Essential Eight Compliance & Assessment Services

Independent Essential Eight gap assessment, maturity uplift and evidence for Australian organisations — and planning for the transition to ASD’s new Essentials series.

The Essential Eight is being retired — what that means for you

On 24 June 2026 the Australian Signals Directorate confirmed that the Essential Eight will be replaced by a new Essentials series. The first chapter, Essentials for Enterprise IT, is the direct evolution of the Essential Eight and was in public consultation until 12 July 2026. Further chapters covering cloud, operational technology and AI are expected to follow.

The transition is deliberately staged. Both frameworks run in parallel, with ASD beginning to deprecate the Essential Eight around 2027 and retiring it fully around 2028. There is no hard cut-off forcing organisations to move immediately.

The practical advice is straightforward: do not stop your Essential Eight work. Existing obligations still apply, government supplier contracts still reference the Essential Eight, and the controls underneath the Essentials series are an evolution of the same eight mitigation strategies rather than a clean break. Organisations that reach Maturity Level Two now will be in a strong position when the new chapters land. Organisations that pause and wait will simply have less time later.

What the Essential Eight requires

The Essential Eight are eight mitigation strategies published by ASD: patch applications, patch operating systems, multi-factor authentication, restrict administrative privileges, application control, restrict Microsoft Office macros, user application hardening, and regular backups.

Each strategy is assessed against four maturity levels, from Maturity Level Zero (significant weaknesses) through to Maturity Level Three (aligned against more capable adversaries). Maturity is assessed per strategy, and your overall posture is generally read at the weakest of the eight — which is why organisations that have invested heavily in a few strategies often still report a low overall maturity.

Who has to comply

Non-corporate Commonwealth entities are required under the Protective Security Policy Framework to implement all eight strategies to at least Maturity Level Two, an obligation that has applied since 1 July 2022. Maturity Level Three is expected where the threat environment warrants it.

Beyond the Commonwealth, the Essential Eight reaches most organisations through contract. State agencies, universities, health services and prime contractors routinely require suppliers to evidence a maturity level, and increasingly ask for independent assessment rather than self-attestation.

It is worth being realistic about the baseline: ASD’s own Commonwealth Cyber Security Posture reporting has repeatedly shown many entities still short of Maturity Level Two across all eight strategies, years after the deadline. If you are behind, you are not unusual — but the gap is measurable and closing it is a defined piece of work.

How we help

  • Essential Eight gap assessment — independent assessment of current maturity across all eight strategies, with evidence reviewed rather than assumed.
  • Maturity uplift roadmap — a sequenced plan to reach your target level, prioritised by risk reduction per dollar rather than by which strategy is easiest.
  • Evidence and reporting — the centrally logged, demonstrable evidence Maturity Level Two actually requires, in a form that survives review.
  • ASD Essentials readiness — mapping your current Essential Eight position onto the emerging Essentials for Enterprise IT chapter, so the transition is an update rather than a restart.
  • Contract and tender support — clear, accurate maturity statements for procurement responses.

Where the Essential Eight sits alongside other obligations, our ISO 27001 implementation and certification support and cyber security maturity assessment and uplift advisory cover the wider programme.

Frequently asked questions

Should we stop Essential Eight work now that it is being retired?

No. Existing PSPF obligations and contractual requirements still apply, and the Essentials series evolves the same eight mitigation strategies rather than replacing them with something unrelated. Work done now carries across. The organisations that will struggle are those that pause for two years and then face a compressed transition.

What maturity level do we need?

Non-corporate Commonwealth entities need Maturity Level Two across all eight strategies under the PSPF, with Level Three where the threat environment warrants it. Everyone else should check their contracts — the required level is usually specified there, and paying for Level Three when a customer asked for Level Two is a common and avoidable expense.

Can we self-assess?

You can, and ASD publishes the maturity model openly. The difficulty is that self-assessments tend to be generous, particularly on application control and administrative privilege restriction, and an assessor or customer reviewing your evidence will apply the wording strictly. An independent assessment tells you what someone else will conclude.

How long does uplift take?

It depends almost entirely on where you start and how your environment is managed. Reaching Maturity Level Two from a low base is typically a six to eighteen month programme, with application control and macro restriction usually the longest items because they affect how people work day to day.

Talk to us about your Essential Eight position

Whether you need an independent assessment, a route to Maturity Level Two, or a plan for the move to ASD Essentials, we can set out what is actually required. Get in touch.