Small business cyber safety
The Essential Eight Is Evolving: What ASD Has Published So Far
ASD has proposed a broader Essentials series, beginning with an evolution of the Essential Eight. The current Essential Eight remains recommended guidance.
In June 2026, the Australian Signals Directorate announced consultation on a proposed Essentials series. ASD describes it as an expansion of the current framework, designed to give organisations greater flexibility while maintaining a clear path towards stronger cyber resilience. [1]
The official announcement uses the language of evolution, not immediate replacement. It says the evolution of the current Essential Eight guidance will become the first chapter of the series and that existing Essential Eight controls and investments should remain strongly aligned. [1]
The short version
Keep implementing the Essential Eight while the proposed guidance is developed. Cyber.gov.au still recommends the eight mitigation strategies as a baseline, and ASD says organisations can expect strong alignment with their existing controls and investments. [1] [2]
What is changing?
The biggest published change is the structure. The Essential Eight is one baseline built around eight mitigation strategies. ASD proposes a series of chapters, with the evolution of the current guidance forming the first chapter: Essentials for enterprise IT. Additional chapters are planned, but the official announcement does not name or describe them. [1]
From a fixed list towards a broader series
The proposed series is grounded in ASD’s Information Security Manual and is described as prioritised, threat-informed guidance for contemporary technology environments. ASD says it will be supported by practical tools and clear implementation guidance. [1]
ASD also says the series is intended to provide greater flexibility in how organisations implement cyber security. The public announcement does not yet provide the final requirements or explain how organisations will be assessed under the first chapter. [1]
Why is the Essential Eight changing?
ASD says the consultation is intended to help its guidance keep pace with emerging threats and advances in defensive capabilities. It describes the proposed series as guidance for contemporary technology environments. [1]
The consultation included government, industry, regulators and organisations already using the Essential Eight. ASD says that feedback will help shape the future development of the series. [1]
What has not changed
- The Essential Eight is still current guidance. Cyber.gov.au continues to recommend it as a baseline. [2]
- Existing work still matters. ASD says organisations using the Essential Eight can expect strong alignment with their current controls and investments. [1]
- The underlying risks remain. Unpatched systems, weak sign-in, excessive administrator access, unsafe applications and untested backups still create opportunities for attackers.
- There is no overnight cutover. The new series is being developed progressively, beginning with enterprise IT.
Has ASD published a retirement date?
No retirement date appears in ASD’s public consultation announcement. It says consultation on Essentials for enterprise IT ran until 12 July 2026, but it does not publish a final release date or a timetable for retiring the Essential Eight. [1]
Until ASD publishes further guidance, the factual position is simple: the Essential Eight remains the baseline recommended on Cyber.gov.au. [2]
What should a small business do now?
- Do not pause Essential Eight work. Continue patching, strengthening sign-in, limiting administrator access, controlling applications and testing backups.
- Record what is actually in place. Ask for evidence rather than a simple “compliant” label: patch reports, MFA coverage, administrator lists, backup test results and exceptions that still need attention.
- Map your technology environments. Note which services are on business devices, in Microsoft 365 or Google Workspace, in other cloud services, or managed by an outside provider.
- Clarify shared responsibility. A cloud provider may secure the platform while your business remains responsible for user access, configuration, data and recovery choices.
- Watch the official source. When the new chapter is published, compare it with your current controls instead of starting from zero.
Five questions to ask your IT provider
- Which Essential Eight maturity level are we working towards, and why is it proportionate for this business?
- Can you show which controls are fully implemented, partly implemented or not applicable?
- Which of our services are cloud-based, and who is responsible for each security setting?
- How are exceptions recorded when a device, application or business process cannot meet the normal control?
- Who will review the new Essentials guidance and explain what genuinely needs to change?
A useful answer should include evidence, limitations and next actions. A badge or maturity claim without that detail tells an owner very little about the real security position.
Sources and further reading
Frequently asked questions
Is the Essential Eight already obsolete?
No. Cyber.gov.au still presents it as a recommended baseline, and ASD says existing controls and investments should align strongly with the proposed new series.
Will the eight controls disappear?
ASD says the current guidance will evolve into the first chapter of the Essentials series and that existing controls and investments should remain strongly aligned. It has not yet published the final chapter or detailed how individual controls will be presented.
Should a microbusiness aim for the highest maturity level now?
Not automatically. The target should reflect the business’s risks, systems, customers and obligations. The immediate priority is to understand the current position, close serious gaps and ask for evidence behind any maturity claim.