If you've spent the last couple of years working toward an Essential Eight maturity level, recent industry reporting on plans from the Australian Signals Directorate (ASD) is worth knowing about. Here's what's been reported, why it's happening, and - more importantly - what it actually means for your business in the short term.
What's Been Reported
According to recent industry reporting, ASD plans to retire the Essential Eight framework and replace it with a broader "Essentials" series covering several security domains. Reported details include:
- A deprecation period beginning within around 12 months
- Full retirement of the Essential Eight within around 24 months
- Both frameworks reportedly running concurrently during the transition
- An initial Essentials series covering three chapters: Enterprise IT, Operational Technology, and Cloud
- A possible future fourth chapter addressing agentic AI
We haven't seen ASD's own formal documentation on this yet, so treat the specifics above as reported rather than confirmed in detail. We'll update this article once ASD publishes official guidance.
Why Change a Framework Businesses Have Spent Years Adopting?
The Essential Eight was designed around 2017, for a world of on-premises, domain-joined IT. Cloud and SaaS adoption has since become the norm for most small and medium businesses, and a lot of the framework's controls were never a clean fit for environments where a vendor like Microsoft owns the infrastructure layer. Reporting suggests this gap, along with confusion caused by shifting maturity level requirements over time, is a key driver behind the change.
Moving toward outcome-focused guidance rather than guidance tied to specific technologies would bring ASD's approach closer to how frameworks like NIST CSF and ISO 27001 already operate.
Does This Mean You Should Stop Working on the Essential Eight?
No. The Essential Eight remains the current, active framework, and a multi-year transition has reportedly been flagged rather than an immediate switch-off. If your business is mid-way through an uplift, or if insurers, clients, or tenders currently ask about your Essential Eight maturity, that requirement doesn't disappear today. The underlying controls - MFA, patching, restricted admin access, backups - are fundamental security practices regardless of which framework organises them, so work toward them remains worthwhile either way.
What to Actually Do Right Now
- Keep going if you're mid-assessment. Don't pause an Essential Eight uplift waiting for a framework that hasn't launched yet.
- Check with anyone who requires Essential Eight maturity of you - insurers, clients, tender bodies - on how they intend to treat the transition once Essentials is released.
- Watch for ASD's official announcement rather than acting on early reporting alone.
- Avoid rushing into any vendor pitching a finished "Essentials package" before ASD has actually published the framework.
Frequently Asked Questions
Is the Essential Eight being retired?
According to industry reporting, the Australian Signals Directorate (ASD) has flagged plans to retire the Essential Eight framework over roughly the next two years, replacing it with a broader "Essentials" series. Both frameworks are reported to run side by side during the transition, so nothing changes overnight.
What is replacing the Essential Eight?
Reporting points to a new "Essentials" series starting with three chapters covering Enterprise IT, Operational Technology, and Cloud, with a possible future chapter on agentic AI. Full details haven't been published yet, so treat specifics as subject to change until ASD releases official guidance.
Should I stop working on Essential Eight maturity now?
No. The Essential Eight remains the current, valid benchmark referenced by insurers, clients, and tenders, and a multi-year transition window has reportedly been flagged. Continuing your current uplift work is still the right move - the underlying controls (MFA, patching, backups, restricted admin access) aren't going away, even if the framework that organises them does.
Where can I get official, up-to-date information?
ASD's own publications (cyber.gov.au) are the authoritative source once the Essentials series is formally released. This article is based on industry reporting and is general information only, not a substitute for ASD's official guidance.
We help Perth businesses understand where they sit against the Essential Eight today, and how to plan ahead as ASD's guidance evolves.
Essential Eight Assessment →Not sure how this affects your business?
Call 0433 087 091 for a free, no-obligation conversation about your current security posture and what to keep an eye on.
Book a Free ConsultationFor related reading, see our guides to The Essential Eight Explained and Essential Eight and Cyber Insurance.
This article is based on industry media reporting of ASD's stated plans at the time of writing, and is general information only, not formal compliance or legal advice. Details may change before ASD publishes official guidance - refer to ASD's own publications at cyber.gov.au for authoritative, up-to-date information.