ASD's eight prioritised mitigation strategies, and the baseline named in most Australian government contracts. Being retired and replaced by the Essentials series.
The Essential Eight is a set of eight prioritised mitigation strategies published by the Australian Signals Directorate through the Australian Cyber Security Centre, designed to help organisations prevent, limit and recover from cyber incidents. It is the most widely referenced cyber baseline in Australia and appears by name in a great many government contracts, tenders and funding agreements.
The eight strategies are application control, patching applications, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, patching operating systems, multi-factor authentication, and regular backups. Implementation is measured in maturity levels, currently Maturity Level One through Three.
For a broader prioritised control programme beyond the eight strategies, see the CIS Controls. Use the named Essential Eight maturity level where a contract or policy requires it, and use CIS Controls to structure the wider uplift.
On 24 June 2026 ASD confirmed the Essential Eight will be retired and replaced by a new Essentials series: domain-specific guidance rather than a single universal checklist. Three domains have been confirmed — enterprise IT, cloud, and operational technology — with agentic AI mentioned as a possibility rather than a commitment. Public consultation on the first chapter, Essentials for Enterprise IT, closed on 12 July 2026.
ASD's indicative timeline is deprecation at around twelve months and full retirement at around twenty-four — roughly mid-2027 and mid-2028. Those are approximate figures given by ASD, not published calendar dates, and consultation remains open so the timeline can move. Both frameworks are expected to run in parallel through the transition.
The Essential Eight is live today. It remains what contracts and assessors reference, and ASD's stated position is that investment made under it carries forward.
The PSPF sets Essential Eight Maturity Level Two as the mandatory baseline for applicable Commonwealth entities.
Since the conclusion of assessments against the older top-four model in November 2025, all DISP members are required to achieve and maintain the full Essential Eight at Maturity Level Two across the corporate ICT environment used to deal with Defence. This applies from Entry Level upward and is where most DISP applicants encounter friction.
A named maturity level is a common contract condition well beyond Defence, across federal, state and local government engagements.
The Essential Eight has become a common shorthand for baseline cyber hygiene in Australia, well outside its original government audience.
Essential Eight uplift is measured in maturity levels, currently Maturity Level One through Three, assessed per strategy.
Driven by your contract, your regulator or your risk. Commonwealth entities are required at Maturity Level Two; DISP members must hold full Essential Eight at Maturity Level Two across the corporate ICT environment used to deal with Defence.
Maturity is assessed strategy by strategy, and the overall rating is limited by the weakest. Seven strategies at Maturity Level Two with one at Level One yields an overall Level One, which is where most organisations discover the gap between what they believed and what they can evidence.
Sequenced by effort against maturity gain. Patching cadence and application control are typically the two hardest, and the ones most often deferred.
The controls have to produce records. An assessor tests evidence, not intent, and "we do patch regularly" without a patch register does not survive.
Maturity decays. Patch windows slip, exceptions accumulate, new systems arrive outside the standard build. Sustaining a maturity level is a continuous obligation rather than a project.
Frame evidence around control outcomes and risk reduction rather than maturity level attainment alone. Evidence written that way carries into the Essentials series without rework.
Soveriq assesses maturity against evidence rather than self-assertion, builds the remediation roadmap sequenced by effort against maturity gain, and puts in place the evidence routines that make a maturity claim defensible at assessment.
On the transition, our position is the same as ASD's: keep going. We frame evidence around control outcomes so it carries into the Essentials series, and we help you find and triage the contract clauses that name a maturity level.
On internal review. Where Soveriq has performed the uplift, we do not then assess it and present that as independent assurance. What we provide is readiness validation, labelled as such, and where genuine independence is required it is performed by someone independent of that work and disclosed to you in writing.
What we will not do. Soveriq does not issue maturity certifications and does not promise an assessment outcome.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
No. ASD has been explicit that the framework remains live and supported through the transition, and that investment made under it carries forward. It is still what contracts, tenders and assessors reference today. Pausing now would leave you exposed and, for regulated entities, non-compliant.
ASD has given approximate figures rather than published calendar dates: deprecation around mid-2027, full retirement around mid-2028. Consultation is open and the timeline can move. Treat those as planning assumptions, not deadlines.
Search your contracts, tenders and funding agreements for a named Essential Eight maturity level. Those clauses do not update themselves, and when the framework retires somebody has to decide whether each obligation transfers, gets renegotiated or is already satisfied. It is the only part of this transition with a hard commercial consequence attached, and it is far easier now than in 2028.
Maturity is assessed per strategy and the overall rating reflects the weakest. Seven strategies at Maturity Level Two with one lagging still scores Maturity Level One. This is the mechanic that most often surprises organisations at assessment.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope