Compliance

The Essential Eight is being replaced. What Australian businesses should do now.

AD AWD Digital 12 Jun 2026 7 min read
Four colleagues working around a boardroom table beside floor-to-ceiling windows

ASD announced in June 2026 that the Essential Eight will be retired in favour of a new Essentials series over about two years. Here is what changes, what does not, and why the maturity work you do this year still counts.

The answer, up front

The short answer: keep going. Nothing you have already done stops counting. Patching, application control, multi-factor authentication and tested backups are controls, not paperwork, and they carry across whatever the framework ends up being called. A two-year transition is a long runway, not a reset.

The work worth pausing is anything you were doing purely to move a maturity number rather than to reduce risk. Everything else continues. ISO 27001 & Essential Eight is where the assessment and uplift work sits, Cyber Security is where the controls get operated day to day, and a national charity’s Essential Eight programme shows the sequence in practice.

Patching, application control, MFA and tested backups are controls, not paperwork. They carry across whatever the framework is called.

Why this matters now

For most Australian businesses, compliance has quietly moved from a back-office concern to a board-level one. The tools people rely on every day now sit across cloud services, personal devices and a supply chain of third parties, and the gaps between them are exactly where problems appear.

The teams that stay ahead are not the ones with the biggest budgets. They are the ones that treat this as an ongoing operating discipline rather than a project that finishes. That shift in mindset is what separates a setup that holds up under pressure from one that only looks fine until the day it does not.

What good looks like

When compliance is handled well, it tends to be invisible. The difference shows up in the details rather than the dashboards. A few markers to look for:

  • Clear ownership, so there is never a question of whose job a given task is.
  • Proactive maintenance and monitoring, so most issues are caught before anyone raises a ticket.
  • Documented, tested procedures that a new team member could follow under pressure.
  • Regular reporting in plain language, not a wall of metrics that hide the real story.

Want this handled for you?

Our engineers do this every day for businesses across Australia. Have a plain-English conversation about where you stand and what to fix first.

Get in touch

Where to start

You do not need to fix everything at once. Start with an honest assessment of where the real risk sits, then sequence the work so the highest-impact changes land first. That usually means shoring up the basics, closing the obvious gaps, and building the routine that keeps them closed.

From there, the work compounds. Each improvement makes the next one easier, and the environment gets steadily more resilient without a disruptive overhaul. If you would like a hand mapping that path for your business, we are happy to help.

Start here

Not sure where to start?

A no-obligation conversation about your infrastructure, security posture and operational risk. No lock-in, and a response within one business day.