Skip to main content
Frameworks 6 min read

Essentials for Operational Technology: What We Know, and Why It Matters

ASD is replacing the Essential Eight with a domain-split Essentials series, and one chapter is written for operational technology. No draft exists yet. What is confirmed, what is not, why an outcomes-based model fits OT better than a maturity ladder, and what to do before it lands.

Darragh Downey

Principal Consultant, O/IT Cyber


Buried in the announcement that ASD will retire the Essential Eight is something more significant for anyone running a control estate: the replacement will include a chapter written specifically for operational technology.

That has not happened before. Australian government cyber guidance has, until now, been written for corporate IT and then handed to OT operators to adapt as best they could. A dedicated chapter changes the starting position.

What is confirmed

The replacement is a series ASD calls Essentials, split by domain rather than issued as one control set:

  • Essentials for Enterprise IT — the direct successor to the Essential Eight. Consultation closed in July 2026 and publication is the next step.
  • Essentials for Operational Technology — confirmed as a chapter, on the explicit basis that OT does not behave like enterprise IT and should not be governed as if it does.
  • Essentials for Cloud.
  • A possible fourth chapter on agentic AI.

The Essential Eight and the new series will run side by side, with deprecation beginning around twelve months from mid-2026 and full retirement at around twenty-four.

What is not confirmed

Being straight about this matters, because there is already commentary circulating that treats the OT chapter as though its contents are known.

No consultation date for the OT chapter has been published. No draft is available. No control set, no structure, no timeline beyond its position as the second chapter in the series. Anyone telling you what Essentials for OT requires is guessing.

What we can reason about is the design direction ASD has stated for the series as a whole, and that direction is genuinely relevant to OT.

The two design changes that matter most

Outcomes and intent, rather than prescriptive controls. The stated shift is away from technology-specific instructions towards what the control is meant to achieve, leaving organisations to meet it with whatever fits their environment.

For OT this is the difference between failing and passing. Under a prescriptive model, “patch applications within two weeks” is either met or not met, and in an estate where the vendor certifies against a specific version it is not met. Under an outcomes model, the question becomes whether you have addressed the risk that patching addresses — which segmentation, monitoring, restricted access and a replacement plan can legitimately answer.

Decoupling threat-informed controls from a fixed maturity ladder. This is the more interesting one. The Essential Eight’s ladder assumes all eight controls progress together, so an organisation blocked on one is held at that level regardless of everything else.

That assumption is precisely what breaks in OT. An operator can be genuinely strong on access control, backups, segmentation and monitoring, and still be pinned at the bottom by operating system patching it cannot perform without breaking vendor certification. A model that decouples the controls lets that operator report an accurate picture instead of a misleadingly poor one.

Why this matters commercially, not just technically

Responsible entities in the nine asset classes named by the Enhanced CIRMP Rules have until June 2028 to comply with a nominated cyber framework. The Essential Eight — the framework most commonly nominated — is withdrawn on roughly that schedule.

So the nomination decision is live now, and a chapter written for OT is a plausible destination for operators who nominated the Essential Eight and have been quietly struggling to make it fit. Worth watching for that reason alone.

What to do before it lands

Waiting is the wrong response. Most of the work that a control set for OT will ask for is work you should already be doing, and none of it is framework-specific.

Get the boundary written down. Which assets are in scope, where the operational environment stops and the enterprise begins, and which systems sit in between. Every framework asks this and none of them can help you until you have answered it. This transfers completely.

Finish the asset inventory. It gates everything downstream and it is the single most common reason an assessment stalls. Equipment installed across decades, controllers with no software inventory, SCADA estates assembled by acquisition. This will not get easier by waiting.

Map the dependencies. Which vendors have standing remote access, which suppliers are single-sourced, and what the interdependencies with other assets look like.

Build the evidence habit now. Whatever the chapter asks for, it will ask you to demonstrate it rather than assert it. Organisations that record what they do as they do it pass assessments that organisations relying on policy documents fail.

Document your compensating positions. For every control you cannot meet, write down why, what you do instead, and what the replacement plan is. Under an outcomes-based model that document stops being an admission and becomes your compliance argument.

Have a say in it

ASD ran the Enterprise IT consultation through the ACSC Partner Portal, and has indicated there will be further opportunities to contribute on the operational technology and cloud chapters.

If you run a control estate, that is worth acting on. The gap between guidance written for OT by people who operate it and guidance written for OT by people who do not is large, and consultation is the point at which that gets decided. The Essential Eight’s poor fit for OT was not malice — it was written for a different job, by people solving a different problem, and nobody in OT was in the room.

The honest summary

There is no emergency here and no draft to react to. What there is, is a stated intention to write control guidance for operational technology for the first time, on design principles that fit OT considerably better than what they replace.

The preparation that matters is not framework-specific. Boundary, inventory, dependencies, evidence. Do that, and whatever the chapter says when it arrives, you will be mapping onto it rather than starting from nothing.


Running a control estate and working out what to nominate before June 2028? Get in touch — this transition is most of what we are talking to operators about right now.

Share LinkedIn Email