Back to Resources

The Essential Eight Is Being Retired: What Compliance Leaders Need to Know Now

By Manuel Salazar, Director of Cyber Services, Orro

Over the past fortnight, I have had close to the same conversation with four different clients, across four different sectors. Someone on the compliance or risk team has seen a headline about the Essential Eight being retired, and the question that follows is always some version of the same thing: does this mean we can stop doing the work?

The short answer is no. The longer answer is worth setting out properly, because the announcement itself is being reported accurately in most places, but it is still being misread in ways that could lead organisations to pause work they should continue.

What actually changed on 24 June

On 24 June 2026, the Australian Signals Directorate confirmed it intends to retire the Essential Eight within the next two years. Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre within ASD, set out the reasoning publicly: the framework is being replaced, not scrapped in place, by a broader body of guidance called the Essentials series.

The first chapter, Essentials for Enterprise IT, is the direct evolution of the current Essential Eight. ASD opened national consultation on that chapter on 15 June 2026 through the Cyber Security Partnership Program portal, and submissions closed on 12 July 2026. Further chapters covering cloud and operational technology are expected to follow, with agentic AI flagged as a domain under consideration. As of this writing, ASD has not yet published findings from that consultation, so the detail of what the finished Essentials for Enterprise IT chapter will require is still to come.

Industry commentary has attached rough timing to the transition: deprecation of the Essential Eight beginning around the 12-month mark and full retirement around 24 months, with both frameworks live and supported in the meantime. That is a reasonable read of ASD’s public statements, but it is worth being precise: ASD has committed to retiring the Essential Eight “within the next two years”, not to a fixed date. Treat the two-year figure as an outer boundary, not a countdown clock.

The eight controls have not moved

Here is the part that gets lost in the headlines. The eight mitigation strategies themselves have not changed since ASD’s last structural update in November 2023: patching applications, patching operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening, and regular backups. They remain exactly what insurers, government tenders, and assessors are measuring organisations against today.

That matters practically for the sectors we work with most. Government agencies are still required to demonstrate Essential Eight maturity under the Protective Security Policy Framework. Financial services clients are still fielding Essential Eight questions in due diligence and supply chain assessments. Mining and manufacturing clients bidding into government and enterprise contracts are still being asked for maturity evidence as a condition of tender. None of that changes on 24 June, on 12 July, or on any date announced so far.

Evidence Snapshot

AUD $4.26 million. The average cost of a data breach in Australia, a record high and a 27 percent increase since 2020, according to IBM’s Cost of a Data Breach report. The controls underneath the Essential Eight exist to reduce exactly that kind of cost, and that logic does not change because the framework carrying them gets a new name.

Answering the only question that matters

If you are partway through an Essential Eight maturity uplift, keep going. ASD has been explicit that existing compliance work forms the foundation of the Essentials series rather than being set aside by it. Controls and tooling invested in under Maturity Level One or Two carry forward. There is no scenario in the current guidance where that work becomes wasted effort.

If you have not started, the retirement announcement is not a reason to wait for the Essentials series to land before beginning. Essential Eight guidance, current today, is what your insurer, your tenderer, or your board will ask about between now and whenever the transition actually completes. Starting now against the framework in force, rather than waiting for a framework that has not yet been published, is the lower-risk path by a wide margin.

Where the real work is now

The practical shift for compliance and risk leaders is less about the framework label and more about how the work gets governed. Treat Essential Eight maturity as a continuous discipline rather than a point-in-time assessment, because ASD’s own language is pointing toward a prioritised, threat-informed, outcomes-based approach. When the Essentials for Enterprise IT chapter is finalised, organisations that have built ongoing validation into their programme will absorb the change with far less disruption than those treating maturity as a box ticked once a year.

The takeaway for compliance leaders is simple: do not stop, do not wait, and do not treat the retirement announcement as permission to defer control uplift. Keep using the Essential Eight as the minumum today, while preparing your governance model for a broader, more continuous Essentials series tomorrow.

That is the conversation we are having with clients right now: keep the current programme moving, build the governance habit that continuous validation requires, and treat the Essentials series as an evolution to plan for rather than a reason to pause. If you want a clear-eyed view of where your current maturity sits and what the transition means for your specific environment, our Compliance and Assurance team can walk through it with you, supported by ongoing validation through our Continuous Threat Exposure Management service.

For the practical side of both compliance shifts, see the companion readiness guide.