What is replacing the ASD Essential Eight, how the maturity model works and what Essential 8 compliance means for businesses of 15 to 70 staff.






The ASD Essential Eight is a set of eight security controls published by the Australian Signals Directorate. The Essential 8 framework is not a law and there is no certification body, but cyber security Essential 8 alignment is now something insurers, government buyers and enterprise customers ask Australian businesses to evidence. In June 2026 ASD announced it is replacing the Essential Eight with a broader body of guidance called the Essentials series. This page explains what is changing, what to do if you are partway through the work, how the eight controls apply on Microsoft 365, and what an assessment involves.
Yes. On 24 June 2026 the Australian Signals Directorate confirmed the Essential Eight will be retired and replaced by a new Essentials series. The first chapter, Essentials for enterprise IT, is the direct successor to the Essential Eight. ASD expects to begin deprecating the Essential Eight in about 12 months, and to retire it in about 24.
Until then the Essential Eight remains current guidance. Insurers, government buyers and enterprise customers will keep asking about it through the transition.
ASD describes the replacement as prioritised, threat-informed guidance for modern technology rather than a fixed compliance ladder. What it has said so far:
On maturity levels, ASD has said it wants to stop requirements shifting under businesses that have not changed anything, by moving away from a fixed maturity ladder. Whether Levels 1 to 3 survive in the final document is not yet confirmed. What is not changing is the underlying work: multi-factor authentication, patching, backups, restricting admin access and application control are not going away.
Keep going. ASD has said the new guidance is designed to align with existing Essential Eight controls, so work done now carries across. Stopping to wait for the final document leaves the same gaps open for another year or more.
Three practical steps while the new guidance is finalised:
The Essential 8 is a set of eight baseline cyber security mitigation strategies. It is prioritised guidance, not a certification, a standard or legislation. The Essential Eight explained simply: eight controls that make the most common attacks much harder and more expensive to pull off.
You will see it written as the ASD Essential Eight, Essential 8 ACSC, Essential Eight ACSC, Essential Eight ASD and the E8. They all mean the same Essential Eight framework. ASD is the agency, and the Australian Cyber Security Centre is the part of ASD that publishes the guidance on cyber.gov.au. Most pages that have the Essential 8 explained skip this, which is why the names cause so much confusion. The Essential Eight and the Essential 8 are the same thing.
The Essential Eight mitigation strategies, also called the Essential Eight controls or the ASD Essential 8 controls, are listed below. ASD groups the ASD Essential Eight controls into strategies that prevent attacks, limit the damage and help you recover, and the Essential Eight strategies are designed to work together.
Stops unapproved programs, scripts and installers from running. When people search for application control Essential 8 guidance, this is what they mean: nothing runs unless it has been approved. On a Microsoft 365 business it is usually managed through Intune and Windows application control policies.
Keeps third-party software such as browsers, PDF readers and Office patched to a set timeframe, not when someone gets to it. Essential 8 patching covers applications here and operating systems in control 6.
Blocks macros from the internet and limits macros to staff with a genuine business need. On Microsoft 365 this is a policy setting, not a product purchase.
Configures web browsers and common applications so they cannot run the components attackers rely on, such as old browser plugins and unnecessary scripting.
Separates admin accounts from everyday accounts, and stops admin accounts from browsing the web or reading email. In Microsoft 365 that means dedicated admin accounts rather than giving staff global admin rights on their day-to-day login.
Keeps Windows and other operating systems patched to a set timeframe, and removes versions the vendor no longer supports.
Enforces MFA across internet-facing services and important systems. Since the November 2023 update to the maturity model, Maturity Level 2 requires phishing-resistant MFA, so SMS codes do not qualify.
Backs up data, software and settings, keeps copies out of reach of ransomware, and tests restores. Microsoft does not back up your Microsoft 365 tenant in the way this control means: retention settings and recycle bins are not backup, so meeting it needs a separate backup product with a tested restore.
The Essential Eight maturity model, formally the ASD Essential 8 maturity model, grades each of the eight controls on a four-point scale.
You will also see it called the ACSC Essential 8 maturity model, the ACSC Essential Eight maturity model or the E8 maturity model. Two things people get wrong. Essential 8 maturity is assessed per control, so each Essential 8 maturity level has to be reached by all eight controls before a business can claim it. And ASD recommends lifting all Essential 8 levels together before pushing any single control higher.
The baseline. Essential 8 Level 1 is aimed at attackers using commodity tools, and is where most businesses of 15 to 70 staff should start.
The level most government panels and larger customers ask for. The biggest practical jump in Essential 8 Level 2 is multi-factor authentication: Essential 8 ML2 requires phishing-resistant methods such as passkeys, FIDO2 security keys or Windows Hello for Business.
No, not legally. No Australian law requires a private company to implement the Essential Eight. Essential Eight compliance is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework, which sets ASD Essential 8 compliance at Maturity Level 2.
For everyone else, Essential 8 cybersecurity has become a commercial requirement. Cyber insurers ask about Essential Eight cyber security controls at renewal. Government panels name Essential 8 cyber maturity levels in their conditions. Enterprise customers send supplier questionnaires built around cybersecurity Essential 8 controls. The plain answer for a business of 15 to 70 staff: you are not breaking the law by not doing it, but you may lose cover and contracts.
No. There is no official Essential Eight certification and no accredited certification body. ASD does not certify organisations or licence assessors. What exists is an assessment against the maturity model, producing documented evidence of where you sit for each control. That evidence, and the date it was assessed, is what insurers and buyers actually ask for. If you need something formally certifiable, SMB1001 has tiered certification and is often a more realistic starting point for businesses of 15 to 70 staff.
An Essential Eight audit measures where you sit against each of the eight controls and produces the evidence behind each grade. It is not the same as an uplift: the assessment tells you where you are, and the uplift is the project that moves you. As an Essential Eight assessment process guide, a typical assessment runs in this order:
For a business of 15 to 70 staff the scope is much smaller than an enterprise assessment: usually one Microsoft 365 tenant, a single fleet of laptops and often no on-premises servers. Elscomm does not apply the Essential Eight to every client by default, but we can assess and uplift against it for businesses that need it. Talk to us about an Essential Eight assessment.
The Information Security Manual is ASD's full control catalogue. The Essential Eight is a prioritised subset of it, and each control traces back to specific ISM controls. That is how government and regulated buyers reconcile the two when they ask for both, and it is why Essential Eight evidence can usually be reused when a buyer asks about the ISM.