04/08/2026
If you've ever been asked about your "Essential Eight maturity level" — for a tender, a contract, or your cyber insurance — this one's for you. 👇
Australia's cyber agency (ASD) is rewriting the country's baseline security rulebook.
The Essential Eight — the framework that's shaped how Aussie businesses do cyber security since 2017 — is being evolved into a broader new set of guidance called the "Essentials series." ASD opened consultation on it in June 2026, and plans to phase the Essential Eight out over roughly the next two years.
Before anyone panics: nothing has changed yet. The Essential Eight is still the current standard, still in force, and still what you should be working to today. This is a heads-up, not an emergency.
Here's the shape of it (and these dates aren't locked — the timeline could shift):
🗓️ Now → approximately mid-2027: the Essential Eight stays fully active and is the baseline.
🗓️ ~mid-2027: ASD expects to start deprecating it — but both frameworks run side by side, so no hard cut-off.
🗓️ ~mid-2028: planned full retirement, with the Essentials series taking over.
So why the change? The Essential Eight was built back when most businesses ran on Windows computers in an office. Today you're on cloud, Microsoft 365, mobiles and apps — and the old framework was never designed for that world. The new guidance is being built for how businesses actually work now, with a big focus on cloud and login security.
The part that matters most to you: if you've already done the work, it counts. ASD has been clear the new series will align closely with the existing controls. MFA, patching, backups, limiting admin access — none of that becomes wasted effort. One nuance worth knowing: what may need reframing isn't your controls, it's how you evidence them — so keep good records.
What I'd actually do:
✅ Keep going — don't stop or wait for the new version.
✅ Lean into cloud and login security now (MFA, secure Microsoft 365 settings) — that's clearly where it's heading.
✅ Check where "Essential Eight" is named in your contracts, tenders and insurance — those may need updating down the track.
✅ Ask your IT provider if they're across it. A good one already is. If they haven't heard of it… that tells you something.
The rulebook is getting a modern update — and that's a good thing. The businesses that stay secure won't be the ones chasing a score. They'll be the ones doing the actual work underneath it.
We're tracking the ASD consultation closely to keep our Brisbane & Gold Coast clients ahead of it. Want to know where you stand right now? Book a free review at netcomp.com.au — or read the official detail at cyber.gov.au.