SecureLoop
Cloud Security6 min read

The Essential Eight Is Being Retired: What It Means for Small Business

In June 2026 the Australian Signals Directorate confirmed it will replace the Essential Eight with a new β€œEssentials” series. If you run a small business, the honest answer to β€œdo I still need to bother?” is yes β€” and here's why the change matters less than the headline suggests.

Here's the news in one line: on 24 June 2026, the Australian Signals Directorate (ASD) confirmed the Essential Eight β€” the cyber security baseline nearly every Australian business has been pointed at for years β€” is being retired and replaced by a new, multi-chapter framework called the Essentials series. Understandably, a lot of small business owners saw that and thought: great, I've been meaning to sort out my security, and now the goalposts are moving before I even start.

Don't let it stall you. The change is real, but it's staged, it's slow, and β€” this is the part that matters β€” it's designed so the work you do now carries across. Let's walk through what's actually happening and what you should do about it.

What's actually changing

The ASD is moving from the Essential Eight's fixed list of eight technical controls to a broader, outcomes-based set of guidance called the Essentials series. Instead of β€œdo these eight specific things,” the new approach leans toward β€œachieve these security outcomes in a way that fits your environment.” It's being released in chapters β€” enterprise IT first, then areas like operational technology and cloud β€” rather than as one document on one day.

The reasoning is straightforward once you hear it. The Essential Eight was built for a 2017 world of Windows computers sitting in an office. Most small businesses now run on cloud services β€” Microsoft 365, Google Workspace, Xero, and a dozen web apps β€” where some of the original eight controls map awkwardly or not at all. The new framework is an acknowledgement that security guidance needs to fit how businesses actually operate today: cloud-first.

The timeline: this is a slow change, not a switch-off

The single most important thing to understand is that the Essential Eight is not disappearing overnight. The ASD has described a staged transition running over roughly two years, with the two frameworks sitting side by side as live guidance while everyone moves across. Current signals point to the Essential Eight beginning to be wound down around the middle of 2027 and fully retired around 2028 β€” and even those dates come with the ASD's own caveat that they may shift.

For a small business, that's a long runway. Anything you do to improve your security against the Essential Eight today will be relevant for years, not months.

Why you should still care about the Essential Eight right now

Three reasons, all practical:

It's still the current, supported baseline

Until the transition completes, the Essential Eight is the live standard the ASD stands behind. It hasn't changed β€” the eight controls are exactly what they were.

It's still what other people measure you against

Government tenders, larger clients doing due diligence, and β€” increasingly β€” cyber insurers all reference Essential Eight maturity. That doesn't change the day the framework starts transitioning. If you want the contract or the cover, the Essential Eight is still the yardstick.

The work carries across

The ASD has been explicit that Essential Eight investment won't be wasted β€” the new Essentials series is expected to align closely with the existing controls. Multi-factor authentication, patching, backups and admin restriction don't stop mattering because the framework's name changes.

The quiet win: the change validates how small businesses should already be thinking

Here's the part worth sitting with. The reason the ASD is moving away from the Essential Eight is that it was built for on-premises Windows and doesn't fit cloud and SaaS. The new framework is, in effect, the government catching up to where small businesses already live: in the cloud.

If your security thinking has been anchored on the cloud services you actually use β€” securing Microsoft 365 properly, controlling who has access to what, keeping data resident and backed up β€” you're already aligned with the direction the whole framework is heading. The transition isn't a reason to wait. It's confirmation that cloud-first security is the right foundation.

What to do about it (short version)

Nothing about the retirement announcement changes the sensible next step: find out where you stand against the Essential Eight as it exists today, and fix your weakest controls first. Multi-factor authentication and tested backups remain the highest-impact place to start, exactly as they were.

Our free Essential Eight self-check gives you a plain-English maturity read in about five minutes β€” no signup β€” and shows the one control holding your baseline back. For the Microsoft 365 side specifically, the free M365 security check goes deeper.

We're tracking the Essentials series as the ASD publishes each chapter, and we'll add practical, small-business guidance as the real detail lands rather than guessing ahead of it. For now, the Essential Eight is still the map β€” and it still points the right way.

This article summarises publicly announced ASD guidance as at July 2026. Transition dates are indicative and subject to change by the ASD. It is general information, not security or compliance advice.

See where you stand today

Five minutes, no signup β€” a plain-English read on your Essential Eight maturity and the weakest control to fix first.

Brisbane QLD Β· Serving all of Australia