What's changed: On 24 June 2026, ASD's Chris Horlyck, head of cyber security resilience at the ACSC, confirmed the Essential Eight will remain a live, active document during a transition period, but ASD will begin deprecating it in approximately 12 months and retire it fully within 24. It is being replaced by a broader "Essentials" series structured around distinct security domains; enterprise technology first, then operational technology and cloud, with agentic AI flagged as a likely future chapter given the identity and access problems autonomous agents introduce that conventional controls were never designed to handle. The first chapter, Essentials for Enterprise technology, was open on the ACSC Partner Portal for consultation until 12 July 2026.
Why, and why now: The stated rationale is structural, not cosmetic, and ASD has been candid about it. First, a persistent complaint: maturity level requirements have effectively shifted under organisations' feet over the years, as ASD folded new threat tradecraft into existing levels rather than giving the framework room to evolve separately, creating the appearance of security regression without any actual decline in posture. Second, and more fundamental, Essential Eight was built in 2017, evolving from the 2012 Top Four, for an on-premises, Windows-heavy, perimeter-based world. As Horlyck put it, an organisation without cloud today "would be a really surprising architecture." The framework simply wasn't designed for the shared-responsibility model cloud introduces, nor for SaaS, BYOD, microservices, or AI agents now embedded in most operating environments.
The Essentials series decouples threat-informed controls from a fixed maturity ladder, shifting emphasis from prescriptive, technology-specific requirements toward outcomes and intent, giving organisations flexibility to meet guidance with whatever tools suit their environment, rather than a one-size-fits-all checklist applied identically to a 20-person firm and a 500-person enterprise.
An international perspective: ASD's move sits at a distinct point on the spectrum relative to peers. CISA's Cross-Sector Cybersecurity Performance Goals 2.0, released December 2025, made a philosophically similar shift, from a checklist of discrete mitigations toward outcome-oriented, governance-first expectations aligned with NIST CSF 2.0; however, CISA iterated its existing framework rather than sunsetting it, and CPGs remain explicitly voluntary with no audit mandate. Europe's NIS2 Directive took the opposite structural path entirely, rather than a maturity model organisation self-assess against, it is binding law, with mandatory incident reporting timelines and direct board-level liability for non-compliance. ASD's retirement of the Essential Eight is arguably bold, a full sunset of a decade-old brand rather than an iteration or a legislative tightening while notably still stopping short of the EU's compulsory, penalty-backed model.