All insights
Essential Eight

The Essential Eight is being retired. Here's what your firm should do about it.

Nothing, mostly. But for the right reasons, and with your eyes open. ASD is evolving Australia's best-known cyber framework, on a timeline its officials put at about two years, and replacing it with a family of standards called the Essentials series. Here's what's actually changing, what carries across, and what an accounting firm should do while the dust settles.

Nathan James
Founder, Worktopia
3 August 2026Updated 22 August 20267 min read
Retirement flagged for about 2028 · your work carries across · nothing to pause
Retirement flagged for about 2028 · your work carries across · nothing to pause

The short answer, up front

Yes, the Essential Eight is being replaced. In June 2026 the Australian Signals Directorate opened consultation on what it calls an evolution of the Essential Eight into a new Essentials series. Its head of cyber security resilience, Chris Horlyck, told iTnews that ASD would "probably in 12 months, start to deprecate the Essential Eight, and then in 24 months" retire it, so by about mid 2028. ASD's own notice names one chapter, Essentials for enterprise IT, as the evolution of the current guidance, "with additional chapters to follow". iTnews reported the series as covering enterprise IT, cloud, operational technology and potentially agentic AI, with Horlyck flagging agentic AI as a possible dedicated chapter. Work done under the Essential Eight carries across.

No, that is not a reason to pause anything. The Essential Eight remains the live, supported standard today, and it stays the language your insurer, your larger clients and your licensee speak until the new chapters are published and bedded in.

New to the framework? Start here: The Essential Eight, explained for accounting firms

Why the ASD is doing this

The Essential Eight was designed when most business systems lived on a server in a cupboard. As the ACSC's head of cyber security resilience, Chris Horlyck, put it: the Essential Eight started before cloud was really a big thing in the sector.

That's not a small gap for a modern accounting firm. Your practice management, your document store, your email and half your client data now live in cloud services under shared-responsibility models the old framework was never built to describe. Patching your own server is an Essential Eight control; knowing what Microsoft patches for you and what remains your problem is not, and that second question is most of modern security.

So instead of stretching one checklist across every environment, ASD is splitting the guidance into chapters that match how businesses actually run. Its notice commits to enterprise IT first and "additional chapters to follow"; Horlyck has named cloud, operational technology and possibly agentic AI as the domains in view.

There is also a reason behind the change, and it matters to any firm that has watched its maturity score move. Horlyck confirmed to iTnews a long-running complaint that maturity level requirements had "shifted under organisations' feet" as ASD absorbed new threat tradecraft into existing levels, creating the impression of organisations going backwards without any real change in posture. He said the Essentials series was designed to address this by decoupling threat-informed controls from a fixed maturity ladder. That is the structural change. His assurance on the rest: the investment you have made under the Essential Eight "will still be relevant under the Essentials".

The timeline, as reported

1
Now until roughly mid 2027
The Essential Eight remains fully active and supported. The first chapter, Essentials for enterprise IT, was consulted on through ASD's partner portal; that consultation closed 12 July 2026. No public draft has been released.
2
Roughly mid 2027 to mid 2028
Progressive deprecation. The Essential Eight and the Essentials series run side by side while organisations move across.
3
From roughly mid 2028
The Essential Eight is retired. The Essentials series is the standard.

The dates are an ACSC official's stated intentions, reported in June, not a published ASD schedule and not legislation. Expect them to move. What won't move is the direction.

What has happened since June

Not much, and that is worth saying plainly because the emails have not stopped. The consultation on Essentials for enterprise IT closed on 12 July 2026. It ran through ASD's Cyber Security Partnership Program portal, which means there was no public draft to read. As at 22 August 2026 we can find no later ASD publication on the series than the 15 June notice, and no public draft or release date. The Essential Eight Maturity Model remains the published standard you are assessed against. Anyone telling you the replacement is out, or that they have seen it, is ahead of the regulator.

What carries across (almost everything)

ASD's notice promises "strong alignment with their existing controls and investments", and Horlyck was more direct still. In Horlyck's words: the investment you've made under the Essential Eight will still be relevant under the Essentials.

That makes sense once you look at what the eight controls actually are. Multi-factor authentication, patching, backups, restricted admin rights, application control: no successor framework retires those. They're the substance; the framework is the wrapper. A firm sitting at a solid maturity level today starts the Essentials era ahead, not over.

If your firm is mid-way through an Essential Eight uplift, finish it. Stopping now would be like abandoning a fit-out because the building is getting renamed.

They're the substance; the framework is the wrapper. A firm sitting at a solid maturity level today starts the Essentials era ahead, not over.

What it means for an accounting firm, specifically

Your insurer will lag, then follow. Renewal questionnaires are built on Essential Eight language and will be for a while. Expect a messy year or two where forms mix old and new terminology. A documented posture answers both.

Client and licensee questions won't pause. Larger clients' vendor checks and licensee cyber standards keep arriving regardless of which framework name is on them. The underlying asks, MFA, patching, backups, access control, documentation, are identical in both worlds.

Beware the transition merchants. The announcement has already produced two kinds of unhelpful email: "the Essential Eight is dead, stop spending" and "urgent Essentials readiness assessment, act now". Both are selling confusion. There is nothing to buy yet; the first chapter isn't even final.

Watch the cloud chapter. For firms whose entire stack is Microsoft 365, Xero and a document platform, the cloud chapter will eventually be the one that describes your world best. That's a 2027 conversation, and we'll have it with you when there's something concrete to read.

Related reading: Is the Essential Eight mandatory for Australian accounting firms?

What we're doing about it

Our cyber compliance portal tracks client firms' Essential Eight maturity today, and SMB1001 alongside it. As the Essentials chapters firm up we'll map the transition inside the portal, so a firm's existing scores carry across to the new structure rather than resetting to zero. When your licensee or insurer starts using the new language, your evidence will already be in it.

Until then, the standing advice doesn't change: know your maturity level, close the gaps that matter, keep the evidence current.

The short version
ASD opened consultation in June 2026 on evolving the Essential Eight into the Essentials series. Its official's reported timeline: deprecation from about mid 2027, retirement by about mid 2028.
The successor is the Essentials series. ASD has named one chapter, Essentials for enterprise IT, with more to follow; cloud and operational technology are the next domains its officials have named.
Essential Eight work carries across. ASD's notice promises "strong alignment with their existing controls and investments". If you're mid-uplift, finish.
Insurers, clients and licensees will keep speaking Essential Eight for a while yet. A documented posture answers both languages.
Nothing to buy, nothing to pause. Know your maturity, close real gaps, keep evidence current.

Common questions

Is the Essential Eight being replaced?
Yes. In June 2026 the Australian Signals Directorate opened consultation on evolving the Essential Eight into the Essentials series, a set of domain-specific chapters, and ACSC's head of cyber security resilience said ASD would probably start deprecating the Essential Eight in about 12 months and retire it in about 24. Essentials for enterprise IT is the direct successor.
When will the Essential Eight be retired?
No date has been published. ACSC's Chris Horlyck told iTnews in June 2026 that ASD would "probably in 12 months, start to deprecate the Essential Eight, and then in 24 months" retire it, which points to about mid 2027 and mid 2028. Until then it remains the live, supported standard.
Does Essential Eight work still count?
Yes. ASD's notice promises "strong alignment with their existing controls and investments", and ACSC's Chris Horlyck has said the investment made under the Essential Eight "will still be relevant under the Essentials". The core controls, MFA, patching, backups, restricted admin, application control, continue into the successor.
What is the Essentials series?
A family of ASD guidance that ASD calls an evolution of the Essential Eight and its officials describe as its replacement, grounded in the Information Security Manual. ASD's notice names one chapter, Essentials for enterprise IT, with additional chapters to follow; an ACSC official has named cloud, operational technology and possibly agentic AI as the domains in view. Chapters match guidance to the environment a business actually runs.
What should an accounting firm do right now?
Nothing new. Keep working toward your Essential Eight maturity target, keep your evidence documented, and ignore both "it's dead" and "urgent transition assessment" pitches. The framework name is changing; the obligations and the controls are not.
Is the Essential Eight being discontinued?
Not yet. As at August 2026 it is fully active and supported, and the Essential Eight Maturity Model remains the published standard. ASD describes the change as an evolution into the Essentials series; an ACSC official has said deprecation would probably begin about mid 2027 with retirement about mid 2028. Nothing has been discontinued today.
What changes to the Essential Eight controls have been announced?
None that ASD has published. What ACSC's Chris Horlyck has described to iTnews is a structural change: the Essentials series is designed to decouple threat-informed controls from a fixed maturity ladder, so controls can evolve without every organisation's maturity level appearing to slip. The first chapter, Essentials for enterprise IT, was consulted on to 12 July 2026 and no public draft has been released.
Nathan James
Founder, Worktopia
Nathan started Worktopia after years inside a Brisbane accounting firm, moving it off legacy systems and into the cloud. He writes about the practical side of security and IT for practices that would rather be doing the work.
Kip, the Worktopia mascot, holding a coffee
See where you stand

Start with where you are today.

Whatever the framework ends up being called, the first step is the same: an honest baseline. Our free Cyber Compliance Health Check scores your eight controls and shows you the gaps in plain English. Read-only. Nothing in your tenant changes. You approve access, and revoke it any time.

Start a Health Check or call 1300 856 912