Essential Eight to Essentials: a transition tracker
ASD has announced an evolution of the Essential Eight into a new Essentials series, starting with Essentials for enterprise IT. This page tracks what ASD has published against what has only been reported. The difference is being lost, and it changes what you should do.
Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).
On this page 6 sections
This page tracks one question about the Essential Eight: what ASD's proposed Essentials series changes, and when.
The short version
ASD has announced an evolution, not a retirement. ASD has published no deprecation or retirement date for the Essential Eight.
If you have read that the Essential Eight is being retired by 2028, that figure traces to a single media interview rather than to anything ASD has published. It may well prove accurate. It is not, today, a published timeline, and it does not belong in a compliance document as though it were one.
Nothing has changed operationally. The Essential Eight Maturity Model of November 2023 is still the current release, and every obligation (PSPF, DISP, SOCI, the state policies) still points at it.
What ASD has actually published
One item, on 15 June 2026: Consultation on evolution of Essential Eight. In ASD's words:
The proposed evolution introduces a new Essentials series, expanding the current framework to give organisations greater flexibility in how they implement cyber security, while still providing a clear path to achieving strong cyber resilience.
Grounded in the Information Security Manual (ISM), the new Essentials guidance will offer prioritised, threat-informed mitigations for contemporary technology environments, supported by practical tools and clear implementation guidance. Organisations already using the Essential Eight can expect strong alignment with their existing controls and investments, while new adopters will benefit from established best-practice guidance. The evolution of the current Essential Eight guidance will form the first chapter of the series – Essentials for enterprise IT – with additional chapters to follow.
Consultation ran via the ASD Cyber Security Partnership Program portal and closed on 12 July 2026.
That is the entirety of ASD's published position. The words "retire" and "deprecate" do not appear in it. Neither does any date beyond 12 July 2026.
What has only been reported
On 24 June 2026, iTnews reported comments from Chris Horlyck, Head of Cyber Security Resilience at ASD's ACSC:
Then we will look to, probably in 12 months, start to deprecate the Essential Eight, and then in 24 months we'll retire the Essential Eight as a whole.
He also described an overlap: "We anticipate that there will be a transition period where we will keep the Essential Eight a live document and the Essentials a live document."
The same reporting gives a chapter sequence: enterprise IT, then operational technology, then cloud, with agentic AI flagged as possible. None of that sequence appears on any ASD page.
This is a senior official describing intent, and it is worth planning around. It is not a publication, it carries no commencement instrument, and the difference matters if you are writing it into a risk register or a tender response.
The sourcing is thin. The most substantial trade coverage of the consultation (the Australian Computer Society's Information Age, 25 June 2026) describes ASD as having floated an update for comment and gives no deprecation or retirement dates at all. The two-year timeline appears to rest on that single iTnews interview.
Meanwhile the vendor commentary has hardened in the other direction. Pages published since June now assert the retirement as settled fact in their titles: "The Essential Eight is Being Retired", "The E8 Is Dead". If you are reading one of those, check what it cites.
Why an evolution was coming anyway
Two things in ASD's recent output point the same way.
The Essential Eight was never designed for the environment most organisations now run. ASD says so directly in the maturity model: the Essential Eight "has been designed to protect organisations' internet-connected information technology networks", and while its principles may be applied to enterprise mobility and operational technology, "it was not designed for such purposes". Cloud, SaaS and identity, where most of the risk now sits, are outside the frame the 2017 strategies were drawn in.
ASD has already published the layer above it. The Foundations for modern defensible architecture, updated October 2025, describe themselves as "a structural framework upon which to implement ASD's ISM and ASD's Essential Eight Maturity Model". There are ten foundations:
- Centrally managed identities
- High confidence authentication
- Contextual authorisation
- Asset inventory
- Secure endpoints
- Reduced attack surface
- Resilient networks
- Secure-by-Design
- Validation and assurance
- Continuous monitoring
The stack ASD is describing runs: ISM principles at the strategic layer, the MDA Foundations at the architecture layer, and ISM controls plus the Essential Eight at the practical controls layer. An ISM-grounded Essentials series is the natural next step in that structure rather than a reversal of it.
The November 2023 update already pointed this way. ASD said it had "adopted language from mapped controls within the Information security manual (ISM)" to "ensure consistency between the two publications" and to let the ISM's OSCAL baselines for the Essential Eight be ingested automatically by compliance tooling. The grounding in the ISM began with that November 2023 release, not with the 2026 consultation.
What to do now
Keep going. ASD's own line is that organisations already using the Essential Eight "can expect strong alignment with their existing controls and investments". Its architecture guidance goes further: "An organisation that works towards implementing a higher maturity level of ASD's Essential Eight will be well placed to adopt future guidance for achieving modern defensible architecture."
Do not write the 2028 date into anything binding. If a tender response, a board paper or a risk register needs a date, cite the consultation and its closing date, and attribute the deprecation timeline to the interview it came from. Anything else is asserting a timeline ASD has not set.
Expect the ISM to matter more, not less. If the Essentials series is grounded in the ISM, the organisations that already understand their ISM control coverage will have less to redo. That is doubly true if you build software, where the ISM has always carried the requirements the Essential Eight does not.
Treat "we're waiting for the new framework" as a red flag. The tradecraft the Essential Eight mitigates has not paused for the consultation. ASD's Annual Cyber Threat Report 2024–2025 records over 120 incidents involving attacks on edge devices in FY2024–25. 96% of them were successful.
Changelog
| Date | What happened | Source |
|---|---|---|
| 25 August 2026 | Page last checked. The consultation notice is still stamped "Last updated: 15 Jun 2026" — unchanged since the day it went up — and no draft or final Essentials publication exists. The Essential Eight Maturity Model still reads November 2023. | cyber.gov.au |
| 12 July 2026 | Consultation on Essentials for enterprise IT closed. | ASD |
| 24 June 2026 | iTnews reports ASD intends to deprecate the Essential Eight in ~12 months and retire it in ~24 months. Media report, not an ASD publication. | iTnews |
| 15 June 2026 | ASD announces consultation on the evolution of the Essential Eight into an Essentials series. | ASD |
| 27 November 2023 | Essential Eight Maturity Model updated — the current release. 48-hour patching introduced, phishing-resistant MFA pulled forward to Level Two, centralised logging added at Level Two, macro execution logging removed. | ASD |
We check this page against cyber.gov.au and update the date at the top whether or not anything has changed, so an old date means we have stopped looking rather than that nothing has happened.
Sources
- ASD — Consultation on evolution of Essential Eight — Published and last updated 15 June 2026
- ASD — Information Security Manual — June 2026 release
- ASD — Essential Eight maturity model — Last updated 27 November 2023
- iTnews — ASD to retire Essential Eight cyber security framework within next two years — 24 June 2026 — secondary source, see below
- ACS Information Age — ASD overhauls Essential Eight cybersecurity guidance — 25 June 2026 — secondary source; gives no retirement date
- ASD — Foundations for modern defensible architecture — Last updated 23 October 2025
Common questions
Has ASD retired the Essential Eight?
No. As at 25 August 2026 the Essential Eight Maturity Model of November 2023 remains the current, published framework, and every existing obligation still points at it. ASD has announced a consultation on evolving the Essential Eight into a new Essentials series, and that consultation closed on 12 July 2026. No draft or final Essentials publication has been released.
Is it true the Essential Eight will be retired by 2028?
That claim comes from a media interview, not from ASD's own publications. ASD's published language is "evolution", and ASD has published no deprecation or retirement date. In an iTnews interview on 24 June 2026, ASD's Head of Cyber Security Resilience said ASD would "probably in 12 months, start to deprecate the Essential Eight, and then in 24 months we'll retire the Essential Eight as a whole", and described a transition period where both documents stay live. That is a useful signal of intent from a senior official, but it is not a published timeline, and it should not be treated as one in a compliance document.
Should we pause our Essential Eight work until the Essentials series lands?
No. Every current obligation still references the Essential Eight, ASD says organisations already using it "can expect strong alignment with their existing controls and investments", and ASD's own architecture guidance states that an organisation working towards a higher Essential Eight maturity level "will be well placed to adopt future guidance". Pausing means carrying the risk the controls exist to mitigate, for a framework change with no published date.
What is the Essentials series?
ASD describes it as an expansion of the current framework, grounded in the Information Security Manual, offering "prioritised, threat-informed mitigations for contemporary technology environments, supported by practical tools and clear implementation guidance". The first chapter is Essentials for enterprise IT, with further chapters to follow. ASD has not published the chapter list; a reported sequence of enterprise IT, operational technology, cloud and possibly agentic AI comes from media reporting only.
Read next
-
Essential Eight requirements matrix
What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.
-
The Essential Eight will not secure the software you ship
Every one of the 108 software development controls in the Information Security Manual is tagged "Essential 8: N/A". The Essential Eight says nothing about how you build software. It still binds you in four specific ways, and something else governs the code itself.
Essential Eight
Need this assessed rather than explained?
We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.