Essential Eight Retirement: A Transition Roadmap to the ASD Essentials Series for Australian SMBs
The Essential Eight retirement is now official, and if you run a small or mid-sized business in Australia the headline can read like a warning. It is not. Handled well, the move to the new ASD Essentials series is the best excuse you have had in years to get your security in order, and the work you do now counts twice.
On 24 June 2026 the Australian Signals Directorate confirmed what the security industry had been expecting for months. The Essential Eight, the maturity model that has shaped Australian cyber security advice since 2017, will be retired. In its place comes a broader body of guidance called the Essentials series. For the better part of a decade the Essential Eight has been the shorthand every board, auditor and managed service provider reached for when someone asked "are we secure enough?" Replacing it is a big deal, and the questions have come thick and fast. Does our current work still count? Do we have to start again? What does an SMB with twenty staff actually do on Monday morning?
This whitepaper answers those questions in plain English. It explains what the Essential Eight retirement does and does not mean, sets out the timeline, introduces the Essentials series, and then gives you a practical ninety day transition roadmap built for small and mid-market organisations rather than for federal departments with dedicated security teams. Because most of the controls in question are configured inside Microsoft 365, we also map each one to exactly where it lives in your tenant, so you can see the work for what it is: specific, finite and worth doing.
What this whitepaper covers
- What the Essential Eight retirement actually means
- The timeline: two years, two frameworks at once
- Meet the Essentials series
- Why this is good news for Australian SMBs
- The eight controls are not going anywhere
- Where your controls already live: Microsoft 365
- A ninety day transition roadmap for SMB and mid-market
- Five mistakes to avoid during the transition
- How All IT helps you make the move
- Frequently asked questions
What the Essential Eight retirement actually means
The single most important thing to understand about the Essential Eight retirement is that it is a replacement, not a deletion. Chris Horlyck, head of cyber security resilience at the Australian Cyber Security Centre, put it plainly when he said the framework would be "replaced, not scrapped in place, by a broader body of guidance called the Essentials series." Nobody is switching the Essential Eight off and leaving Australian businesses with a blank page. The eight controls you may already be working towards remain current, remain the baseline, and remain the thing auditors and insurers will ask about for the foreseeable future.
So why change at all? The Essential Eight was designed for a world of on-premises Windows servers and desktop applications. It has aged well, but it has aged. Most Australian SMBs now run their business from cloud platforms, their staff work from laptops and phones that never touch the office network, and attackers have moved on from the techniques the model was first built to blunt. The ASD has been candid that a point-in-time maturity score, measured once a year and filed away, no longer reflects how security actually works. The Essentials series is the directorate's answer to that gap.
"Replaced, not scrapped in place, by a broader body of guidance called the Essentials series."
Chris Horlyck, Head of Cyber Security Resilience, Australian Cyber Security CentreFor a small business owner, the practical translation is reassuring. You will not wake up one morning to find the ground has shifted. There is a planned, public transition with both frameworks running side by side, and the direction of travel is towards guidance that is clearer about outcomes and more honest about the fact that security is a habit, not an annual event. The businesses that struggle will be the ones that read "retirement" as "permission to wait." The ones that thrive will treat it as a prompt to finish the uplift they have been meaning to get to.
The timeline: two years, two frameworks at once
The ASD has committed to retiring the Essential Eight within about two years of its June 2026 announcement. Current guidance points to deprecation around the twelve month mark, when the Essential Eight stops being actively developed, and full retirement around the twenty four month mark, when the Essentials series becomes the primary reference. Crucially, the two frameworks will operate at the same time during the transition. There is no cliff edge and no single changeover date that catches everyone out.
That overlap is deliberate, and it is good news for anyone planning a budget. It means you can continue an Essential Eight uplift program with confidence, knowing the investment is not wasted, while the Essentials series is published chapter by chapter and the market works out how to assess against it. The consultation for the first chapter, Essentials for Enterprise IT, closed on 12 July 2026, so the direct successor to the Essential Eight is already well advanced.
If your organisation has Essential Eight obligations written into a contract, a tender, a cyber insurance policy or a client agreement, those obligations do not evaporate on announcement day. Check the wording. Many agreements reference the Essential Eight Maturity Model by name, and until those documents are renegotiated the model still applies to you. This is one more reason the sensible response to the Essential Eight retirement is to keep going, not to down tools.
Meet the Essentials series
The Essentials series is not a single document. It is a family of guidance organised into chapters, each addressing a different kind of environment. This is a meaningful change from the Essential Eight, which tried to cover everything with one set of eight mitigation strategies. The first chapter, Essentials for Enterprise IT, is the direct successor and covers the familiar ground of corporate Windows and cloud environments. Further chapters for cloud and operational technology are forthcoming, and a chapter on agentic AI has been flagged as under consideration, which tells you how seriously the directorate is taking the security of automated and AI-driven systems.
The bigger shift is in philosophy. The ASD has described the Essentials series as taking a "prioritised, threat-informed, outcomes-based approach" that emphasises continuous validation rather than point-in-time assessment. Those are four ideas worth unpacking, because together they describe how your security program will be judged in the years ahead.
Prioritised
Not every control carries equal weight for every organisation. The Essentials series is expected to help you focus effort where it reduces the most risk for your specific situation, rather than treating all eight strategies as a flat checklist to be completed in order. For an SMB with limited time and budget, a model that tells you what to do first is genuinely useful.
Threat-informed
The guidance is being written against the techniques attackers are actually using in Australia right now, and it is expected to be updated as those techniques change. This is a move away from a static model towards living guidance that keeps pace with the threat landscape, which matters when ransomware crews refresh their playbooks every few months.
Outcomes-based
Instead of asking "have you deployed this specific tool in this specific way," outcomes-based guidance asks "can you demonstrate that the risk is controlled." That gives you room to achieve the same protection with the tools you already own, which is exactly what most Microsoft 365 customers want to hear.
Continuous validation
This is the big one. The Essential Eight was often assessed once a year, with a consultant producing a maturity score that was accurate on the day and slowly drifted out of date. Continuous validation means proving, on an ongoing basis, that your controls are working. In practice that means monitoring, alerting and regular checks baked into how you run the business, not a once-a-year scramble before the audit.
| Dimension | Essential Eight Maturity Model | ASD Essentials series |
|---|---|---|
| Structure | One set of eight mitigation strategies for all environments | Chapters per environment: Enterprise IT, cloud, OT, AI under consideration |
| Measurement | Point-in-time maturity level (0 to 3) | Continuous validation of outcomes |
| Approach | Prescriptive control checklist | Prioritised, threat-informed, outcomes-based |
| Update cadence | Periodic revisions | Living guidance updated against current threats |
| Status for SMBs | Current now | Rolling out through 2027 to 2028 |
Why this is good news for Australian SMBs
It is easy to read a framework change as more work. For most small and mid-market businesses, the opposite is true, and here is the differentiator worth holding onto: the Essentials series rewards exactly the kind of security that cloud-first SMBs are already well placed to deliver. If your business runs on Microsoft 365, you are closer to the new model than a large enterprise wrestling with twenty years of legacy servers.
Consider what "continuous validation" asks for. It asks that your controls be monitored and verifiable on an ongoing basis. A modern Microsoft 365 tenant already produces this. Microsoft Secure Score measures your configuration every day. Entra ID logs every sign-in and flags the risky ones. Intune reports in real time on which devices are patched and compliant. Defender raises alerts the moment something looks wrong. The telemetry the Essentials series will expect you to act on is sitting in your tenant right now, often switched on and unread. The large enterprise has to build this. The SMB on Microsoft 365 has to start reading it.
The outcomes-based approach helps too. Under a strict checklist, a small business can fail an assessment for not using a named, expensive tool even when it has achieved the same protection a cheaper way. Outcomes-based guidance asks whether the risk is controlled, which lets you lean on the capabilities bundled into the Microsoft 365 licences you already pay for. For a business watching every dollar, that is the difference between a security program that feels affordable and one that feels like a tax.
The eight controls are not going anywhere
Whatever the framework is called, the underlying controls are proven and are not being watered down. The Essentials for Enterprise IT chapter is the direct successor to the Essential Eight, and the eight mitigation strategies remain the core of good practice. It is worth restating them, because every one of them is work that pays off regardless of what the model is named.
- Application control. Only approved software is allowed to run, which stops most malware before it starts.
- Patch applications. Keep browsers, Office, PDF readers and other apps up to date so known holes are closed.
- Configure Microsoft Office macro settings. Block macros from the internet, a favourite delivery method for attackers.
- User application hardening. Turn off risky features such as Flash, ads and unneeded browser functions.
- Restrict administrative privileges. Give admin rights only to those who need them, and only when they need them.
- Patch operating systems. Keep Windows and other operating systems current, retiring anything out of support.
- Multi-factor authentication. Require a second factor for sign-in, the single most effective control against account takeover.
- Regular backups. Keep tested, recoverable backups so ransomware cannot hold your business to ransom.
None of this is going away. If anything, the Essentials series is likely to push these controls harder, because it will ask you to prove they are working rather than simply to confirm they are configured. The sensible reading of the Essential Eight retirement is that these eight habits are now permanent fixtures of running a business in Australia, and the smart move is to build them into how you operate rather than treating them as a project with an end date.
Where your controls already live: Microsoft 365
Here is the part most whitepapers skip. The eight controls are not abstract ideals. For a Microsoft 365 business they are settings in specific places, and once you know where they live the uplift stops feeling vague. The table below maps each control to where you configure it in a typical Microsoft 365 Business Premium tenant. If you have the licence, you very likely already own the tool.
| Essential Eight control | Where it lives in Microsoft 365 | Licence |
|---|---|---|
| Multi-factor authentication | Entra ID Conditional Access and security defaults | Business Premium |
| Restrict administrative privileges | Entra ID roles and Privileged Identity Management | Business Premium |
| Patch operating systems | Intune update rings and compliance policies | Business Premium |
| Patch applications | Intune app deployment and Microsoft 365 Apps update channels | Business Premium |
| Configure Office macro settings | Intune configuration profiles or Group Policy | Business Premium |
| User application hardening | Intune security baselines and Defender attack surface reduction rules | Business Premium |
| Application control | Defender for Endpoint and Windows Defender Application Control | Business Premium plus setup |
| Regular backups | Third-party Microsoft 365 backup, because native retention is not a backup | Add-on required |
Two things stand out. First, six of the eight controls are covered by a licence most Australian SMBs already hold, Microsoft 365 Business Premium. The uplift is often a configuration exercise, not a purchasing one. Second, backups are the exception. The retention and recycle bin features inside Microsoft 365 are not a backup, because they will not protect you against a determined ransomware attack, a malicious insider or a lapsed licence. A separate, tested backup is the one place most SMBs still need to spend, and it is the control attackers count on you skipping.
A ninety day transition roadmap for SMB and mid-market
You do not need a dedicated security team to respond well to the Essential Eight retirement. You need a plan with a start and an order. The roadmap below is built for a business with limited time, it assumes a Microsoft 365 environment, and it is sequenced so that the controls that block the most common attacks come first. Treat each phase as roughly thirty days.
Days 1 to 30: measure and lock the front door
You cannot improve what you have not measured. Start by reading your Microsoft Secure Score, which gives you an instant, outcomes-based picture of where you stand, and which is exactly the kind of continuous signal the Essentials series will expect you to act on. Then close the two gaps attackers exploit most.
- Record your Microsoft Secure Score and export the recommended actions as your working backlog.
- Enforce multi-factor authentication for every user, with no exceptions, using Conditional Access.
- Review admin accounts and remove standing admin rights from anyone who does not need them daily.
- Confirm a real backup of Microsoft 365 data exists and has been test-restored in the last quarter.
Days 31 to 60: patch, harden and standardise devices
With identity under control, turn to the devices your staff actually work on. This phase is where Intune earns its place in your licence by making patching and hardening automatic rather than something a person has to remember.
- Set Intune update rings so Windows and Microsoft 365 apps patch on a schedule you control.
- Block internet macros through an Intune configuration profile across all managed devices.
- Apply a security baseline and enable Defender attack surface reduction rules for user application hardening.
- Retire unsupported software and operating systems that can no longer receive patches.
Days 61 to 90: validate, monitor and write it down
The final phase is the one that aligns you with the Essentials series philosophy. You move from configuring controls to proving they work and keeping them that way. This is also where you make the program defensible to an auditor, an insurer or a client.
- Turn on alerting in Defender and Entra ID so risky sign-ins and threats are surfaced, not buried.
- Schedule a monthly Secure Score review so validation becomes a habit rather than an annual event.
- Document your controls in a short register that records what is configured, where, and who owns it.
- Run a restore test and record the result, so your backup claim is evidence rather than a hope.
At the end of ninety days you will have closed the gaps that matter most, you will have the eight controls configured in the tools you already own, and you will have the monitoring and documentation that turn a point-in-time score into the continuous validation the Essentials series is built around. You will not have to start again when the new guidance lands. You will already be living it.
Five mistakes to avoid during the transition
The transition window is generous, which creates its own risk. Here are the mistakes we see most often when a framework changes, and how to sidestep them.
1. Treating retirement as a reason to pause
The most expensive mistake is reading "the Essential Eight is being retired" as "security can wait." The controls are current, the threats are current, and attackers do not pause for consultation periods. A ransomware crew does not care which framework you file your maturity score under.
2. Confusing native retention with a backup
The recycle bin and retention policies in Microsoft 365 are not a backup. If you have ticked the backup control on the strength of them, you have a gap you will only discover during an incident, which is the worst possible time.
3. Scoring once and filing it away
A maturity assessment that lives in a drawer is already out of date. The Essentials series is built around continuous validation for a reason. Build a monthly rhythm now so you are not caught out later.
4. Buying tools you already own
Many SMBs buy a standalone product to satisfy a control that Microsoft 365 Business Premium already covers. Check what your licence includes before you spend. The uplift is usually configuration, not procurement.
5. Forgetting that people are a control
The strongest technical configuration can be undone by one person clicking one link. Awareness and reporting culture are not in the eight controls by name, but they decide whether your controls hold up under pressure.
It is worth remembering why this matters beyond compliance. Ransomware hit one in three Australian organisations in the last year, and a quarter of staff say they would not report a mistake that let an attacker in. The Essential Eight retirement does not change that risk. It simply gives you a well-timed reason to do something about it.
How All IT helps you make the move
All IT works with small and mid-market businesses across Australia, and almost all of them run on Microsoft 365. That is the sweet spot for responding well to the Essential Eight retirement, because the controls the Essentials series cares about are already within reach in your tenant. We start by measuring where you stand with Secure Score, we close the gaps in a sensible order using the ninety day roadmap above, and we put the monitoring and documentation in place so your security stands up to an auditor, an insurer or a client without a last-minute scramble.
The point is not to chase a maturity number for its own sake. It is to make your business genuinely harder to attack, using the tools you already pay for, in a way that keeps working after the framework changes name. If you also carry obligations under the Privacy Act or a client contract, we help you line those up with the same program rather than running three overlapping projects. The Essential Eight retirement is a prompt. The outcome we aim for is a business that is secure by habit, not by audit.
ASD to retire Essential Eight within two years, consults on replacement, Australian Cyber Security Magazine
Essential Eight: What Organisations Should Expect in 2026, TechRepublic
Essential Eight, Australian Signals Directorate
Frequently Asked Questions
Is the Essential Eight being scrapped?
No. The Australian Signals Directorate has said the Essential Eight will be replaced, not scrapped in place, by a broader body of guidance called the Essentials series. The eight controls stay current and enforceable throughout the transition, so there is no point at which you are left with nothing to comply with.
When will the Essential Eight be retired?
ASD confirmed on 24 June 2026 that it plans to retire the Essential Eight within about two years. Current guidance points to deprecation around the twelve month mark and full retirement around twenty four months, with both frameworks operating at the same time during the transition.
What is the ASD Essentials series?
The Essentials series is a broader set of guidance that takes a prioritised, threat-informed and outcomes-based approach to security. It is organised into chapters for different environments, starting with Essentials for Enterprise IT, with cloud, operational technology and agentic AI chapters flagged to follow. It favours continuous validation over point-in-time assessment.
What should my business do right now?
Keep uplifting the eight core controls, because they are unchanged and still required. The fastest way for a small or mid-sized business to do that is inside Microsoft 365, where multi-factor authentication, patching, application control, macro settings and admin restriction are all configured. Doing this work now positions you for the Essentials series automatically.
Not sure where your eight controls stand?
We will measure your Microsoft 365 tenant against the eight controls, show you the gaps in plain English, and give you a ninety day plan to close them before the Essentials series lands.
