Yes, over time. In June 2026 the Australian Signals Directorate opened consultation on the Essentials series, a broader body of guidance that will replace the Essential Eight. The ACSC has said the Essential Eight will begin to be deprecated in about twelve months and be retired in about two years. ASD has not yet published fixed dates.
If your organisation is partway through an uplift, or has just been asked for a maturity level, that raises an obvious question: should you keep going? For almost everyone, the answer is yes.
What is changing
The Essential Eight was written before most organisations ran in the cloud. It is a short list of prescriptive controls for Windows-centred networks. The Essentials series is designed to cover more ground in separate chapters: enterprise IT first, then operational technology and cloud, with agentic AI under consideration. ASD describes the new guidance as prioritised and threat-informed, with more flexibility in how organisations meet each outcome.
Consultation on the first chapter, Essentials for enterprise IT, ran from 15 June to 12 July 2026 through the ACSC Partner Portal.
What stays the same
ASD has said the Essential Eight and the Essentials will both be live documents during the transition, and that the investment organisations have made under the Essential Eight stays relevant under the Essentials. The controls at the heart of the Essential Eight, which are application control, patching, restricting admin rights, multi-factor authentication, hardening and backups, remain the foundations of any defensible environment. They will not disappear from the new guidance.
Who still asks for Essential Eight levels
The obligations organisations face today are written in Essential Eight terms, and each changes on its own timeline. Commonwealth entities are required to implement the Essential Eight under the Protective Security Policy Framework. The SOCI risk management program rules list Essential Eight Maturity Level One as one of the frameworks a responsible entity can comply with. State policies, such as the NSW Cyber Security Policy, set Essential Eight targets for agencies. Government contracts, prime contractors and cyber insurers ask for maturity levels and evidence.
Until each of those is rewritten, an Essential Eight level is what you will be asked for.
What to do now
Keep going. Stopping an uplift to wait for new guidance leaves you exposed now and behind later.
Keep a record of every setting. Settings written down in one place can be mapped to a new framework far faster than settings scattered across admin consoles.
Keep evidence you can reuse. An evidence pack organised by control, rather than by the Essential Eight's wording, carries across to any framework.
Watch the contracts. When a customer, a regulator or your insurer changes its wording, that is the point to reassess.
We track the Essentials series as it is published and map our clients across when the guidance is final.
Sources: ASD's consultation notice on the evolution of the Essential Eight (cyber.gov.au), and iTnews, 24 June 2026.
Need to reach and prove an Essential Eight level? Essential Eight, done for you
All resources
