the current framework, grounded in the Information Security Manual, offering "prioritised, threat-informed mitigations for contemporary technology environments, supported by practical tools and clear implementation guidance". The first chapter is Essentials for enterprise IT, with further chapters to follow. ASD has not published the chapter list; a reported sequence of enterprise IT, operational technology, cloud and possibly agentic AI comes from media reporting only.

  • Essential Eight requirements matrix

    What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.

  • The Essential Eight will not secure the software you ship

    Every one of the 108 software development controls in the Information Security Manual is tagged "Essential 8: N/A". The Essential Eight says nothing about how you build software. It still binds you in four specific ways, and something else governs the code itself.

Essential Eight

Need this assessed rather than explained?

We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.