For almost a decade, "Are we Essential Eight compliant?" has been the default shorthand Australian organisations use for "are we taking security seriously?" That's about to change. The Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC) have confirmed the Essential Eight will be retired over the next two years and replaced with a new "Essentials series." For partners, this isn't a distant policy footnote. It's a live compliance conversation clients will start having over the next 24 months, and it's worth understanding the shape of it now.
Why the framework is being replaced
The Essential Eight was built for a different era of enterprise IT, one centred on on-premises infrastructure and comparatively predictable, conventional malware. ASD and ACSC have been direct about the limitation this creates today: a framework designed around static threat conditions struggles to keep pace with attackers who move faster than any periodically updated control list can, including threats shaped by AI, and with the shift toward cloud and SaaS environments that the original eight controls were never built to reflect.
There's a second, more practical frustration the change is meant to fix. Because new threat techniques have historically been folded into the existing maturity levels rather than addressed separately, organisations have periodically found their maturity rating slipping even though their actual security posture hadn't gotten any worse, simply because the goalposts moved underneath them. Separating the framework's threat-informed guidance from its fixed maturity ladder is intended to stop that from happening.
What's replacing it
The Essentials series takes a different structural approach to its predecessor. Rather than a fixed list of controls tied to specific technologies, it's built around outcomes and intent, giving organisations more room to meet the guidance using tools appropriate to their own environment.
It's being rolled out as a series of chapters covering distinct domains, starting with "Essentials for enterprise IT," with operational technology and cloud chapters to follow, and the possibility of a dedicated chapter addressing agentic AI further down the track. Consultation on the first chapter ran through the ACSC Partner Portal until 12 July 2026.
The transition timeline
This isn't a hard cut-over. ASD has confirmed that both the Essential Eight and the new Essentials guidance will run in parallel for a period, with the Essential Eight beginning to be progressively deprecated at around the 12-month mark and retired in full at around the two-year mark.
Importantly, ASD has been explicit that organisations who have already invested in Essential Eight maturity won't see that work discarded. The Essentials series is expected to align closely with the existing eight strategies, patching, MFA, restricting administrative privileges, application control, macro restrictions, user application hardening, and backups remain foundational regardless of what the framework is ultimately called.
What clients should be doing now
For clients who've built their security posture around Essential Eight maturity levels, the sensible approach during the transition is straightforward:
-
Keep maintaining current Essential Eight controls as normal; none of that investment is being made redundant.
-
Watch for each Essentials chapter as it's published, starting with enterprise IT.
-
Treat the overlap between the two frameworks as a head start rather than something to rebuild from scratch.
Ask their advisors, including their MSP or security partner, how the shift toward outcomes-based, threat-informed guidance might change what "good" looks like for their environment, particularly around cloud and AI-related risk.
What this means for MailGuard partners
A couple of things worth bringing into client conversations as this transition plays out.
First, several of the original eight strategies sit directly in email security's lane, restricting Office macros and hardening user-facing applications like browsers, PDF readers, and email clients exist specifically to reduce the ways a malicious email can turn into a compromise. As the Essentials series moves toward threat-informed, outcomes-based guidance rather than a static checklist, it's a natural opening to revisit whether a client's current email security layer is actually keeping pace with the threats driving this change in the first place, particularly AI-generated phishing and BEC content that's increasingly difficult to catch with signature-based filtering alone.
Second, this is a genuinely good moment for a client review, independent of any specific product conversation. A framework transition gives clients a legitimate, non-alarmist reason to revisit their security posture rather than waiting for an incident to force the issue. Partners are well placed to get ahead of that conversation now, while the Essentials guidance is still being published in stages, rather than fielding it reactively once the first chapter lands.
Keeping Businesses Safe and Secure
Prevention is always better than a cure, and one of the best defences is to encourage businesses to proactively boost their company's cyber resilience levels to avoid threats landing in inboxes in the first place. The fact that a staggering 94% of malware attacks are delivered by email, makes email an extremely important vector for businesses to fortify.
No one vendor can stop all email threats, so it's crucial to remind customers that if they are using Microsoft 365 or Google Workspace, they should also have a third-party email security specialist in place to mitigate their risk. For example, using a specialist AI-powered email threat detection solution like MailGuard.
For a few dollars per staff member per month, businesses are protected by MailGuard's specialist, AI-powered zero-day email security. Special Ops for when speed matters! Our real-time zero-day, email threat detection amplifies your client's intelligence, knowledge, security and defence.
MailGuard provides a range of solutions to keep businesses safe, from email filtering to email continuity and archiving solutions. Speak to your clients today to ensure they're prepared and get in touch with our team to discuss fortifying your client's cyber resilience.
Talk to us
MailGuard's partner blog is a forum to share information; we want it to be a dialogue. Reach out to us and tell us what your customers need so we can serve you better. You can connect with us on social media or call us and speak to one of our consultants.
Australian partners, please call us on 1300 30 65 10
US partners call 1888 848 2822
UK partners call 0 800 404 8993




