Security

The Essential Eight Is Being Retired — What That Actually Means for Your Business

In June 2026 the Australian Signals Directorate announced its flagship Essential Eight framework will be retired within about two years, replaced by a new “Essentials” series. If you've been told to “get Essential Eight compliant,” here's what's genuinely changing — and what hasn't changed at all yet.

If you run a business in Australia and have looked into cyber security at all, you've met the Essential Eight — the ASD's list of eight baseline mitigation strategies that's been the de facto national standard since 2017. So the June 2026 announcement that it's being retired understandably raised the question: does that mean everything I've been told to do is now wrong?

Short answer: no. But there's a real change coming, and it's genuinely good news for small businesses specifically. Here's the honest picture, current as of writing.

What was actually announced

On 15 June 2026, the ASD opened a national consultation on evolving the Essential Eight into a new Essentials series. The consultation on its first chapter — "Essentials for enterprise IT" — ran until 12 July 2026. According to the ACSC, the plan is to begin deprecating the Essential Eight roughly a year out and retire it fully within about two years, phasing in the new guidance during the transition.

The stated reasoning is worth understanding, because it explains why the change matters for smaller businesses:

  • The Essential Eight was designed around conventional threats — malware, phishing, privilege escalation — and predates the current AI-accelerated threat landscape.
  • Several of its controls implicitly assume an organisation with a real IT team and enterprise budget — a poor fit for the small and medium businesses that make up most of the economy.
  • In practice, many organisations have treated it as a box-ticking compliance exercise rather than a genuine, risk-based security program.

The new series is intended to be more flexible, more threat-informed, and explicitly more workable for organisations that aren't large enterprises — while still mapping cleanly onto what existing Essential Eight adopters already have in place.

The single most important thing to understand right now: nothing you're obliged to do today has changed. The Essential Eight, its Maturity Model, and its assessment process are all still published, still current, and still the standard that government contracts, cyber insurers, and enterprise security reviews reference. What ASD has put out is a proposal being consulted on — the final control set and its regulatory standing haven't been published. Don't stop implementing the Essential Eight on the strength of the announcement.

What this means depending on where you're at

If you've already invested in Essential Eight compliance

Your investment is safe. ASD has been explicit that existing adopters can expect strong alignment between their current controls and the new framework — the tools and platforms you've put in place are expected to map across. This is an evolution, not a teardown. Keep going.

If you were about to start

Still start — with the Essential Eight, now. It remains the live standard, the transition is measured in years, and everything you implement maps forward. Waiting for the new series to be finalised would mean doing nothing about security for a year or more, which is a far worse position than implementing today's baseline.

If you're a small business that always found the Essential Eight a bit much

This is the good news. The whole direction of the change is toward something more practical and cost-conscious for exactly your situation. In the meantime, the reality that gets lost in the framework debate is that the highest-impact controls were always the achievable ones anyway.

What actually matters, regardless of the framework name

Frameworks come and go; the fundamentals underneath them barely move. Whatever the guidance ends up being called, the controls that do most of the heavy lifting for a small business are the same, and most are free or nearly so:

  • Multi-factor authentication on everything, starting with email — and ideally phishing-resistant MFA like passkeys where you can. This single step stops the large majority of account-takeover attacks.
  • Keep software and operating systems patched. Automatic updates where possible; unpatched software is one of the most common ways in.
  • Regular, tested backups that are kept isolated enough that ransomware can't encrypt them too. Untested backups are just hope.
  • Restrict administrative privileges — not everyone needs to be an admin, and every admin account is a bigger prize for an attacker.
  • Staff awareness of the actual threats, particularly the invoice and payment-redirection fraud covered in our Business Email Compromise guide, which no technical control fully prevents.

Notice these are, almost verbatim, the most impactful parts of the Essential Eight — and they'll be the backbone of whatever replaces it, because they're what actually works. Getting these right is time far better spent than worrying about which framework document is current.

The bottom line: the Essential Eight is being retired, but slowly, and its replacement is aimed at making baseline security more achievable for small businesses, not less. Right now it remains the live standard — so keep implementing it, focus on the high-impact fundamentals that will carry across regardless, and treat the framework change as a signal that help for smaller organisations is coming, not as a reason to pause.

Frequently asked questions

Is the Essential Eight still valid in 2026?

Yes. Despite the announced retirement, the Essential Eight, its Maturity Model, and its assessment process remain published, current, and the standard referenced by government contracts, cyber insurers, and security reviews. Nothing an organisation is obliged to do today has changed.

What is replacing the Essential Eight?

A new "Essentials series," starting with a chapter on enterprise IT, with operational technology and cloud chapters expected to follow. It aims to be more flexible, more threat-informed, and more practical for smaller organisations, while mapping cleanly onto existing Essential Eight controls.

When will the Essential Eight be retired?

Based on ACSC statements, deprecation is expected to begin roughly a year after the June 2026 announcement, with full retirement in about two years. The existing framework stays in place during the transition.

Should my small business wait for the new framework before acting?

No. The transition takes years, and the highest-impact controls — MFA, patching, backups, restricted admin access, staff awareness — carry across regardless of the framework's name. Waiting means leaving your business exposed for no benefit.

Not sure where your business actually stands on the fundamentals? Get in touch for a straight, no-sales-pitch assessment.

Get in touch →