Call NowFree Quote
Cybersecurity

Cyber Security Compliance Is Changing: A Checklist for the Next Two Years

Reporting that ASD plans to retire the Essential Eight over the next couple of years is the kind of news that can trigger two unhelpful reactions: panic, or ignoring it completely. Neither is the right response. Here's a practical, low-drama checklist for what's actually worth doing over the transition period.

Know someone who needs this checklist?

Forward it to whoever handles IT, admin, or operations on your team.

✉️ Forward to Your Team

Right Now: Get Your Own House in Order

  • Document your current posture. Know what security controls you have in place today, and roughly what maturity or level they sit at. This is useful under any framework, current or future.
  • Don't pause work in progress. If you're mid-way through an Essential Eight uplift, keep going. Stopping to wait for a framework that isn't published yet helps no one.
  • Keep doing the fundamentals. MFA, patching, backups, and restricted admin privileges are good practice regardless of which framework eventually organises them.

Within the Next Few Months: Ask the Right People

  • Your cyber insurer - ask how they intend to handle the Essential Eight to Essentials transition, and whether premiums or policy terms are likely to change.
  • Clients or tenders requiring a maturity level of you - confirm whether they'll keep referencing the current framework until it's formally retired.
  • Your IT provider or vCIO - ask them to flag official ASD announcements as they happen, rather than relying on early media reporting (including this article).

Over the Next One to Two Years: Plan, Don't Predict

Once ASD publishes the actual Essentials chapters, the sensible move is to map your existing controls against the new outcome-based guidance rather than starting from zero. Budgeting for that mapping exercise as part of your IT roadmap is more useful than trying to predict specifics now, since the full framework hasn't been released.

What Not to Do

  • Don't buy a vendor's "Essentials-ready" package before ASD has published the framework. Nobody can sell a finished solution against guidance that doesn't exist yet.
  • Don't drop your current compliance posture on the assumption it's about to become irrelevant. It remains the active benchmark today.
  • Don't treat early reporting as ASD's final word. Specifics can change between an early announcement and formal publication.

Frequently Asked Questions

Do I need to do anything urgently because of the Essential Eight changes?

No. Reporting describes a transition measured in years, with both frameworks running concurrently for a period. There's no immediate action required - the value in preparing now is avoiding wasted spend later, not meeting a deadline.

What's the single most useful thing to do right now?

Document your current security posture clearly - what controls you have, at what level, and why. A clear baseline is useful regardless of which framework you're measured against later, and it's the thing most businesses don't have when a compliance requirement changes.

Should I wait for the new framework before starting any new security work?

No. Core controls like MFA, patching, backups, and restricted admin access are good practice under any framework, current or future. Waiting only delays genuine risk reduction for no compliance benefit.

How do I stay updated as ASD releases more detail?

Check ASD's own publications at cyber.gov.au periodically, and ask your IT provider to flag changes that affect your specific compliance obligations as they're formally announced.

We help Perth businesses build a practical IT and security roadmap that holds up as frameworks like the Essential Eight evolve.

IT Strategic Planning →

Want a clear view of where you actually stand?

Call 0433 087 091 for a free, no-obligation conversation about your current security posture and how to plan ahead.

Book a Free Consultation

For related reading, see Already Working Toward Essential Eight Maturity? and Why the Essential Eight Never Quite Fit Cloud-Based Businesses.

This article is based on industry media reporting of ASD's stated plans at the time of writing, and is general information only, not formal compliance or legal advice. Refer to ASD's own publications at cyber.gov.au for authoritative guidance, and consult your insurer or relevant compliance bodies directly about your specific obligations.

Share this article