Call NowFree Quote
Cybersecurity

Already Working Toward Essential Eight Maturity? What the ASD Changes Mean for You

If you've spent the last year budgeting for, and working toward, a higher Essential Eight maturity level, news that ASD plans to retire the framework can feel like the rug being pulled out from under you. It isn't - but it does mean a few things are worth checking before you keep spending on the current plan.

First, This Isn't a Reason to Stop

Industry reporting on ASD's plans describes a transition measured in years, not weeks, with the Essential Eight and the new Essentials series reportedly running side by side for a period before the older framework is formally retired. Nothing about an Essential Eight uplift becomes pointless or wasted the moment ASD makes an announcement. The controls you're implementing - MFA, patching, backups, restricted admin access - are standard security practice, not bespoke to one framework's naming convention.

What's Genuinely Uncertain Right Now

We don't yet know, and won't until ASD publishes formal guidance, whether there'll be an official way to map an existing Essential Eight maturity level onto the new framework. Without that, every business currently anchored to Essential Eight maturity levels may need to redo parts of its assessment from scratch under the new model, rather than simply translating an existing result across. That's a bigger lift than a like-for-like rename, so it's worth being realistic about the possibility when planning budgets beyond the next 12 months.

Three Things to Check Before You Spend Further

  1. Talk to your cyber insurer. Ask whether they intend to keep referencing Essential Eight maturity for policy terms until it's formally retired, and what happens once the new framework exists.
  2. Talk to any client or tender body that requires a maturity level of you. Confirm how they'll treat the transition, and whether there's flexibility if requirements shift mid-engagement.
  3. Avoid signing up to a vendor's "Essentials-ready" package right now. ASD hasn't published the framework yet, so anyone selling a finished product against it is getting ahead of the actual guidance.

What to Keep Doing

Keep progressing your current Essential Eight work. The strategies it covers map directly onto how most businesses actually get compromised, and that won't change just because the framework around them is being redesigned. If anything, businesses that are already disciplined about patching, MFA, and backups will have the easiest time adapting to whatever outcome-based guidance ASD eventually releases, since outcome-based frameworks reward good underlying practice rather than a specific checklist.

Frequently Asked Questions

Should I pause my Essential Eight uplift because of the ASD changes?

Generally no. Reporting suggests a multi-year transition with both frameworks running concurrently, and the Essential Eight remains the current benchmark referenced by insurers and clients. Pausing work to wait for a framework that hasn't been published yet means losing momentum for no real benefit.

Will my current maturity level still count under the new framework?

That's genuinely unclear at this stage. We haven't seen an official crosswalk or mapping from ASD showing how Essential Eight maturity levels might translate to the new Essentials series. Until one is published, treat your current maturity level as valid under the existing framework, not as something with a confirmed equivalent elsewhere.

What should I ask my insurer or client about this?

Ask how they plan to treat the transition: whether they'll keep referencing Essential Eight maturity until it's formally retired, whether they'll adopt the new framework once it's released, and whether there's a grace period if requirements change mid-contract.

Is it worth starting a new Essential Eight assessment now, given the framework is being retired?

Generally yes, if you don't already have one. The underlying controls it assesses (MFA, patching, backups, restricted admin privileges) are core security practices that will matter regardless of which framework organises them, and a multi-year transition window means there's no immediate reason to wait.

We help Perth businesses keep their Essential Eight uplift on track, and plan ahead sensibly as ASD's guidance changes.

IT Strategic Planning →

Mid-way through an Essential Eight uplift?

Call 0433 087 091 for a free, no-obligation conversation about where you stand and how to plan around the transition.

Book a Free Consultation

For related reading, see ASD Is Retiring the Essential Eight and Cyber Security Compliance Is Changing.

This article is based on industry media reporting of ASD's stated plans at the time of writing, and is general information only, not formal compliance or legal advice. Confirm current requirements with your insurer, client, or tender body directly, and refer to ASD's own publications at cyber.gov.au for authoritative guidance.

Share this article