Framework · ASD Essentials series
On 15 June 2026 ASD opened consultation on a successor to the Essential Eight: a series of chapters grounded in the ISM, the first of them Essentials for enterprise IT. The Essential Eight stays in force and the Maturity Level Two mandate has not moved. This page separates what ASD has published from what has been reported, and says what to do with the difference.
Two sources
Most coverage runs the two together. They are not the same kind of statement. ASD's announcement is policy; the iTnews interview is an official's expectation. Both are worth reading, and only one of them binds anyone.
From ASD
Published · 15 Jun 2026Consultation ran through the ASD Cyber Security Partnership Program portal until 12 July 2026. Source: cyber.gov.au, “Consultation on evolution of Essential Eight”.
Reported by iTnews
Interview · 24 Jun 2026ASD has published no dates. The words “deprecate” and “retire” appear in the reporting, not in the announcement. The calendar years on this page are derived from the interview and marked as such.
Timeline
Jun 2017
Essential Eight published
ASD distils its Strategies to Mitigate Cyber Security Incidents into a baseline of eight for internet-connected enterprise IT.
Nov 2023
Current maturity model
The release still in force: 48-hour patch windows for exploited vulnerabilities, phishing-resistant MFA from ML2, and the four-level model.
Feb to Oct 2025
Modern Defensible Architecture
ASD and eight partner agencies publish ten architecture-first foundations, updated in October after more than 240 stakeholder responses.
15 Jun 2026
Essentials series announced
Consultation opens on Essentials for enterprise IT, the first chapter, grounded in the ISM. Submissions close 12 July.
About 2027
Deprecation begins
An ACSC official's expectation, quoted by iTnews: both frameworks live, with the Essential Eight starting to be deprecated roughly a year after the consultation.
Reported, not published
About 2028
Retirement
The same interview: full retirement of the Essential Eight roughly two years out. No ASD publication carries a date.
Reported, not published
What carries over
ASD's Foundations for Modern Defensible Architecture describes itself as the structural frame for implementing the ISM and the Essential Eight, and says an organisation working toward a higher maturity level will be well placed for it. Hover a strategy to see where its work lands.
Patch applications
Patch operating systems
Multi-factor authentication
Restrict administrative privileges
Application control
Restrict Microsoft Office macros
User application hardening
Regular backups
This mapping is ours, not ASD's. It is drawn from the requirements in the November 2023 maturity model and the foundation descriptions in ASD's Foundations for Modern Defensible Architecture (October 2025). The logging and analysis requirements that enter every strategy from ML2 feed the tenth foundation, continuous and actionable monitoring; those eight lines are left off the drawing for legibility.
What to do now
The mandate has not changed. The PSPF still requires non-corporate Commonwealth entities to implement every strategy to Maturity Level Two, contracts with primes still name the Essential Eight, and the November 2023 model is still the one an assessor will open. A team that slows its program because a successor is coming will be assessed against the current model in the meantime.
The evidence you gather now is the evidence the Essentials chapter will read. ASD said the new guidance is grounded in the ISM and that existing controls and investments align strongly. So the work worth doing is not a new spreadsheet. It is making sure each control has an owner, each piece of evidence has a date, and each exception is a recorded decision, because those three things transfer and a screenshot folder does not.
Where you have a choice, prefer controls shaped like the foundations. A reliable asset inventory, centrally managed identity, and monitoring you act on outlive any particular list of eight, and they are the parts of the current model that got harder at ML2 and ML3 for exactly that reason.
In Alvor
The Essential Eight, at every level, today
The pack installs every strategy at ML1, ML2 and ML3 with owners, evidence and review dates. Nothing about the transition changes what is required of you this year, so this is where the work happens now.
ComplianceThe Essentials chapter, the day it is published
You can add any framework in Alvor, so when Essentials for enterprise IT is final it goes in the day ASD publishes it, in ASD's own structure, and is crosswalked to the Essential Eight so your evidence is reused. Each control is then assessed against the new wording, which is what an assessor will hold you to.
How the framework builder worksThe successor is architecture-first, and so is Alvor
Asset inventory, identity, Secure-by-Design and continuous assurance are the shape of the foundations. They are also the shape of the product: the asset register, Secure by Design reviews, and controls with automated checks were built for that model before ASD named it.
Security architectureAdvisory for the transition
Alvor Advisory runs Essential Eight uplift and Australian-context engagements. If you want a second opinion on where your ML2 program will land under the Essentials, that is the conversation to have.
AdvisoryQuestions
Not yet. ASD announced a successor, the Essentials series, on 15 June 2026 and opened consultation on its first chapter. An ACSC official told iTnews to expect deprecation to start about a year later and retirement about two years out, but ASD has published no dates and the Essential Eight remains in force.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.