




The Australian Government’s cyber strategy: A new dawn for the Essential Eight
The Essential Eight is one of the most significant cyber security frameworks in Australian history - and it's being retired. Here's what the new ASD Essentials series looks like, why the change is happening, and what your organisation needs to know right now.

Let’s start with a quick recap. In the first of this three-blog series, we discussed key changes from the Australian Government's seven-year national cyber security strategy, launched in 2023, and its three escalating phases, known as Horizons.
In this second blog, we discuss the move to retire the Essential Eight as laid out in Horizon 2. And take it from us – this is one of the most significant cyber security framework shifts in Australian history.
It will see the Essential Eight not just updated, but evolved into an entirely new series with new expectations. Of course, the big questions are: What will take its place, and what difference will it make?
The next horizon
In its Horizon 2 Action Plan, the Australian Signals Directorate (ASD) says it intends to retire the Essential Eight guidance framework within two years. While the ASD is yet to confirm the exact date, by our reckoning that puts it in mid-2028.
It will be replaced by a broader and entirely new ‘Essentials’ series. The series will cover enterprise IT, cloud, operational technology, and potentially agentic AI as distinct security domains. And at the same time, maturity-level expectations will rise across the economy.
Why the change?
ASD's reasoning is compelling.
Essential Eight's core limitation was structural. It was designed for a world where enterprise IT was still on-premises, and cloud adoption was in its infancy. As such, its controls don’t translate to today's shared-responsibility models and SaaS environments.
ASD has also acknowledged that shifting maturity-level requirements have given many organisations the impression they’re moving backwards on cyber security. The reality is that they haven’t experienced any actual deterioration in their security posture – but perception is critical.
The ASD Essentials series
The new Essentials series is far more than a framework refresh. It’s a rethink of how cyber security guidance should work.
The leading practical difference is flexibility.
Instead of telling you which controls to implement and how, the Essentials guidance describes the outcome you need to achieve – and it’s up to you how you get there. This means you don’t need to discard your existing tools and investments; you need to point them at the right outcomes.
This new guidance is grounded in ASD’s Information Security Manual (ISM), which is a risk-based control catalogue, not a compliance checklist. This is a significant change. In practical terms, that means the mitigations are prioritised and built around real threats found in modern environments. ASD will provide practical implementation guidance to support a smooth transition.
As for getting your team up to speed with the new Essentials, you won’t need to go it alone. To ensure appropriate governance awareness and training for all staff who access your systems, ASD says it will develop standards to guide your people through the proposed Essentials series for Enterprise IT.
The new Essentials series – how it’s structured
The Essentials framework will consist of three initial chapters:
Enterprise IT – first to be released
Operational Technology (OT)
Cloud
It’s widely anticipated that Agentic AI could also become a dedicated chapter – and with good reason. It would certainly be a logical extension given the distinct identity and access requirements for non-person entities (AI agents) operating on networks, and the threat posed by prompt injection.
Why call out prompt injection? Prompt injection has rapidly evolved into one of the most serious and fastest-growing threats facing organisations that have deployed AI agents. Featuring as the number one threat in OWASP’s Top 10 for LLM Applications, it manipulates AI models into ignoring their instructions, leaking data, or taking unintended actions. So, when AI agents have access to your files, systems, and internal processes, a single malicious input hidden in an email, document, or webpage can cause serious damage.
What's expected of your organisation under Essentials?
The Essentials series final guidance hasn’t been published yet; ASD is still reviewing submissions from government, industry, regulators, and organisations already using the Essential Eight. ASD expects to publish this guidance in late 2026.
However, while nothing has changed for now, ASD has signalled where things are headed.
The fixed maturity ladder will be replaced with expected security outcomes. This will take you from having to apply prescriptive controls tied to specific technologies, to achieving set security outcomes – with whichever tools you choose. In short: more flexibility, less prescription. Instead of being told what to do, you’ll be ‘judged’ on the results you’ve achieved – and the feeling of going backwards should be resolved.
What does this mean for your organisation, though?
Outcomes will outweigh evidence artefacts. If you’ve depended on artefacts like supplier screenshots to prove that you have application controls to reach your maturity level (but you don’t really know what risk that control exists to treat), you’re potentially in for a shock. Essentials is based on what you achieved, not what you installed.
More coverage to reflect cloud, SaaS, and AI.While the Agentic AI domain is yet to be confirmed (although we can’t imagine it wouldn’t be), dedicated cloud guidance will spell out what your shared responsibility with a cloud provider actually looks like in real life – using controls that didn’t exist earlier.
Your investment to date is safe. All of the work you’ve done to align with the Essential Eight will still be relevant to Essentials, says ASD. And if you’ve reached Maturity Level 1 or 2, those controls will map directly across.
What you need to be aware of now – under Horizon 2
While Essentials isn’t expected to become the new standard until 2028, there are other changes you need to be aware of under the Horizon 2 umbrella.
The Essential Eight Maturity Level 2 (ML2) is expected to become the recommended baseline for all industries by 2026 – not just the government. In practical terms, ML2 requires applying controls consistently and verifiably across your environment, rather than implementing them in pockets.
In a high-risk sector like critical infrastructure, energy, finance, or defence? Then ML3 is your new target. ML3 requires those controls to be resilient against sophisticated, targeted attacks, and requires you to provide evidence of continuous improvement.
What does this mean in practice?
Your asset and vulnerability management must be systematic, not reactive
Application control and patch management must be documented and auditable
Multi-factor authentication must extend to all privileged users and internet-facing systems
User application hardening and macro restrictions must be enforced and verified
The compliance burden for ML3 won’t just be technical either – you’ll need to provide evidence of your maturity, not just assert it.
Other key changes under Horizon 2
Even before the new Essentials series lands, ASD has already made significant changes to the existing framework since the November 2023 update. They include:
Critical patching: When vendors assess a vulnerability as critical, you must patch within 48 hours. And this applies across ML1 through ML3.
Faster high-risk application patching (browsers, email clients, PDF software, security software): This must now be completed within two weeks, tightened from one month (ML1).
MFA: There’s a new minimum standard requiring phishing-resistant MFA at ML2, and workstation authentication via phishing-resistant MFA (e.g. smart cards, Windows Hello for Business) at ML2 and ML3.
Event logging: This is now mandatory at ML2, including centralised collection, protection, and analysis.
Administrative privileges: Governance processes for privileged access to data repositories added across ML1–ML3, including break glass accounts.
What next?
In our final blog in this series, we’ll cover two Horizon 2 priorities: sovereign SOC and monitoring, and securing AI.
In the meantime, if anything in this or our earlier blog has raised questions about where your organisation sits, and where to from here, we're happy to help you work it out.
Get in touch – no obligation, just a straight conversation.


