Independent Essential Eight gap assessment, maturity uplift and evidence for Australian organisations — and planning for the transition to ASD’s new Essentials series.
On 24 June 2026 the Australian Signals Directorate confirmed that the Essential Eight will be replaced by a new Essentials series. The first chapter, Essentials for Enterprise IT, is the direct evolution of the Essential Eight and was in public consultation until 12 July 2026. Further chapters covering cloud, operational technology and AI are expected to follow.
The transition is deliberately staged. Both frameworks run in parallel, with ASD beginning to deprecate the Essential Eight around 2027 and retiring it fully around 2028. There is no hard cut-off forcing organisations to move immediately.
The practical advice is straightforward: do not stop your Essential Eight work. Existing obligations still apply, government supplier contracts still reference the Essential Eight, and the controls underneath the Essentials series are an evolution of the same eight mitigation strategies rather than a clean break. Organisations that reach Maturity Level Two now will be in a strong position when the new chapters land. Organisations that pause and wait will simply have less time later.
The Essential Eight are eight mitigation strategies published by ASD: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups.
Each strategy is assessed against four maturity levels, from Maturity Level Zero (significant weaknesses) through to Maturity Level Three (aligned against more capable adversaries). Maturity is assessed per strategy, and your overall posture is generally read at the weakest of the eight — which is why organisations that have invested heavily in a few strategies often still report a low overall maturity.
Non-corporate Commonwealth entities are required under the Protective Security Policy Framework to implement all eight strategies to at least Maturity Level Two, an obligation that has applied since 1 July 2022. Maturity Level Three is expected where the threat environment warrants it.
Beyond the Commonwealth, the Essential Eight reaches most organisations through contract. State agencies, universities, health services and prime contractors routinely require suppliers to evidence a maturity level, and increasingly ask for independent assessment rather than self-attestation.
It is worth being realistic about the baseline: ASD’s own Commonwealth Cyber Security Posture reporting has repeatedly shown many entities still short of Maturity Level Two across all eight strategies, years after the deadline. If you are behind, you are not unusual — but the gap is measurable and closing it is a defined piece of work.
Where the Essential Eight sits alongside other obligations, our ISO 27001 implementation and certification support and cyber security maturity assessment and uplift advisory cover the wider programme.
No. Existing PSPF obligations and contractual requirements still apply, and the Essentials series evolves the same eight mitigation strategies rather than replacing them with something unrelated. Work done now carries across. The organisations that will struggle are those that pause for two years and then face a compressed transition.
Non-corporate Commonwealth entities need Maturity Level Two across all eight strategies under the PSPF, with Level Three where the threat environment warrants it. Everyone else should check their contracts — the required level is usually specified there, and paying for Level Three when a customer asked for Level Two is a common and avoidable expense.
You can, and ASD publishes the maturity model openly. The difficulty is that self-assessments tend to be generous, particularly on application control and administrative privilege restriction, and an assessor or customer reviewing your evidence will apply the wording strictly. An independent assessment tells you what someone else will conclude.
It depends almost entirely on where you start and how your environment is managed. Reaching Maturity Level Two from a low base is typically a six to eighteen month programme, with application control and macro restriction usually the longest items because they affect how people work day to day.
Whether you need an independent assessment, a route to Maturity Level Two, or a plan for the move to ASD Essentials, we can set out what is actually required. Get in touch.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.