ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Framework · Essential Eight

The Essential Eight, and what replaces it.

ASD's eight mitigation strategies are still the baseline Australian security programs are measured against, and the PSPF still mandates Maturity Level 2 for non-corporate Commonwealth entities. They are also evolving into the Essentials series. Here is the framework, the maturity model, and the transition, plainly.

Get DemoThe Retirement Timeline

The eight strategies

01

Patch applications

02

Patch operating systems

03

Multi-factor authentication

04

Restrict administrative privileges

05

Application control

06

Restrict Microsoft Office macros

07

User application hardening

08

Regular backups

The Strategies

Eight controls, chosen for effect.

ASD selected these eight from its full mitigation catalogue because they blunt the attacks that actually happen. They are designed for internet-connected enterprise IT; ASD itself notes they were not designed for OT or enterprise mobility.

01

Patch applications

Known vulnerabilities in the software people use every day, closed on a clock, with the tightest windows for internet-facing services.

02

Patch operating systems

The same discipline one layer down, so the platform the applications stand on is not the open door.

03

Multi-factor authentication

A stolen password stops being enough, with phishing-resistant MFA expected as maturity rises.

04

Restrict administrative privileges

Admin rights become scarce, requested, time-bound, and separate from everyday accounts.

05

Application control

Only approved executables, libraries, and scripts run. Everything else is denied by default.

06

Restrict Microsoft Office macros

Macros from the internet are blocked, and what remains runs only where a business case exists.

07

User application hardening

Browsers and productivity apps lose the legacy features attackers rely on, like ads for Java and web ads.

08

Regular backups

Backups happen, are tested, and cannot be modified or deleted by the accounts ransomware compromises.

The Maturity Model

Four levels, defined by the adversary,
not the checklist.

ML0

Weaknesses in overall posture

The starting state ASD assumes nothing about: gaps an adversary with commodity tooling can already use.

ML1

Commodity tradecraft

Mitigates actors using widely available tools and techniques against any target that presents itself.

ML2PSPF mandate

A modest step-up in capability

Actors willing to invest more in a specific target: better phishing, and workarounds for weak MFA. This is the level the PSPF mandates for non-corporate Commonwealth entities.

ML3

Adaptive tradecraft

Actors much less reliant on public tools and techniques. ASD is explicit that even ML3 will not stop sufficiently resourced adversaries.

The rules that surprise first-time implementers: you target one level and must reach it across all eight strategies before claiming it; the model is risk-based, so documented exceptions are legitimate; and there is no certification. Assessment is something you do, or commission, not a badge you buy.

The Transition

It is being retired. Slowly, deliberately, and on the record.

On 15 June 2026 ASD opened consultation on evolving the Essential Eight into a broader Essentials series, grounded in the ISM, with Essentials for enterprise IT as the first chapter. ASD's own announcement never says “retire”; that timeline came from ACSC officials, quoted by iTnews: a transition period with both frameworks live, deprecation starting in roughly 12 months, and retirement in roughly 24. ASD's consistent advice through all of it: the investment you have made under the Essential Eight will still be relevant under the Essentials.

2017

Essential Eight published

ASD distils its Strategies to Mitigate Cyber Security Incidents into a baseline of eight, designed for internet-connected enterprise IT.

Nov 2023

Current maturity model

The November 2023 release tightens patching windows (48 hours for critical vulnerabilities) and strengthens phishing-resistant MFA. It is still the current version.

Feb–Oct 2025

Modern Defensible Architecture

ASD publishes Foundations for Modern Defensible Architecture with eight international partner agencies: ten architecture-first foundations, from reliable asset inventory to Secure-by-Design and continuous monitoring.

15 Jun 2026

The Essentials series announced

ASD opens consultation on the evolution of the Essential Eight into a broader Essentials series, grounded in the ISM. The first chapter is Essentials for enterprise IT; consultation ran to 12 July 2026.

~2027–2028

Deprecation, then retirement

ACSC officials, quoted by iTnews in June 2026, anticipate a transition period with both frameworks live, deprecation of the Essential Eight starting in roughly 12 months, and full retirement in roughly 24. ASD has published no calendar dates.

With Alvor

Run the Essential Eight as a program, not a scramble.

Run the eight as a control set

The Essential Eight ships as a framework pack in the Compliance module: the strategies become controls with named owners, evidence, and review dates, not a spreadsheet revisited before each assessment.

Compliance

Document the exceptions properly

ASD's model is risk-based: exceptions are allowed, documented, and owned. In Alvor an exception is a risk register entry with an owner and an expiry, so the assessor sees a decision, not a gap.

Risk Management

Ready for the architecture era

The successor guidance is architecture-first: asset inventory, Secure-by-Design, continuous assurance. That is the shape of Alvor itself, so the transition lands on a system you already run, not a new project.

Security Architecture

Uplift with the advisory practice

Alvor Advisory runs Essential Eight and Australian-context engagements: identity and access, APRA CPS 234 and CPS 230, and SOCI readiness, measured once and mapped across.

Advisory

Questions

The transition, answered plainly.

Yes, gradually. On 15 June 2026 ASD opened consultation on evolving the Essential Eight into a broader Essentials series. ACSC officials, quoted by iTnews, anticipate a transition period with both frameworks live, deprecation of the Essential Eight starting in roughly 12 months and full retirement in roughly 24; ASD has published no calendar dates. As of September 2026 the framework is still live on cyber.gov.au and the PSPF mandate still applies.

ASD's new Essentials series, grounded in the Information Security Manual. The first chapter is Essentials for enterprise IT, which consulted through July 2026, with additional chapters to follow; press reporting points to operational technology and cloud next, and possibly a dedicated agentic AI chapter. The series draws on ASD's architecture-first Foundations for Modern Defensible Architecture.

Patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups. ASD selected them from its full mitigation catalogue as the baseline that most effectively blunts real-world attacks on internet-connected enterprise IT.

Non-corporate Commonwealth entities are mandated by the PSPF to reach at least Maturity Level 2 across all eight strategies, and to consider ML3 where their threat environment warrants it. Everyone else picks a risk-based target level; the rule that surprises teams is that a level only counts once every one of the eight strategies reaches it.

Yes, and that is ASD's own position, not ours. The consultation announcement says organisations already using the Essential Eight can expect strong alignment with their existing controls and investments, and ASD's Modern Defensible Architecture guidance says an organisation working toward a higher Essential Eight maturity level will be well placed to adopt the future guidance.

No. The Essential Eight has no certification scheme; assessment is something you perform or commission, and an independent assessment is only required where a directive, regulator, or contract demands one. What matters is being able to show the controls, the evidence, and the documented exceptions on any given day.

Get started

See how Alvor works for your role

Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.

Request DemoView Pricing
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • On-Premise Deployment
  • Security Architecture
  • Assets
  • Components
  • Dependency Mapping
  • Data Governance
  • Secure by Design
  • Security Design Review
  • Threat Modeling
  • Risk
  • Compliance
  • Policy
  • Security Management
  • Business Continuity
  • Third-Party Risk Management

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • PCI DSS
  • Essential Eight

Company

  • About
  • Advisory
  • Compliance
  • Blog
  • Security
  • Pricing
  • Compare

Legal

  • Privacy
  • Cookie Policy
  • Terms
  • Disclosure

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

LinkedIn