Do not pause Essential Eight work because ASD announced an Essentials series. As of mid-2026, ASD is consulting on a successor framework (starting with Essentials for enterprise IT), with both Essential Eight and the new series expected to run in parallel before any later deprecation and retirement. Your insurers, tenders, and DISP-facing questionnaires still use today's Essential Eight maturity model. The practical move for Australian SMBs: baseline and uplift against Essential Eight now, keep dated evidence, and map forward when final Essentials chapters land — not wait two years.
What is the ASD Essentials series?
The ASD Essentials series is the Australian Signals Directorate's planned successor guidance to the Essential Eight: a modular, outcomes-focused set of chapters covering domains such as enterprise IT first, then cloud and operational technology (with further chapters possible later). Official commentary has stressed that investments made under Essential Eight remain relevant, and that Essential Eight stays a live document during a transition period.
That is different from a sudden "E8 is dead" switch. Public reporting (including ASD/ACSC commentary covered by Australian trade press in June 2026) describes:
- ▸Consultation on the first chapter — Essentials for enterprise IT (feedback windows reported through mid-July 2026)
- ▸A transition period where Essential Eight and Essentials are both live
- ▸Indicative timing discussed by ACSC leadership of roughly ~12 months toward deprecation and ~24 months toward retirement of Essential Eight — framed as expectations, not fixed calendar deadlines published as hard law
Until ASD publishes final chapters and any formal retirement notice, treat press timelines as directional. Always check cyber.gov.au for the current Essential Eight model and any Essentials publications.
Is Essential Eight being retired right now?
No — Essential Eight is not retired today. It remains the maturity model Australian SMBs meet in insurance questionnaires, many Commonwealth and state procurement conversations, and defence supply-chain expectations that reference Essential Eight maturity (commonly ML2 for in-scope ICT under DISP-related cyber requirements).
What is happening is an evolution: ASD is designing broader, more flexible guidance that better covers modern estates (identity-heavy SaaS, cloud, OT) than a single eight-control set written for a different era of enterprise IT. Evolution is not permission to freeze patching, MFA coverage, admin rights hygiene, backups, or application control while you "wait for the new PDF."
If a vendor tells you to stop Essential Eight work because "Essentials replaces everything next quarter," treat that as a sales story — not ASD policy. For the mandatory-vs-practical landscape, see our guide: Is Essential Eight mandatory in Australia?.
What should Australian SMBs do now?
Keep implementing and measuring Essential Eight. Baseline your maturity, close the highest-risk gaps, and file evidence you can reuse when frameworks rename.
A practical 2026–27 sequence for most SMBs:
- Confirm why you care — insurance renewal, client tender, board assurance, or defence supply-chain pressure. That drives target maturity (often ML1 first; ML2 when contracts or DISP-adjacent scope demand it).
- Get an independent maturity baseline — scored strategies with evidence, not a verbal "we're roughly ML1."
- Fund uplift separately — assessment ≠ remediation. Your MSP or IT team implements; keep the assessor independent where insurers or auditors care about objectivity.
- Keep a dated evidence pack — MFA coverage, patch SLAs, backup restore tests, privileged access reviews, application control status, email authentication (SPF/DKIM/DMARC where relevant).
- Watch ASD publications — when Essentials chapters finalise, map your existing controls and evidence to the new outcomes language. Do not rebuild from zero if your E8 program is real.
Aussie Pentest's published Essential Eight assessment for environments up to 50 seats is $4,950 + GST — maturity scoring, evidence-oriented reporting, gap analysis, and a prioritised roadmap. It is not ASD endorsement, an "E8 certified" badge, or a guarantee any insurer or panel will accept a specific report. Acceptance stays with them.
Will Essential Eight work still count under Essentials?
ASD has publicly indicated that investment under Essential Eight remains relevant under the Essentials direction — tools and platforms many organisations already run are expected to map into the newer outcomes language. That is the opposite of "throw away MFA / EDR / backup / app control programs."
What will change over time is how you describe and evidence outcomes, especially once cloud and OT chapters exist and procurement language updates. Organisations with clear maturity scores, configuration evidence, and a remediation backlog with owners and dates will remap faster than those with only a marketing slide saying "we do Essential Eight."
Essential Eight vs Essentials series: what is actually different?
Essential Eight (current): eight mitigation strategies + ML0–ML3 maturity; familiar and relatively prescriptive; live and what most questionnaires still reference. Essentials series (incoming): modular chapters (enterprise IT first; cloud/OT later); more outcomes/intent oriented; first chapter in/near consultation — not a full overnight replacement. SMB action: baseline + uplift now; track publications and remap evidence when chapters finalise.
Essential Eight is also not the same as ISO 27001. E8 is a technical mitigation maturity model; ISO is a management-system wrapper. Many SMBs still do E8 first. Detail: Essential Eight vs ISO 27001.
How does this affect insurance, tenders, and DISP?
Near term: little changes in the questions you are asked. Brokers, underwriters, and tender panels still ask about Essential Eight maturity, MFA, backups, patching, privileged access, and whether you have recent independent testing. DISP-related cyber expectations for in-scope ICT have long pointed at Essential Eight ML2 — do not assume that language flips the week a consultation PDF appears.
"We're waiting for Essentials" is a weak answer at renewal. "We assessed in 2026, closed critical gaps, and hold evidence" is a strong one. Keep assessment, uplift, and penetration testing artefacts distinct.
A human-led penetration test (published from $5,000 / $12,000 / $20,000 AUD depending on scope) proves what an attacker can achieve in scoped systems. An Essential Eight assessment scores mitigation maturity.
An automated security assessment (from $80 / $200 / $500 / $2,000) is an analyst-reviewed first look — not a pentest and not an E8 scorecard. Pick the artefact that matches the question.
For cost inclusions on the E8 product itself: Essential Eight assessment cost in Australia.
What should you avoid during the transition?
Pausing patch and identity work "until the new model"; buying a new tool stack only because the logo says Essentials; self-attesting ML2 without evidence; letting the implementer grade their own homework when you need independent assurance; overclaiming ("ASD endorsed", "E8 certified company", "guaranteed insurance approval"); ignoring cloud and SaaS identity.
If you need ongoing prioritisation across insurance questionnaires, roadmap owners, and board language while frameworks shift, that is vCISO territory (published $2,500 / $4,250 / $6,500 per month) — advisory and oversight, not implementation and not incident response.
How do you turn this into a 90-day plan?
Days 1–15 — Scope and baseline: decide target maturity (ML1 vs ML2) from real drivers; book an independent Essential Eight assessment; list systems in scope (endpoints, identity, email, servers, backups, admin pathways).
Days 16–45 — Evidence and quick wins: collect configuration exports and process proof; close obvious gaps (MFA coverage holes, local admin sprawl, untested backups, overdue critical patches, macro/application-control weak spots).
Days 46–90 — Uplift and file the pack: ticket remaining gaps with owners and dates; store the assessment report, severity/gap register, and remediation proof where your broker or tender lead can reuse them; schedule a quarterly reminder to re-check ASD Essentials publications.
When a client or insurer also asks "when was your last pentest?", answer with a real engagement and a usable report — not a scanner PDF. See what a penetration testing report should include.
Bottom line for Australian SMBs
The Essentials series is a long transition, not an excuse to idle. Essential Eight remains the model most commercial conversations use in 2026. Baseline honestly, uplift with your MSP or IT team, keep evidence, and remap when final Essentials chapters publish. That path protects insurance and tender narratives better than waiting for a perfect new checklist.
Next step: If you need a fixed-fee maturity baseline (≤50 seats) with a board-readable gap roadmap — not a bundled uplift pitch — start with Aussie Pentest's Essential Eight assessment ($4,950 + GST published). For exploit evidence on scoped systems, talk penetration testing. For continuous oversight while frameworks evolve, see vCISO.

