The Essential Eight Is Being Retired — What Australian Businesses Need to Know
· By Paul Harvey
The Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC) announced in June 2026 that the Essential Eight cyber security framework will be retired within two years and replaced by a new framework called "Essentials for enterprise IT". Mycelium 365 helps Australian businesses understand what this transition means and how to ensure their cyber security posture remains strong through the change.
What is the Essential Eight and why is it being retired?
The Essential Eight is the ASD''s prioritised set of cyber security mitigation strategies, introduced to stop the majority of cyber attacks targeting Australian organisations. It covers application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. For nearly a decade it has served as the de facto baseline for Australian government agencies, defence contractors, and enterprises seeking a defensible security posture.
ASD has said the framework is being retired because it was developed around conventional malware and relatively static threat conditions. It has become too rigid for faster-moving threats, including AI-enabled attacks, supply-chain compromise, identity-based intrusions, and rapidly shifting technology environments such as SaaS and hybrid cloud. The replacement framework will be more adaptive and threat-informed rather than a static compliance ladder that organisations climb once and then defend annually.
What is "Essentials for enterprise IT" — the replacement framework?
Based on what ASD has published so far, "Essentials for enterprise IT" is described as a set of prioritised, threat-informed mitigations rather than a static compliance ladder. National consultation on the draft framework ran until 12 July 2026, giving industry, government, and security practitioners the opportunity to shape the final structure before publication.
Importantly, ASD has signalled that the new framework is expected to align closely with existing Essential Eight controls. Organisations that have invested in implementing Essential Eight maturity — MFA, application control, patching, backups, and administrative privilege restriction — will not see that work made redundant. Instead, those controls will be reframed inside a more dynamic model that reflects modern enterprise IT.
The expected transition timeline is two years, meaning the Essential Eight remains the operative framework through 2026 and into 2027, with the replacement expected to progressively supersede it from 2028.
Does the Essential Eight still apply right now?
Yes. The Essential Eight remains fully in place during the transition period, and businesses should continue implementing and maintaining it. Government procurement requirements that reference Essential Eight maturity levels remain in effect, and Defence Industry Security Program (DISP) requirements for defence contractors are unchanged.
Organisations that treat the ASD announcement as a reason to pause their cyber security investment are making a significant risk management error. Attackers are not waiting for a new framework — ransomware, business email compromise, and identity attacks continue to escalate. Cyber insurers still ask about Essential Eight controls at renewal. Auditors and clients still request evidence of maturity.
The transition period is the time to strengthen existing controls, not relax them. Anything you implement now to satisfy Essential Eight will remain relevant when the new framework is published, because the underlying threats and mitigations do not fundamentally change.
What should Australian businesses do during the transition?
There are five practical actions Australian businesses should take now:
- Continue Essential Eight implementation — maturity levels are still required for government and defence procurement, and are still the benchmark used by cyber insurers and enterprise clients.
- Monitor ASD and ACSC publications for the finalised "Essentials for enterprise IT" guidance as it is released through 2026 and 2027.
- Document your current Essential Eight maturity level so you have a clear baseline to map against when the new framework is published. Without documentation, you cannot demonstrate continuity of controls.
- Engage with your IT provider to understand how the new framework will affect your existing controls, tooling, and reporting. This conversation should happen now, not after the framework is finalised.
- Don''t pause cyber insurance renewal questionnaires — insurers are still asking about Essential Eight compliance regardless of the upcoming transition, and gaps in your answers will affect premiums and coverage.
How does the transition affect Microsoft 365 and Azure environments?
The controls that currently satisfy Essential Eight in a Microsoft 365 environment — MFA via Microsoft Entra ID, patching via Microsoft Intune, application control via Microsoft Defender, and daily backups via Azure Backup — are foundational security controls that any replacement framework will also require. These are not Essential-Eight-specific implementations; they are the modern baseline for identity, endpoint, and data protection in a Microsoft-native environment.
Microsoft Defender for Endpoint provides the endpoint detection and response (EDR) capability that will be relevant regardless of framework name, and Microsoft Sentinel provides the SIEM and threat-hunting layer that a more adaptive, threat-informed framework will almost certainly emphasise more heavily than Essential Eight did.
Mycelium 365''s managed services are built on these Microsoft-native controls, which are framework-agnostic and will remain relevant through the transition. Clients on our managed offering will not need to re-platform when the new framework is published — the same controls will map into the new model.
How Mycelium 365 helps Australian businesses through the Essential Eight transition
Mycelium 365 monitors ASD and ACSC guidance closely and will update our managed services offering as the "Essentials for enterprise IT" framework is finalised. Our current managed services are built on Microsoft-native controls that satisfy Essential Eight today and will align with the replacement framework tomorrow. We''ll keep clients informed of any configuration or reporting changes required as the new framework is published, so there are no surprises at audit or renewal.
Our governance and compliance advisory service covers cyber security framework readiness, and our Security Operations Centre provides the ongoing detection and response capability that both Essential Eight and its replacement will require. See our guide to the Cyber Security Act 2024 for related regulatory context, and our AI Readiness Assessment if you''re preparing for AI-related security obligations.
Frequently asked questions
Is the Essential Eight still required in 2026?
Yes. The Essential Eight remains fully in place through 2026 and into the two-year transition period announced by the ASD. Australian government procurement, DISP requirements for defence contractors, and cyber insurance questionnaires all continue to reference Essential Eight maturity levels. Businesses should continue implementing and maintaining Essential Eight controls until ASD formally retires the framework.
What is replacing the Essential Eight in Australia?
The Essential Eight is being replaced by a new ASD framework called 'Essentials for enterprise IT'. It is described as a set of prioritised, threat-informed mitigations rather than a static compliance ladder, designed to be more adaptive to modern threats including AI-enabled attacks, identity-based intrusions, and shifting cloud environments. National consultation on the draft framework ran until 12 July 2026.
When will the Essential Eight be fully retired?
ASD has indicated a two-year transition period from the June 2026 announcement, meaning the Essential Eight is expected to be progressively superseded from around 2028. The exact retirement date will depend on when 'Essentials for enterprise IT' is formally published and adopted into government procurement and DISP requirements.
Will my Essential Eight compliance work still be relevant under the new framework?
Yes. ASD has signalled that 'Essentials for enterprise IT' is expected to align closely with existing Essential Eight controls. Investments in MFA, application control, patching, backups, and privileged access management will remain relevant — they will simply be reframed inside a more dynamic, threat-informed model. Organisations should document their current maturity now to map cleanly into the new framework.
