IT Security

Essential 8 Compliance

What is replacing the ASD Essential Eight, how the maturity model works and what Essential 8 compliance means for businesses of 15 to 70 staff.

The ASD Essential Eight is a set of eight security controls published by the Australian Signals Directorate. The Essential 8 framework is not a law and there is no certification body, but cyber security Essential 8 alignment is now something insurers, government buyers and enterprise customers ask Australian businesses to evidence. In June 2026 ASD announced it is replacing the Essential Eight with a broader body of guidance called the Essentials series. This page explains what is changing, what to do if you are partway through the work, how the eight controls apply on Microsoft 365, and what an assessment involves.

Replacing the ASD Essential Eight: is it being retired?

Yes. On 24 June 2026 the Australian Signals Directorate confirmed the Essential Eight will be retired and replaced by a new Essentials series. The first chapter, Essentials for enterprise IT, is the direct successor to the Essential Eight. ASD expects to begin deprecating the Essential Eight in about 12 months, and to retire it in about 24.

  • June 2026: ASD announces the Essentials series and consults with industry.
  • 12 July 2026: consultation on Essentials for enterprise IT closes.
  • Not yet confirmed: the final Essentials for enterprise IT is published.
  • Around mid 2027: the Essential Eight begins to be deprecated.
  • Around mid 2028: the Essential Eight is retired.

Until then the Essential Eight remains current guidance. Insurers, government buyers and enterprise customers will keep asking about it through the transition.

How the Essential 8 framework is changing: Essentials for enterprise IT

ASD describes the replacement as prioritised, threat-informed guidance for modern technology rather than a fixed compliance ladder. What it has said so far:

  • Threat-informed: built around the techniques attackers actually use and the intent behind each control.
  • Outcome-focused: less reliance on prescriptive technical settings, more on what each control must achieve.
  • Written for cloud and SaaS: the Essential Eight assumed on-premises Windows networks, while the new series is written for Microsoft 365, cloud and hybrid environments.
  • Compatible: designed to align with existing Essential Eight work, so progress carries across.
  • More chapters to follow: further chapters are planned, including one for operational technology.

On maturity levels, ASD has said it wants to stop requirements shifting under businesses that have not changed anything, by moving away from a fixed maturity ladder. Whether Levels 1 to 3 survive in the final document is not yet confirmed. What is not changing is the underlying work: multi-factor authentication, patching, backups, restricting admin access and application control are not going away.

Partway through an Essential Eight uplift? What to do now

Keep going. ASD has said the new guidance is designed to align with existing Essential Eight controls, so work done now carries across. Stopping to wait for the final document leaves the same gaps open for another year or more.

Three practical steps while the new guidance is finalised:

  • Finish the controls that stop the most attacks first: multi-factor authentication, patching and tested backups.
  • Keep your evidence current: insurers and buyers ask for dated proof of what is in place, and that evidence will map across to the Essentials series.
  • Avoid deep investment in anything tied to a specific maturity setting until ASD confirms how levels will work, unless a contract requires it now.

What is the Essential 8? ASD, ACSC and the E8 explained

The Essential 8 is a set of eight baseline cyber security mitigation strategies. It is prioritised guidance, not a certification, a standard or legislation. The Essential Eight explained simply: eight controls that make the most common attacks much harder and more expensive to pull off.

You will see it written as the ASD Essential Eight, Essential 8 ACSC, Essential Eight ACSC, Essential Eight ASD and the E8. They all mean the same Essential Eight framework. ASD is the agency, and the Australian Cyber Security Centre is the part of ASD that publishes the guidance on cyber.gov.au. Most pages that have the Essential 8 explained skip this, which is why the names cause so much confusion. The Essential Eight and the Essential 8 are the same thing.

The Essential 8 controls, and how each one applies on Microsoft 365

The Essential Eight mitigation strategies, also called the Essential Eight controls or the ASD Essential 8 controls, are listed below. ASD groups the ASD Essential Eight controls into strategies that prevent attacks, limit the damage and help you recover, and the Essential Eight strategies are designed to work together.

1. Essential 8 application control

Stops unapproved programs, scripts and installers from running. When people search for application control Essential 8 guidance, this is what they mean: nothing runs unless it has been approved. On a Microsoft 365 business it is usually managed through Intune and Windows application control policies.

2. Patch applications

Keeps third-party software such as browsers, PDF readers and Office patched to a set timeframe, not when someone gets to it. Essential 8 patching covers applications here and operating systems in control 6.

3. Essential 8 macros: Microsoft Office macro settings

Blocks macros from the internet and limits macros to staff with a genuine business need. On Microsoft 365 this is a policy setting, not a product purchase.

4. User application hardening

Configures web browsers and common applications so they cannot run the components attackers rely on, such as old browser plugins and unnecessary scripting.

5. Restrict administrative privileges

Separates admin accounts from everyday accounts, and stops admin accounts from browsing the web or reading email. In Microsoft 365 that means dedicated admin accounts rather than giving staff global admin rights on their day-to-day login.

6. Patch operating systems

Keeps Windows and other operating systems patched to a set timeframe, and removes versions the vendor no longer supports.

7. Multi-factor authentication

Enforces MFA across internet-facing services and important systems. Since the November 2023 update to the maturity model, Maturity Level 2 requires phishing-resistant MFA, so SMS codes do not qualify.

8. Regular backups

Backs up data, software and settings, keeps copies out of reach of ransomware, and tests restores. Microsoft does not back up your Microsoft 365 tenant in the way this control means: retention settings and recycle bins are not backup, so meeting it needs a separate backup product with a tested restore.

The Essential 8 maturity model, Levels 0 to 3

The Essential Eight maturity model, formally the ASD Essential 8 maturity model, grades each of the eight controls on a four-point scale.

Essential 8 maturity levels explained

  • Maturity Level 0: the control is not meaningfully in place.
  • Maturity Level 1: partly aligned with the intent of the control. Aimed at attackers using widely available tools.
  • Maturity Level 2: mostly aligned with the intent of the control. Aimed at attackers willing to invest more time and effort.
  • Maturity Level 3: fully aligned with the intent of the control. Aimed at capable attackers targeting a specific organisation.

You will also see it called the ACSC Essential 8 maturity model, the ACSC Essential Eight maturity model or the E8 maturity model. Two things people get wrong. Essential 8 maturity is assessed per control, so each Essential 8 maturity level has to be reached by all eight controls before a business can claim it. And ASD recommends lifting all Essential 8 levels together before pushing any single control higher.

Essential 8 Maturity Level 1 vs Maturity Level 2

  • Multi-factor authentication: Level 1 requires MFA on internet-facing services. Level 2 requires phishing-resistant MFA and extends it to important data and privileged access.
  • Patching: Level 1 patches internet-facing applications within two weeks, or 48 hours where an exploit exists. Level 2 adds more frequent vulnerability scanning and tighter timeframes across more software.
  • Admin privileges: Level 1 validates requests and blocks admin accounts from email and the web. Level 2 adds regular review, removal of unused access and logging of privileged activity.
  • Application control: Level 1 covers workstations. Level 2 extends it to internet-facing servers.
  • Backups: Level 1 requires backups to be performed, retained and restore-tested. Level 2 also stops standard accounts from changing or deleting backups.

Essential 8 Level 1

The baseline. Essential 8 Level 1 is aimed at attackers using commodity tools, and is where most businesses of 15 to 70 staff should start.

Essential 8 Maturity Level 2 (ML2)

The level most government panels and larger customers ask for. The biggest practical jump in Essential 8 Level 2 is multi-factor authentication: Essential 8 ML2 requires phishing-resistant methods such as passkeys, FIDO2 security keys or Windows Hello for Business.

Essential 8 compliance: do you have to comply?

No, not legally. No Australian law requires a private company to implement the Essential Eight. Essential Eight compliance is mandatory for non-corporate Commonwealth entities under the Protective Security Policy Framework, which sets ASD Essential 8 compliance at Maturity Level 2.

For everyone else, Essential 8 cybersecurity has become a commercial requirement. Cyber insurers ask about Essential Eight cyber security controls at renewal. Government panels name Essential 8 cyber maturity levels in their conditions. Enterprise customers send supplier questionnaires built around cybersecurity Essential 8 controls. The plain answer for a business of 15 to 70 staff: you are not breaking the law by not doing it, but you may lose cover and contracts.

Is there an Essential 8 certification?

No. There is no official Essential Eight certification and no accredited certification body. ASD does not certify organisations or licence assessors. What exists is an assessment against the maturity model, producing documented evidence of where you sit for each control. That evidence, and the date it was assessed, is what insurers and buyers actually ask for. If you need something formally certifiable, SMB1001 has tiered certification and is often a more realistic starting point for businesses of 15 to 70 staff.

Essential 8 audit: what an Essential Eight assessment involves

An Essential Eight audit measures where you sit against each of the eight controls and produces the evidence behind each grade. It is not the same as an uplift: the assessment tells you where you are, and the uplift is the project that moves you. As an Essential Eight assessment process guide, a typical assessment runs in this order:

  • Scope: agree which systems, devices and accounts are in scope and which maturity level you are aiming for.
  • Evidence: collect configuration evidence from Microsoft 365, devices, backups and admin accounts.
  • Grade: assess each of the eight controls against the maturity model.
  • Report: document where you sit on each control and what is missing.
  • Roadmap: set out the order to close the gaps, starting with the controls that stop the most attacks.

Essential Eight assessment for SMEs

For a business of 15 to 70 staff the scope is much smaller than an enterprise assessment: usually one Microsoft 365 tenant, a single fleet of laptops and often no on-premises servers. Elscomm does not apply the Essential Eight to every client by default, but we can assess and uplift against it for businesses that need it. Talk to us about an Essential Eight assessment.

ACSC Essential Eight to ISM mapping

The Information Security Manual is ASD's full control catalogue. The Essential Eight is a prioritised subset of it, and each control traces back to specific ISM controls. That is how government and regulated buyers reconcile the two when they ask for both, and it is why Essential Eight evidence can usually be reused when a buyer asks about the ISM.

Essential Eight services from Elscomm

Need to show insurers or customers where you stand? Talk to us about an Essential Eight assessment.