If you've been working on your Essential Eight maturity, you might have seen the news: the ACSC is evolving the framework. Cue the immediate worry that everything you've done is about to be obsolete.
It isn't. Let me walk you through what's actually happening.
In June 2026, the Australian Cyber Security Centre opened a consultation on something they're calling the "Essentials series". The Essential Eight as you know it becomes the first chapter, titled "Essentials for enterprise IT", with more chapters to follow.
The one thing to take away: your Essential Eight work is not wasted. The ACSC says organisations already using it can expect strong alignment with the new guidance.
What the Essentials Series Actually Is
The Essential Eight has been Australia's baseline for years. Eight mitigation strategies, three maturity levels, clear and prescriptive. That isn't going away.
The Essentials series builds on it. Grounded in the Information Security Manual, the new guidance aims to be more threat-informed and better suited to modern environments: cloud-first businesses, remote teams, identity-based attacks. It comes with practical tools and clearer implementation advice.
Think of it less as a replacement and more as the next edition. The current framework becomes chapter one. Future chapters will expand into areas the original Eight was never designed to cover.
Why the Change
Because the threat landscape moved. When the Essential Eight was designed, the average small business ran a server in the back room and a desktop on every desk. Now most run entirely on cloud software, with staff working from kitchen tables and client sites.
Attacks shifted the same way. Credential theft, business email compromise, supply chain compromises. The ACSC is reshaping the guidance to match how businesses actually operate now, not how they operated in 2017.
What This Means for You Today
Nothing breaks. Nothing is deprecated. The Essential Eight is still the current, active benchmark.
If you've spent time rolling out MFA, tightening backups, or working with your IT provider on patching, all of that still counts. Government departments, insurers, and supply chains asking for Essential Eight maturity are still asking for the same thing they were asking for last month.
You do not need to rewrite your IT roadmap. You do not need to start over. Keep going.
The Timeline
Consultation ran from 15 June to 12 July 2026 through the ASD Cyber Security Partnership Program portal. The ACSC is now reviewing feedback before publishing the final guidance.
No release date has been announced. No deprecation schedule either. My read, based on how these frameworks have transitioned in the past, is that we'll see a long overlap period once the new guidance lands, likely 12 to 18 months where both are recognised side by side. That's an educated guess, not an official position.
What I'm Doing About It
I'm tracking the consultation and the draft guidance as it develops. Eito's assessment maps directly to the current Essential Eight, and when the Essentials series publishes, I'll map every question across.
Your data stays in your browser, so your history and reports remain intact no matter what changes. When the transition happens, I'll make sure you can see clearly how your existing answers line up with the new structure.
What You Should Do
Don't pause your security work waiting for new paperwork. The fundamentals aren't changing:
- Keep patching. Outdated software is still the easiest way in.
- Keep MFA on. It's still the single best defence against stolen credentials.
- Keep testing your backups. A backup you've never restored is a hope, not a plan.
- Keep admin access tight. Staff should only have the access their job requires.
- Talk to your IT provider about the Essentials evolution so they're across it too.
Whether a control is called "Essential Eight" or "Essentials for enterprise IT", the protection underneath is the same. Stopping ransomware and preventing invoice fraud still comes down to getting the basics right.
Want to know where you stand against the current framework? Run the free self-assessment at /assess. Fifteen minutes, no account, and you'll walk away with a prioritised list of gaps.
