Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

ASD to Retire the Essential Eight: What the New “Essentials” Series Means for Your Business

The Australian Signals Directorate (ASD) has confirmed it will retire the Essential Eight within the next two years and replace it with a broader, more flexible framework called the Essentials series. If your business is working toward an Essential Eight maturity level, or has been asked for one in a tender, this is the most significant change to Australia’s baseline cyber guidance since the Essential Eight launched in 2017. Here’s what’s actually changing, when, and what it means for the work you’ve already done.

Update 12 July 2026: consultation has closed

Consultation on Essentials for enterprise IT ran via the ASD Cyber Security Partnership Program portal and closed on 12 July 2026. The window to submit feedback has passed. ASD is now working through submissions from government, industry, regulators and organisations already using the Essential Eight. Nothing has changed for you operationally: the Essential Eight remains the live, supported framework, and the deprecation clock has not started.

What ASD announced

Speaking to iTnews in June 2026, Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre (ACSC) within ASD, set out the plan. The Essential Eight will remain a live, supported document for now, sitting alongside the new Essentials guidance during a transition period. ASD then expects to begin deprecating the Essential Eight in around 12 months, and to retire it entirely at around 24 months.

Crucially for anyone mid-project: ASD has been explicit that work already done on the Essential Eight is not wasted. “The investment you’ve made under the Essential Eight will still be relevant under the Essentials,” Horlyck said. ASD’s own consultation notice puts it the same way. Organisations already using the Essential Eight “can expect strong alignment with their existing controls and investments.” The controls and tools you have implemented (multi-factor authentication, patching, application control, backups and the rest) map across to the new framework rather than being thrown out.

Where the Essentials series is up to

The consultation on the first chapter closed on 12 July 2026. ASD ran it as a national consultation with government, industry, regulators and organisations that currently use the Essential Eight, so the next milestone is the publication of Essentials for enterprise IT itself, shaped by that feedback. ASD has not committed publicly to a publication date.

One detail from ASD’s consultation notice matters more than it first appears: the Essentials guidance is grounded in the Information Security Manual (ISM). That tells you the direction of travel. The ISM is a risk-based, control-catalogue document, not a checklist with a score attached. If you have been treating the Essential Eight as eight boxes to tick, the new guidance will be a harder landing than you expect. If you have been treating it as a set of risk-driven controls you can justify, it will not be.

Why the Essential Eight is being retired

The Essential Eight was first published in 2017, evolving from ASD’s “Top Four” mandatory controls from 2012. Its core limitation is structural: it was designed for on-premises enterprise IT at a time when cloud adoption was still nascent. As Horlyck put it, the Essential Eight “started before cloud was really a big thing,” and its controls don’t translate cleanly to the shared-responsibility models of cloud and SaaS environments that almost every organisation now relies on.

There’s a second, long-standing complaint the change is designed to fix: the so-called “moving goalposts” problem. Because ASD absorbed new attacker tradecraft into the existing maturity levels over time, organisations could appear to go backwards on their maturity score without their actual security posture deteriorating at all. The Essentials series decouples threat-informed controls from a fixed maturity ladder, so the bar stops shifting under your feet.

What is the Essentials series?

Rather than a single list of eight controls applied to everything, the Essentials series breaks guidance into distinct security domains, each with its own chapter. The planned chapters are:

  • Essentials for Enterprise IT: the first chapter. Consultation closed on 12 July 2026 and publication is the next step. This is the closest successor to today’s Essential Eight.
  • Essentials for Operational Technology (OT): separate guidance for industrial control systems and OT environments, where IT-style controls often don’t fit.
  • Essentials for Cloud: dedicated cloud guidance that spells out what your shared responsibility with a cloud provider actually looks like in practice, and uses controls that simply don’t exist on-premises.
  • Agentic AI (likely): Horlyck flagged that AI agents may warrant their own chapter, given the distinct identity and access requirements of non-person entities operating on networks and threats such as prompt injection that conventional controls don’t address.

The biggest philosophical shift is from prescriptive controls tied to specific technologies toward outcomes and intent. Instead of mandating a particular product behaviour, the Essentials guidance describes the security outcome you need to achieve, giving you flexibility to meet it with whatever tools fit your environment. The series draws heavily on ASD’s Modern Defensible Architecture work, with a stronger emphasis on defence in depth and protecting your “crown jewels” rather than relying on a thin security perimeter around the IT environment.

The timeline at a glance

  • 12 July 2026: consultation on Essentials for enterprise IT closed. Feedback is now with ASD.
  • Now: the Essential Eight remains the active, supported framework. Nothing you are required to do today has changed.
  • Next: ASD publishes Essentials for enterprise IT, followed by chapters for operational technology and cloud.
  • Transition period: both the Essential Eight and the Essentials are maintained as live documents simultaneously.
  • ~12 months out (from mid-2026): ASD begins deprecating the Essential Eight.
  • ~24 months out: the Essential Eight is retired as a whole.
Analyst presenting an information security framework
ASD plans to begin deprecating the Essential Eight around 12 months from mid-2026, with full retirement at about 24 months.

Should you still do the Essential Eight?

Short answer: yes. The Essential Eight is the live framework today, it is still what tenders and contracts reference, and ASD has confirmed your investment carries over. Walking away now would leave you exposed and non-compliant against the requirement that’s actually in force. The right move is to keep maturing against the Essential Eight while building your controls in a way that will transition smoothly. That is exactly what an outcomes-based approach encourages.

I will put this more bluntly than a news report would. The organisations that will feel the Essentials transition as a shock are the ones that bought a maturity score. If your evidence for application control is a screenshot and a supplier’s word, and nobody in the business can explain which risk that control exists to treat, then you do not have a control. You have an artefact. Outcome-based guidance is unforgiving of that, because it asks what you achieved rather than what you installed. The change rewards organisations that treated cyber security as a management system rather than a checklist. If your controls are tied to documented risks and outcomes, the way a proper information security management system works, you’ll map into the Essentials series with very little rework.

How this connects to ISO 27001 and ISO 42001

The direction ASD is taking (outcomes over prescriptive controls, risk-led decisions, defence in depth, guidance grounded in the ISM) is the same logic that underpins ISO 27001. An ISO 27001 information security management system already ties your controls to the risks that matter to your business and documents why each control exists, which is precisely the mindset the Essentials series is moving toward. Organisations with a mature ISMS are well-placed for the transition. If you want that thinking without a full certification project, our cyber and information security advisory work is the shorter route.

The flagged agentic AI chapter is also telling. As AI agents take on real work inside businesses, the governance questions (identity and access for non-person entities, prompt-injection risk, accountability) line up closely with ISO 42001, the new AI management system standard. Businesses adopting AI should be thinking about both security and AI governance together. For more on how those fit, see ISO 42001 and ISO 27001: how they fit together.

What you should do now

  • Keep going with the Essential Eight. It’s the current requirement and your investment carries forward. If you are not sure where you stand, an Essential Eight assessment gives you an honest maturity rating and a costed roadmap, usually inside a fortnight.
  • Document the “why” behind your controls, not just the “what.” Outcome- and risk-based records transition cleanly to the Essentials series. This is the single highest-value thing you can do in the next twelve months.
  • Map your cloud and SaaS shared responsibilities now: the Essentials series will make this explicit, and most Essential Eight programs under-cover it.
  • If you use or build AI, get ahead of governance with ISO 42001 thinking before the agentic AI guidance lands.
  • Watch for publication. The consultation has closed, so the next thing to react to is the release of Essentials for enterprise IT itself.

Frequently asked questions

Can I still comment on the Essentials consultation?

No. Consultation on Essentials for enterprise IT ran through the ASD Cyber Security Partnership Program portal and closed on 12 July 2026. Further chapters (operational technology and cloud) are still to come, so there will be future opportunities for ASD partners to contribute.

Is the Essential Eight still valid in 2026?

Yes. The Essential Eight is the active, supported framework today and remains so throughout the transition. ASD will not begin deprecating it until around 12 months out, with full retirement around 24 months out.

Will my Essential Eight work be wasted?

No. ASD has confirmed that the controls and tools you’ve invested in under the Essential Eight remain relevant under the Essentials series and will map across to the new guidance. What may not carry over is thin evidence. Controls you cannot justify against a risk will be harder to defend under outcome-based guidance than they were under a checklist.

What is replacing the Essential Eight?

A broader “Essentials” series, grounded in the Information Security Manual, with separate chapters for enterprise IT, operational technology and cloud, and likely a dedicated chapter for agentic AI. It shifts from prescriptive, technology-specific controls toward security outcomes and intent.

When does the change take effect?

Consultation on the first chapter closed on 12 July 2026 and ASD is working through the feedback. Both frameworks will then run side by side, with deprecation of the Essential Eight beginning around 12 months from mid-2026 and full retirement at around 24 months.

Plan your transition with an experienced auditor

Streamline helps Australian organisations reach their Essential Eight maturity level today and build security in a way that transitions cleanly to the Essentials series, and to ISO 27001 and ISO 42001 where they fit. You work directly with an experienced information security auditor, and your system is built around how your business actually operates. To talk it through, email hello@streamline.business or call Brisbane 07 3667 8280, Sydney 02 8315 7780 or Melbourne 03 9034 3990.

Sources: ASD / ACSC, “Consultation on evolution of Essential Eight”; iTnews, 24 June 2026. Last updated 12 July 2026.

Related: ASD has also published CI Fortify, which asks critical infrastructure operators to run isolated for three months. If you supply those operators, your access is cut in the first stages of that plan, and your own testing equipment may be the thing that defeats the isolation.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring

Filed Under: Articles Tagged With: #informationsecurity

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire