Back to Resources

The Essential Eight Is Being Retired: What Compliance Leaders Need to Know Now

By Manuel Salazar, Director of Cyber Services, Orro

Over the past fortnight I’ve had close to the same conversation with four different clients, across four different sectors. Someone on the compliance or risk team has seen a headline about the Essential Eight being retired, and the question that follows is always some version of the same thing: does this mean we can stop.

The short answer is no. The longer answer is worth setting out properly, because the announcement itself is being reported accurately in most places and misread anyway.

What actually changed on 24 June

On 24 June 2026, the Australian Signals Directorate confirmed it intends to retire the Essential Eight within the next two years. Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre within ASD, set out the reasoning publicly: the framework is being replaced, not scrapped in place, by a broader body of guidance called the Essentials series.

The first chapter, Essentials for Enterprise IT, is the direct evolution of the current Essential Eight. ASD opened national consultation on that chapter on 15 June 2026, running through the Cyber Security Partnership Program portal, and closed submissions on 12 July 2026. Further chapters covering cloud and operational technology are expected to follow, with agentic AI flagged as a domain under consideration. As of this writing, ASD has not yet published findings from that consultation, so the detail of what the finished Essentials for Enterprise IT chapter will actually require is still to come.

Industry commentary has attached rough timing to the transition: deprecation of the Essential Eight beginning around the 12-month mark, full retirement around 24 months, with both frameworks live and supported in the meantime. That timing is a reasonable read of ASD’s public statements, but it is worth being precise that ASD itself has committed to “within the next two years,” not a fixed date. Treat the two-year figure as an outer boundary, not a countdown clock.

The eight controls have not moved

Here is the part that gets lost in the headlines. The eight mitigation strategies themselves, patching applications, patching operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening, and regular backups, have not changed since ASD’s last structural update in November 2023. They remain exactly what insurers, government tenders, and assessors are measuring organisations against today.

That matters practically for the sectors we work with most. Government agencies are still required to demonstrate Essential Eight maturity under the Protective Security Policy Framework. Financial services clients are still fielding Essential Eight questions in due diligence and supply chain assessments. Mining and manufacturing clients bidding into government and enterprise contracts are still being asked for maturity evidence as a condition of tender. None of that changes on 24 June, on 12 July, or on any date announced so far.

Evidence Snapshot

AUD $4.26 million. The average cost of a data breach in Australia, a record high and a 27 percent increase since 2020, according to IBM’s Cost of a Data Breach report. The controls underneath the Essential Eight exist to reduce exactly that kind of cost, and that logic does not change because the framework carrying them gets a new name.

Answering the only question that matters

If you are partway through an Essential Eight maturity uplift, keep going. ASD has been explicit that existing compliance work forms the foundation of the Essentials series rather than being set aside by it. Controls and tooling invested in under Maturity Level One or Two carry forward. There is no scenario in the current guidance where that work becomes wasted effort.

If you have not started, the retirement announcement is not a reason to wait for the Essentials series to land before beginning. Essential Eight guidance, current today, is what your insurer, your tenderer, or your board will ask about between now and whenever the transition actually completes. Starting now against the framework in force, rather than waiting for a framework that has not yet been published, is the lower-risk path by a wide margin.

Where the real work is now

The practical shift for compliance and risk leaders is less about the framework label and more about how the work gets governed. Treat Essential Eight maturity as a continuous discipline rather than a point-in-time assessment, because that is the direction ASD’s own language, prioritised, threat-informed, outcomes-based, is pointing. When the Essentials for Enterprise IT chapter is finalised, organisations that have built ongoing validation into their programme will absorb the change with far less disruption than those treating maturity as a box ticked once a year.

That is the conversation we are having with clients right now: keep the current programme moving, build the governance habit that continuous validation requires, and treat the Essentials series as an evolution to plan for rather than a reason to pause. If you want a clear-eyed view of where your current maturity sits and what the transition means for your specific environment, our Compliance & Assurance team can walk through it with you, alongside ongoing validation through our Continuous Threat Exposure Management service.

For the practical side of both compliance shifts, see the companion readiness guide.