Cyber Security · June 2026 · 5 minute read
The Essential Eight is being retired. Here’s what that actually means for your business.
If you’ve spent any time around Australian cyber security in the past few years, you’ve probably heard of the Essential Eight. It’s the Australian Signals Directorate’s (ASD) baseline set of eight strategies for protecting your business from cyber threats — things like patching software, multi-factor authentication, and restricting who can install programs on your computers.
On 24 June 2026, ASD confirmed it’s retiring the Essential Eight over the next two years and replacing it with a new framework called the Essentials series. If you’ve never heard of the Essential Eight, this might not seem like big news. But if your business has been working towards it — or if a client, insurer, or government tender has ever asked about your “E8 maturity level” — it’s worth five minutes to understand what’s changing.
What’s actually happening
According to Chris Horlyck, ASD’s Head of Cyber Security Resilience, the plan looks like this:
- Right now: the Essential Eight remains the active, supported framework. Nothing changes immediately.
- The next 12 months or so: ASD begins gradually deprecating the Essential Eight while the new Essentials series is rolled out alongside it.
- Around 24 months from now: the Essential Eight is retired completely.
The replacement — the Essentials series — will be broader than the old model. Rather than one fixed checklist, it’s being built as a set of separate chapters covering different parts of a modern business: enterprise IT first, then cloud and operational technology, with artificial intelligence likely to get its own chapter down the track.
Why is this happening?
The short answer: the Essential Eight was built in 2017, for a world that looked very different to 2026.
Back then, most businesses ran everything on their own servers, in their own office. Cloud computing was still a “nice to have” for a lot of companies. Today, as ASD itself put it, a business without any cloud services would be the unusual one.
There’s also a fairness issue. The Essential Eight was designed with one fixed bar for everyone to clear, regardless of size. A 500-person financial firm and a 15-person accounting practice were being measured against the same checklist — even though the financial firm has an IT team and budget the accounting practice could never match. Industry voices have pointed out that several of the old controls were realistically built for larger organisations, and were genuinely difficult for small and medium businesses to implement in a way that was actually cost-effective.
The new Essentials series is meant to fix that — shifting away from “tick every box the same way” towards a more flexible, outcomes-based approach that still gets you to a secure result, without forcing a 15-person business to behave like a 500-person one.
What this means if you’re a small or medium business
This is not a reason to relax on cyber security, and it’s not a reason to panic either.
A few things worth knowing:
The work you’ve already done still counts. ASD has confirmed that controls and tools you’ve put in place under the Essential Eight — multi-factor authentication, regular patching, restricted admin access, backups — remain relevant under the new framework. None of that becomes wasted effort.
Nothing changes today. The Essential Eight is still the active standard right now, and will be for some time yet. If you’re partway through lifting your maturity level, there’s no reason to stop or wait and see.
The new framework is likely to be a better fit for businesses your size. If you’ve ever looked at the Essential Eight and felt like some of it was written for a much bigger organisation than yours, the Essentials series is explicitly trying to solve that problem — built around real-world business context rather than a one-size-fits-all checklist.
This is a multi-year transition, not an overnight switch. Full retirement of the Essential Eight isn’t expected for roughly two years, and the first chapter of the replacement (covering everyday business IT) is still in public consultation as of mid-2026. There’s no final published version yet to act on.
What should you actually do right now?
If cyber security has been on your “get around to it eventually” list, this is a good moment to actually get started — not because the rules are changing, but because the basics (MFA, patching, backups, restricting who can install software) protect your business regardless of which framework they sit under.
If you’re already working on Essential Eight controls, keep going. Stopping now because “it’s being replaced anyway” would be a bit like deciding not to wear a seatbelt because car safety standards are due for an update — the actual risks to your business haven’t gone anywhere.
And if you’re not sure where your business currently stands, that’s exactly the kind of conversation we have with clients every day. We can give you a clear, plain-English picture of your current security posture, what’s genuinely worth prioritising for a business your size, and how to build towards good practice without paying for enterprise-grade complexity you don’t need.
Want to know where your business stands?
Get in touch for a no-pressure conversation about your IT security — no jargon, no scare tactics, just a clear picture of where you’re at.
Get in touchSources: ASD/ACSC consultation on the Essentials for Enterprise IT series, with public submissions open until 12 July 2026 via the ACSC Partner Portal. Reporting on the announcement via iTnews (24 June 2026) and the Australian Cyber Security Magazine.