The Essential Eight Is Being Retired – Should You Be Concerned?

If you’ve invested time and effort into improving your organisation’s Essential Eight maturity, recent news from the Australian Signals Directorate (ASD) may have raised some questions.
The short answer? No, you shouldn’t be concerned – and you certainly shouldn’t stop your cyber security improvement program.
ASD has announced plans to evolve the current Essential Eight framework into a broader “Essentials” series, designed to better address today’s technology environments, including cloud services, operational technology and emerging AI-related risks. The transition is expected to occur over the next two years, with Essential Eight continuing as an active framework during that period. [cyber.gov.au], [itnews.com.au]
Why Is ASD Making This Change?
The Essential Eight has served Australian organisations well, providing a practical baseline for cyber security. However, it was developed at a time when on-premises infrastructure was still the norm and cloud adoption was far less widespread.
The new Essentials series aims to provide more flexible, threat-informed guidance for modern technology environments while maintaining strong alignment with existing Essential Eight controls and investments.
What Does This Mean for Your Organisation?
For most organisations, the practical answer is simple:
- Continue implementing and maintaining Essential Eight controls.
- Don’t pause security uplift programs.
- Expect future guidance to expand beyond traditional enterprise IT.
- Begin thinking more broadly about cyber resilience across cloud, SaaS, third-party services and AI-enabled technologies.
In other words, the foundations you’re building today remain valuable. Multi-factor authentication, patch management, secure backups, application control and privileged access management aren’t going away.
A Board-Level Perspective
Boards should view this change as an evolution rather than a disruption.
The key question is no longer simply, “What is our Essential Eight maturity level?” Instead, directors should be asking:
“How effectively are we managing cyber risk across our business-critical systems, cloud platforms, third-party suppliers and emerging AI capabilities?”
The new Essentials series is likely to encourage a more holistic and risk-based approach to cyber security, helping organisations focus on resilience and business outcomes rather than compliance alone.
The Bottom Line
The Essential Eight remains Australia’s leading cyber security baseline today. Organisations should continue their current uplift activities while keeping an eye on the development of the new Essentials series.
At Protogy, our recommendation is clear:
Treat Essential Eight as the foundation of your cyber security program, not the destination. Continue the journey, preserve the investment you’ve already made, and prepare to align with the next generation of ASD guidance as it emerges.
Cyber security fundamentals remain fundamental — regardless of what the framework is called.

