Two clocks are running, and most responsible entities are only watching one of them.
The first is the Enhanced CIRMP Rules, which commenced in June 2026. They give responsible entities in the affected asset classes until June 2028 to comply with a nominated cyber security framework.
The second is the Australian Signals Directorate, which has said it will retire the Essential Eight within about two years — deprecating it at roughly the twelve-month mark and retiring it at twenty-four.
Those windows overlap almost exactly. An entity that nominates the Essential Eight today is nominating a framework that may not exist by the time its compliance deadline arrives.
What is replacing it
The successor is a set of guidance ASD calls the Essentials series. Rather than one control set for everything, it splits into chapters by domain:
- Essentials for Enterprise IT — the direct evolution of the Essential Eight, and the first chapter out for consultation
- Essentials for Operational Technology
- Essentials for Cloud
- A possible further chapter on agentic AI
The stated shift is from prescriptive, technology-specific controls toward outcomes and intent. The reasoning is straightforward: the Essential Eight was written for on-premises corporate Windows fleets before cloud adoption was normal, and its controls do not map cleanly onto software-as-a-service or shared-responsibility environments.
Why this matters more in OT than anywhere else
There is going to be an ASD chapter written specifically for operational technology. For anyone running a control estate, that is the significant part of this announcement, and it is worth understanding why.
The Essential Eight has never fitted an operational technology environment well. Its assumptions are that you control the software, you can patch on your own schedule, your endpoints are general-purpose computers, and a user at a desk is the main way in. A control estate breaks all four. The software is vendor-supplied and vendor-certified. Patching is gated by outage windows and warranties. Half the endpoints are controllers rather than computers. And the most common way in is a maintenance contractor’s remote session.
Walk the eight against a control estate and the picture is consistent:
- Application control fits conceptually, because the software set is far more static than a corporate fleet. It is hard in practice, because a false positive stops a process rather than annoying an office worker.
- Patch applications and patch operating systems are the direct conflicts. Estates running well past vendor support are common, and the reason is usually that the process software was certified against that version.
- Configure Microsoft Office macro settings is normally out of scope inside the OT zone, because Office is not there.
- Restrict administrative privileges applies, and is usually where the real risk sits. Shared operator accounts, standing vendor access, and credentials in scripts are the normal condition.
- Multi-factor authentication is valuable at the boundary, particularly for remote vendor access. It is much harder inside the zone.
- Regular backups applies and is usually under-scoped: controller logic, device configuration and engineering project files matter as much as data.
An operator with excellent database backups and no copy of its PLC programs cannot recover the process. That is the kind of thing a control set written for OT would say, and the Essential Eight never did.
What to do now
Do not panic-switch. ASD has been explicit that existing Essential Eight investment is not wasted, and the new series is expected to align closely with the existing controls. The work you have done on access control, backups and patching is the same work.
Do not treat the nomination as settled either. Five frameworks sit on the list — ISO/IEC 27001, the Essential Eight, NIST CSF 2.0, C2M2 and the AESCSF. Until now the sensible selection criteria were fit and effort. Durability is now a third one. If two frameworks fit your environment equally, the one that will still exist in 2028 is the better nomination.
Get the boundary right, because that survives any framework change. The single most valuable thing in a risk management program is a written, defensible statement of which zone is which, what applies where, and what compensating controls cover the difference. That analysis carries across from the Essential Eight to whatever replaces it. A per-control compliance table does not.
Watch the OT chapter specifically. If you run a control estate, the Essentials for Operational Technology chapter is likely to be the first piece of ASD guidance that was actually written for your environment. Being ready to map onto it early is worth more than optimising against a framework being withdrawn.
The honest summary
Nothing about this is an emergency. The transition period is measured in years and the direction of travel is toward guidance that fits OT better than what exists today.
But the specific combination — a compliance deadline in 2028 and a framework retirement on roughly the same schedule — means the nomination decision is no longer a formality. It is worth ten minutes of thought now rather than a migration under time pressure later.
Working out which framework to nominate, or how the transition affects a program already built around the Essential Eight? Get in touch.