The Essential Eight is being retired. Here's why you don't need to panic
If you’ve spent the last few years being told the Essential Eight is the security benchmark to aim for, this week’s news might land like a brick: the Australian Signals Directorate has confirmed it’s retiring it. Cue the worry that the thing you were working towards is about to vanish, and you’re back to square one.
You’re not. This is an evolution, not a reset, and for a well-run small business it’s closer to a non-event than a crisis. Here’s what actually changed, and why the right response is to keep calm and keep going.
What ASD actually announced
On 24 June 2026, ASD said it intends to retire the Essential Eight within about two years and replace it with a broader “Essentials” series. Rather than one list, the new guidance is expected to come in chapters: one for enterprise IT, others for operational technology and cloud, and likely one dedicated to AI.
The timeline is gradual. The Essential Eight is expected to be deprecated in around 12 months and retired in around 24, and both the old and new guidance stay live during the changeover. ASD has opened consultation on the first chapter, Essentials for enterprise IT, with feedback due by 12 July 2026. So nothing switches off tomorrow, and nothing you’ve done is wasted.
Why they’re changing it
The Essential Eight was built for a different era of IT. It was designed around on-premises systems, back when most businesses ran their own servers in a cupboard down the hall. That world has moved to the cloud, to software you log into rather than install, and to a shared model where you and your providers each hold part of the responsibility. The old list doesn’t map cleanly onto that, and it was always a bit rigid for threats that now move fast and increasingly involve AI.
In other words, ASD isn’t admitting the ideas were wrong. It’s repackaging good advice for the way businesses actually work now.
The bit that matters: the fundamentals don’t change
Here’s the reassuring part. Strip away the framework names and the maturity ladders, and security for a normal business still comes down to the same handful of habits it always has:
- Multi-factor authentication on your accounts
- Keeping software and devices up to date
- Tested, offline backups
- Limiting who has admin rights
- Turning off risky old features and training your team
Those don’t disappear when the Essential Eight does. They’re exactly what the new guidance will be built on, just sorted differently. If you’ve been quietly getting the basics right, you’re already most of the way to whatever comes next. (We broke those basics down in the Essential Eight, explained for a business that isn’t a bank if you want the plain-English version.)
Why small businesses especially can relax
The Essential Eight, with its three maturity levels and detailed control sets, was really aimed at large and government organisations. For a small or medium business, it was often more than you needed and harder than it should be to act on. A lot of owners looked at it, felt vaguely guilty, and moved on.
If that’s you, there’s a more sensible fit. SMB1001 is a security standard built specifically for the size of business most of us run. Its current edition, SMB1001:2026, organises the same fundamentals (technology management, access management, backup and recovery, written plans, and staff training) into clear tiers a small business can actually reach and demonstrate. It’s voluntary, it sits alongside ASD’s guidance rather than replacing it, and it’s a recognised stepping stone on the way to bigger standards like ISO 27001 if you ever need them.
It’s worth being straight about how it works: the lower tiers (Bronze, Silver and Gold) are based on a director attesting that the controls are in place, not an independent audit. Only the top two tiers are externally audited. That’s not a weakness, it’s what makes it achievable for a small team, as long as the attestation is truthful and the controls are genuinely there and kept up. You can read the full breakdown on our SMB1001 page.
What to actually do now
- Don’t rip anything out. The Essential Eight is live for a couple more years, and the controls behind it are still good security.
- Keep doing the fundamentals. They’re framework-proof. Whatever the next acronym is, MFA, patching and backups will be in it.
- If you’re a small or medium business, get the basics organised under a standard built for your size. It’s more achievable than the enterprise framework and gives you something to show clients and insurers.
- Have it actively managed. The real risk isn’t the framework changing, it’s the basics quietly lapsing. Someone keeping them done matters more than which list they’re on.
The takeaway
Frameworks come and go. The fundamentals are boringly constant, which is the best thing about them. If your basics are solid and actively managed, this week’s headline is just that, a headline. Nothing you need to lose sleep over.
Want the basics sorted, whatever the framework's called?
SMB1001 packages the fundamentals into tiers a small business can actually reach. Book a free, no-obligation chat and we'll show you where you stand.