Framework · Essential Eight
ASD's eight mitigation strategies are still the baseline Australian security programs are measured against, and the PSPF still mandates Maturity Level 2 for non-corporate Commonwealth entities. They are also evolving into the Essentials series. Here is the framework, the maturity model, and the transition, plainly.
The eight strategies
Patch applications
Patch operating systems
Multi-factor authentication
Restrict administrative privileges
Application control
Restrict Microsoft Office macros
User application hardening
Regular backups
The Strategies
ASD selected these eight from its full mitigation catalogue because they blunt the attacks that actually happen. They are designed for internet-connected enterprise IT; ASD itself notes they were not designed for OT or enterprise mobility.
Known vulnerabilities in the software people use every day, closed on a clock, with the tightest windows for internet-facing services.
The same discipline one layer down, so the platform the applications stand on is not the open door.
A stolen password stops being enough, with phishing-resistant MFA expected as maturity rises.
Admin rights become scarce, requested, time-bound, and separate from everyday accounts.
Only approved executables, libraries, and scripts run. Everything else is denied by default.
Macros from the internet are blocked, and what remains runs only where a business case exists.
Browsers and productivity apps lose the legacy features attackers rely on, like ads for Java and web ads.
Backups happen, are tested, and cannot be modified or deleted by the accounts ransomware compromises.
The Maturity Model
The starting state ASD assumes nothing about: gaps an adversary with commodity tooling can already use.
Mitigates actors using widely available tools and techniques against any target that presents itself.
Actors willing to invest more in a specific target: better phishing, and workarounds for weak MFA. This is the level the PSPF mandates for non-corporate Commonwealth entities.
Actors much less reliant on public tools and techniques. ASD is explicit that even ML3 will not stop sufficiently resourced adversaries.
The rules that surprise first-time implementers: you target one level and must reach it across all eight strategies before claiming it; the model is risk-based, so documented exceptions are legitimate; and there is no certification. Assessment is something you do, or commission, not a badge you buy.
The Transition
On 15 June 2026 ASD opened consultation on evolving the Essential Eight into a broader Essentials series, grounded in the ISM, with Essentials for enterprise IT as the first chapter. ASD's own announcement never says “retire”; that timeline came from ACSC officials, quoted by iTnews: a transition period with both frameworks live, deprecation starting in roughly 12 months, and retirement in roughly 24. ASD's consistent advice through all of it: the investment you have made under the Essential Eight will still be relevant under the Essentials.
ASD distils its Strategies to Mitigate Cyber Security Incidents into a baseline of eight, designed for internet-connected enterprise IT.
The November 2023 release tightens patching windows (48 hours for critical vulnerabilities) and strengthens phishing-resistant MFA. It is still the current version.
ASD publishes Foundations for Modern Defensible Architecture with eight international partner agencies: ten architecture-first foundations, from reliable asset inventory to Secure-by-Design and continuous monitoring.
ASD opens consultation on the evolution of the Essential Eight into a broader Essentials series, grounded in the ISM. The first chapter is Essentials for enterprise IT; consultation ran to 12 July 2026.
ACSC officials, quoted by iTnews in June 2026, anticipate a transition period with both frameworks live, deprecation of the Essential Eight starting in roughly 12 months, and full retirement in roughly 24. ASD has published no calendar dates.
With Alvor
The Essential Eight ships as a framework pack in the Compliance module: the strategies become controls with named owners, evidence, and review dates, not a spreadsheet revisited before each assessment.
ComplianceASD's model is risk-based: exceptions are allowed, documented, and owned. In Alvor an exception is a risk register entry with an owner and an expiry, so the assessor sees a decision, not a gap.
Risk ManagementThe successor guidance is architecture-first: asset inventory, Secure-by-Design, continuous assurance. That is the shape of Alvor itself, so the transition lands on a system you already run, not a new project.
Security ArchitectureAlvor Advisory runs Essential Eight and Australian-context engagements: identity and access, APRA CPS 234 and CPS 230, and SOCI readiness, measured once and mapped across.
AdvisoryQuestions
Yes, gradually. On 15 June 2026 ASD opened consultation on evolving the Essential Eight into a broader Essentials series. ACSC officials, quoted by iTnews, anticipate a transition period with both frameworks live, deprecation of the Essential Eight starting in roughly 12 months and full retirement in roughly 24; ASD has published no calendar dates. As of September 2026 the framework is still live on cyber.gov.au and the PSPF mandate still applies.
ASD's new Essentials series, grounded in the Information Security Manual. The first chapter is Essentials for enterprise IT, which consulted through July 2026, with additional chapters to follow; press reporting points to operational technology and cloud next, and possibly a dedicated agentic AI chapter. The series draws on ASD's architecture-first Foundations for Modern Defensible Architecture.
Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. ASD selected them from its full mitigation catalogue as the baseline that most effectively blunts real-world attacks on internet-connected enterprise IT.
Non-corporate Commonwealth entities are mandated by the PSPF to reach at least Maturity Level 2 across all eight strategies, and to consider ML3 where their threat environment warrants it. Everyone else picks a risk-based target level; the rule that surprises teams is that a level only counts once every one of the eight strategies reaches it.
Yes, and that is ASD's own position, not ours. The consultation announcement says organisations already using the Essential Eight can expect strong alignment with their existing controls and investments, and ASD's Modern Defensible Architecture guidance says an organisation working toward a higher Essential Eight maturity level will be well placed to adopt the future guidance.
No. The Essential Eight has no certification scheme; assessment is something you perform or commission, and an independent assessment is only required where a directive, regulator, or contract demands one. What matters is being able to show the controls, the evidence, and the documented exceptions on any given day.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.