Skip to content

Security1 publisher2 min readPublished

ASD starts steering Australian organisations off the Essential Eight in mid-2027

Australia's replacement Essentials series covers the cloud, identity and OT that eight on-premises controls never touched. Both frameworks stay live until full retirement around mid-2028, and ASD calls those dates targets.

The Watch · Security desk

Illustration accompanying ASD starts steering Australian organisations off the Essential Eight in mid-2027

What happened

  • ASD said in June 2026 that it will replace the Essential Eight with an outcomes-focused Essentials series covering enterprise IT, cloud, operational technology and potentially agentic AI.
  • Deprecation is expected to begin around mid-2027, when ASD starts steering organisations toward the new framework.
  • Full retirement of the Essential Eight follows about a year later, around mid-2028, with both frameworks remaining live through the transition.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Contract and insurance language written against "Essential Eight compliance" points at a framework that retires around mid-2028, and the successor obligation for the 98 mandated entities is still unconfirmed.
  • decision Security teams have to decide whether to fund evidence collection for identity, SaaS, cloud and OT outcomes now, given that none of it can be lifted from an existing Essential Eight assessment.
  • contradiction Tenable presents the change as the end of point-in-time compliance, while the same post never says when compliance switches over. A 2027 spending line for continuous evidence rests on customer and insurer expectations, not a regulatory deadline.
  • constraint Chapter-by-chapter guidance limits how far a single control baseline can be applied across an estate, since each environment carries its own outcomes.

The Essentials series is built as chapters, each with its own outcomes-based guidance [3]. The first covers enterprise IT and folds in identity and access along with SaaS such as Microsoft 365 and Google Workspace [3]. Cloud and OT chapters follow, and an agentic AI chapter is flagged as likely [3].

The Essential Eight was eight named technical controls, application control and patching among them, and its coverage stopped at on-premises enterprise IT [2]. Identity, cloud and OT sat outside it [2]. An organisation holding a clean Essential Eight assessment therefore has no prior evidence to reuse for the chapters that cover those environments [15].

June 2026 to mid-2028 is about 24 months, and both frameworks are live for all of it [4][6][14]. Mid-2027 is the point at which ASD begins actively steering organisations toward the new framework, not a date by which compliance must switch over [5]. ASD has described the timelines as targets [7].

The Protective Security Policy Framework requires the Essential Eight for roughly 98 non-corporate Commonwealth entities [8]. For private-sector organisations it is voluntary guidance, and the pressure comes from insurers, customers and contracting government agencies that expect it [9]. Whether the government mandate transfers to the Essentials series has not been confirmed [10].

The argument that periodic point-in-time assessments stop working is Tenable's. Tenable says posture in environments spanning IT, cloud, identity and OT can change quickly and repeatedly between assessments [16], and that the shift pushes organisations toward continuous evidence of their posture [11]. Its recommended answer is exposure management [12]. The post summarises ASD's plan without reproducing an ASD document or quoting a named ASD official [13].

For the 98 PSPF entities, the work available now is mapping which existing Essential Eight evidence carries into the enterprise IT chapter, and the published timetable gives them until at least mid-2027 to do it [5][8][15].

What to watch

  • Whether the Protective Security Policy Framework is amended to require the Essentials series for the 98 non-corporate Commonwealth entities, and from what date.
  • Publication of the enterprise IT chapter, and whether it specifies what evidence identity and SaaS outcomes require.
  • Whether ASD moves the mid-2027 deprecation start, having called its timelines targets.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories