If you've spent the last year working toward Essential Eight Maturity Level 2, there's news worth knowing: the framework itself is on its way out. In June 2026 the Australian Signals Directorate confirmed it will retire the Essential Eight over roughly the next two years, replacing it with a broader, multi-chapter framework called the Essentials series.
Why ASD is replacing it
Essential Eight was built in 2017 for a mostly on-premises, Windows-centric world. Since then, cloud platforms, software-as-a-service, hybrid work and now AI-enabled tools have become standard in almost every Australian business — and ASD has acknowledged the original eight strategies were never designed with any of that in mind. The Essentials series is structured as separate chapters by technology domain, starting with "Essentials for Enterprise IT" and expected to expand into cloud, operational technology and potentially a dedicated AI security chapter.
The timeline
Public consultation on the first chapter, Essentials for Enterprise IT, closed on 12 July 2026. From there, ASD's plan is to run Essential Eight and the Essentials series side by side for a transition period, begin deprecating Essential Eight around 12 months after the June 2026 announcement, and retire it fully at around the two-year mark.
What doesn't change, at least not yet
Essential Eight remains the live, currently supported standard right now — nothing about your existing obligations changes today. Just as importantly, ASD has been explicit that work already done toward Essential Eight maturity isn't wasted: the existing eight strategies are expected to form the foundation the Essentials series builds on, and current investment should map forward rather than needing to be redone from scratch.
What we're recommending to clients
Keep going. If you're mid-uplift toward Essential Eight Maturity Level 2, that's still the right target today, and it's still what DISP's ICT/cyber domain expects in the meantime. What we're doing differently is tracking the Essentials series drafts as they're published, so that when the final framework lands, we can map your existing controls across with minimal rework rather than starting a second uplift project from zero.
This is also a reasonable moment to make sure your cyber program isn't built purely around the Essential Eight's eight named strategies, but around the underlying risks they address — because that's the part that will carry forward regardless of which document ASD is asking you to evidence against.