I have spent the better part of my 25 year IT career watching frameworks come and go. This one’s different. I’ve watched the Essential Eight become the default answer to “are you doing enough,” the topic every questionnaire and every cyber insurance provider
eventually asks about. Now ASD has confirmed it’s being retired within the next two years.
If you have spent the last few years working towards Essential Eight maturity, responding to security questionnaires, or preparing for cyber insurance renewals, that sentence probably just made your stomach drop a little. I get it.
Here is the clarification you are looking for. Your maturity uplift, your questionnaire responses, your insurance renewal prep, none of that is wasted.
Why is ASD retiring the Essential Eight?
The Essential Eight was built for a world of owned infrastructure. Today, your business almost certainly runs on cloud platforms, SaaS tools, and shared responsibility models the original framework never accounted for.
When the Essential Eight was introduced, a typical business owned its servers, ran its own infrastructure, and had a fairly contained environment to secure. That world has largely gone. Your team is most likely running Microsoft 365, a handful of SaaS platforms, and some operational technology that none of those eight strategies were ever designed to address.
ASD has been upfront about this. The framework remains valuable, but it was never built to flex around cloud first architecture, AI tools, or the shared responsibility arrangements that now sit underneath most business technology. So instead of patching an ageing model, they are replacing it with something broader, called the Essentials series.
The new guidance will be grounded in ASD’s Information Security Manual and will be built around outcomes rather than a fixed checklist. In plain terms, it asks what you are protecting and why, rather than handing you eight boxes to tick. The first chapter, Essentials for Enterprise IT, is in consultation from June to July 2026, with cloud, operational technology, and eventually AI expected to follow as separate chapters.

What happens to the work you have already put in?
ASD has said existing Essential Eight investments will carry strong alignment into the new framework. Multifactor authentication, patch management, application control, privileged access management, and backups are not going anywhere.
Did you just waste a year on a framework that’s about to disappear? No.
Think of it like a version upgrade. Windows 10 becoming Windows 11 didn’t wipe your files or undo your work, the interface changed, the substance underneath carried over. Same principle here.
ASD has confirmed a transition period where both frameworks run side by side, and organisations already through Essential Eight maturity levels are carrying that work forward, not starting again.
What is the actual timeline?
- Consultation on Essentials for Enterprise IT, June to July 2026
- New Essentials framework introduced, expected during 2026
- Essential Eight deprecation begins, approximately 12 months from introduction (from 2027)
- Full retirement of the Essential Eight, approximately 24 months from introduction (from 2028)
Children’s Hospital Foundation is a good example of why this matters in practice. They came to ONGC with little visibility over their cyber security posture and a mix of internal and external IT support. They worked through a 12 month roadmap aligned to the Essential Eight to reach compliance with the Privacy Act and the SOCI Act.
None of that work becomes irrelevant because the framework’s name is changing. It becomes the foundation the next chapter builds on.
What should you do next?
Keep going. If you are mid uplift, finish it. If you have not started, the Essential Eight is still the right place to begin, and the transition period gives you time to adjust as the Essentials series rolls out.
A few organisations have asked whether it makes sense to pause and wait for the new framework to land. I would not recommend it. The Essential Eight is still ASD’s recommended baseline today, and everything coming will build on it rather than replace it outright. Waiting just means you enter the next phase further behind than you needed to be.
What this announcement does signal is where your attention should start shifting. Endpoint hardening and patch cycles are not going away, but cloud security, identity, SaaS governance, and eventually AI risk are becoming first-class considerations rather than side conversations. If your current program stops at the eight original strategies, that is worth a second look.
This is also where working with a cyber security managed services provider earns its keep. Keeping pace with a framework that is actively evolving, while running a business, is a lot to carry on top of your day job. A managed cyber security services partner tracks the ASD guidance so you do not have to, and folds it into what your business is already doing rather than handing you a separate project to manage.

The Bottom Line
The Essential Eight is not failing, it is being outgrown by a threat landscape it was never built to cover. If you have been doing the work, that work still counts. If you have not started, today is still a good day to begin.
The framework’s name is changing. What it is protecting you from is not.
If you are still weighing up where your business sits, the next step is a straightforward look at where your current work stands and where the gaps are likely to show up as the Essentials series rolls out.
Whether you are already working with ONGC or considering it for the first time, if you want a clearer picture of where your business sits against the current framework, and where the gaps are likely to show up as the Essentials series rolls out, explore cyber security consulting services with ONGC’s team.
