ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Framework · ASD Essentials series

The Essentials series: what ASD has announced, and what has not changed.

On 15 June 2026 ASD opened consultation on a successor to the Essential Eight: a series of chapters grounded in the ISM, the first of them Essentials for enterprise IT. The Essential Eight stays in force and the Maturity Level Two mandate has not moved. This page separates what ASD has published from what has been reported, and says what to do with the difference.

What carries overThe Essential Eight today

Two sources

What ASD has said, and what the press has said.

Most coverage runs the two together. They are not the same kind of statement. ASD's announcement is policy; the iTnews interview is an official's expectation. Both are worth reading, and only one of them binds anyone.

From ASD

Published · 15 Jun 2026
  • “Grounded in the Information Security Manual (ISM), the new Essentials guidance will offer prioritised, threat-informed mitigations for contemporary technology environments, supported by practical tools and clear implementation guidance.”
  • “Organisations already using the Essential Eight can expect strong alignment with their existing controls and investments, while new adopters will benefit from established best-practice guidance.”
  • “The evolution of the current Essential Eight guidance will form the first chapter of the series, Essentials for enterprise IT, with additional chapters to follow.”

Consultation ran through the ASD Cyber Security Partnership Program portal until 12 July 2026. Source: cyber.gov.au, “Consultation on evolution of Essential Eight”.

Reported by iTnews

Interview · 24 Jun 2026
  • ACSC's head of cyber security resilience, Chris Horlyck, described a transition period with both frameworks live, then: "probably in 12 months, start to deprecate the Essential Eight, and then in 24 months we'll retire the Essential Eight as a whole."
  • "The investment you've made under the Essential Eight will still be relevant under the Essentials."
  • Later chapters are expected to cover operational technology and cloud, with Modern Defensible Architecture described as a key influence on the series.

ASD has published no dates. The words “deprecate” and “retire” appear in the reporting, not in the announcement. The calendar years on this page are derived from the interview and marked as such.

Timeline

From eight strategies to a series of chapters.

Jun 2017

Essential Eight published

ASD distils its Strategies to Mitigate Cyber Security Incidents into a baseline of eight for internet-connected enterprise IT.

Nov 2023

Current maturity model

The release still in force: 48-hour patch windows for exploited vulnerabilities, phishing-resistant MFA from ML2, and the four-level model.

Feb to Oct 2025

Modern Defensible Architecture

ASD and eight partner agencies publish ten architecture-first foundations, updated in October after more than 240 stakeholder responses.

15 Jun 2026

Essentials series announced

Consultation opens on Essentials for enterprise IT, the first chapter, grounded in the ISM. Submissions close 12 July.

About 2027

Deprecation begins

An ACSC official's expectation, quoted by iTnews: both frameworks live, with the Essential Eight starting to be deprecated roughly a year after the consultation.

Reported, not published

About 2028

Retirement

The same interview: full retirement of the Essential Eight roughly two years out. No ASD publication carries a date.

Reported, not published

What carries over

The eight strategies already sit inside the ten foundations.

ASD's Foundations for Modern Defensible Architecture describes itself as the structural frame for implementing the ISM and the Essential Eight, and says an organisation working toward a higher maturity level will be well placed for it. Hover a strategy to see where its work lands.

Essential Eight strategies

Patch applications
Patch operating systems
Multi-factor authentication
Restrict administrative privileges
Application control
Restrict Microsoft Office macros
User application hardening
Regular backups

MDA foundations

01Centrally managed enterprise identities
02High confidence authentication
03Contextual authorisation
04Reliable asset inventory
05Secure endpoints
06Reduced attack surface
07Resilient networks
08Secure-by-Design
09Comprehensive validation and assurance
10Continuous and actionable monitoring

Patch applications

  • 04Reliable asset inventory
  • 06Reduced attack surface

Patch operating systems

  • 04Reliable asset inventory
  • 06Reduced attack surface

Multi-factor authentication

  • 02High confidence authentication

Restrict administrative privileges

  • 01Centrally managed enterprise identities
  • 03Contextual authorisation

Application control

  • 05Secure endpoints

Restrict Microsoft Office macros

  • 05Secure endpoints
  • 06Reduced attack surface

User application hardening

  • 05Secure endpoints
  • 06Reduced attack surface

Regular backups

  • 09Comprehensive validation and assurance

This mapping is ours, not ASD's. It is drawn from the requirements in the November 2023 maturity model and the foundation descriptions in ASD's Foundations for Modern Defensible Architecture (October 2025). The logging and analysis requirements that enter every strategy from ML2 feed the tenth foundation, continuous and actionable monitoring; those eight lines are left off the drawing for legibility.

What to do now

Keep the ML2 program, and treat the evidence as reusable.

The mandate has not changed. The PSPF still requires non-corporate Commonwealth entities to implement every strategy to Maturity Level Two, contracts with primes still name the Essential Eight, and the November 2023 model is still the one an assessor will open. A team that slows its program because a successor is coming will be assessed against the current model in the meantime.

The evidence you gather now is the evidence the Essentials chapter will read. ASD said the new guidance is grounded in the ISM and that existing controls and investments align strongly. So the work worth doing is not a new spreadsheet. It is making sure each control has an owner, each piece of evidence has a date, and each exception is a recorded decision, because those three things transfer and a screenshot folder does not.

Where you have a choice, prefer controls shaped like the foundations. A reliable asset inventory, centrally managed identity, and monitoring you act on outlive any particular list of eight, and they are the parts of the current model that got harder at ML2 and ML3 for exactly that reason.

In Alvor

The evidence moves with you.

The Essential Eight, at every level, today

The pack installs every strategy at ML1, ML2 and ML3 with owners, evidence and review dates. Nothing about the transition changes what is required of you this year, so this is where the work happens now.

Compliance

The Essentials chapter, the day it is published

You can add any framework in Alvor, so when Essentials for enterprise IT is final it goes in the day ASD publishes it, in ASD's own structure, and is crosswalked to the Essential Eight so your evidence is reused. Each control is then assessed against the new wording, which is what an assessor will hold you to.

How the framework builder works

The successor is architecture-first, and so is Alvor

Asset inventory, identity, Secure-by-Design and continuous assurance are the shape of the foundations. They are also the shape of the product: the asset register, Secure by Design reviews, and controls with automated checks were built for that model before ASD named it.

Security architecture

Advisory for the transition

Alvor Advisory runs Essential Eight uplift and Australian-context engagements. If you want a second opinion on where your ML2 program will land under the Essentials, that is the conversation to have.

Advisory

Questions

Common questions about the ASD Essentials series

Not yet. ASD announced a successor, the Essentials series, on 15 June 2026 and opened consultation on its first chapter. An ACSC official told iTnews to expect deprecation to start about a year later and retirement about two years out, but ASD has published no dates and the Essential Eight remains in force.

Get started

See how Alvor works for your role

Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.

Request DemoView Pricing
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign
  • Australia

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • ISM
  • IRAP
  • Essential Eight
  • ASD Essentials
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyDisclosure