Spirit Managed Services is now branded Infotrust.
Cyber Emergency Number:
IT Support Number:
Blog

Preparing for Changes to the Essential Eight Framework

Josh Pain
September 2, 2026
Home

Let's Get STARTED

The Australian Signals Directorate (ASD) has launched a consultation on the evolution of the Essential Eight, signalling the next stage in one of Australia's most widely adopted cyber security frameworks. The proposals are designed to make the guidance more flexible and scalable, helping organisations apply the right security controls for their environment while maintaining the same core objective: reducing cyber risk.  

The proposed changes have already sparked discussion across the cyber security community. At the same time, developments surrounding the US Cybersecurity Maturity Model Certification (CMMC) programme have highlighted a broader point. Compliance frameworks will continue to evolve as technology and threats change.  

Whether you're already aligned with the Essential Eight or planning your first implementation, taking stock of your existing controls now will make any future alignment significantly easier.

Understanding the Proposed Framework

The proposed Essentials series is not simply a renamed version of the Essential Eight. It represents a broader shift in how the ASD intends to present cyber security guidance, moving away from a fixed set of highly prescriptive controls towards clearer security outcomes that organisations can achieve in ways suited to their own technology and risk profile.

The current Essential Eight guidance will become the first chapter of the series, titled Essentials for enterprise IT. Further chapters are expected to address other technology environments as the series develops. Like the existing framework, the new guidance will be grounded in the Information Security Manual (ISM) and informed by the ASD’s understanding of the threats facing Australian organisations.

The ASD has described the proposed framework through four core attributes:

  • Flexible: organisations will have more choice in how they achieve the required security outcomes, rather than being tied to a single technical approach.
  • Threat-informed: the guidance will reflect the ASD’s threat intelligence and incident response experience helping organisations improve their defences.
  • Compatible: existing Essential Eight controls and investments should remain relevant, while closer alignment with the ISM will also support organisations working across other cyber security frameworks.
  • Future-focused: the series can expand as technology and threats change, without requiring the entire framework to be redesigned each time.

For organisations, this should mean greater flexibility and a more practical way to apply security guidance across various technology environments and different levels of risk. It may also make the framework more accessible to organisations that found some of the existing requirements difficult to apply outside a traditional enterprise IT setting.

Importantly, flexibility does not mean weaker security. The way controls are described and assessed may change, but the intended outcomes remain familiar: limiting attacks, protecting assets, reducing the impact of compromise and improving recoverability.

The consultation on Essentials for enterprise IT closed on 12 July 2026. While the ASD has not yet confirmed when the final guidance will be published, now is the ideal time for organisations to review how their existing controls and evidence may align across various standards and frameworks.  

Preparing Your Organisation for the Changes

There is no need to wait for the final guidance before preparing. ASD has indicated that existing Essential Eight controls and investments will remain strongly aligned with the proposed Essentials series. The more useful question is whether those controls are operating consistently and producing evidence that can stand up to scrutiny.

For organisations already using the Essential Eight, preparation should begin with a practical review of the current maturity assessment, looking closely at areas where ownership is unclear or evidence is difficult to produce. While a control may appear complete on paper it can still depend on manual processes or outdated configurations.

Meanwhile, businesses at an earlier stage shouldn’t use the consultation as a reason to delay. The current Essential Eight remains a strong basis for improving cyber security, and the proposed framework is intended to build on that foundation rather than replace it. Starting now will make it easier to adapt once ASD confirms the final guidance.

This is also where a broader governance, risk and compliance (GRC) programme becomes useful. Rather than treating each framework as a separate exercise, organisations can map shared controls across various frameworks and standards e.g. Essential Eight, the ISM, ISO 27001 and CMMC, to name a few. The requirements are not identical, but the outcomes are and there is enough overlap to reduce duplicated work and create a clearer view of how well controls are operating.

What Your Business Should Do Next

The proposed evolution of the Essential Eight changes how the guidance may be structured, but not the security outcomes it is designed to support. Organisations that understand how their controls are working today and those who put the effort into cross-mapping across frameworks and standards, will be in a far stronger position when ASD publishes any updates or changes.

This should be treated as a governance opportunity, not simply another compliance exercise. A useful next step is to revisit the current maturity assessment and test whether the supporting evidence reflects what is happening in practice. Any weaknesses that emerge can then be worked into a realistic improvement plan.

If you need help interpreting the proposed changes or deciding where to focus first, reach out to Infotrust for a consultation.