E8
What is E8?
Essential Eight
Eight mitigation strategies published by the Australian Signals Directorate: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. Each is rated against Maturity Levels 0 to 3. It is one of the cyber security frameworks a responsible entity can nominate under the CIRMP Rules, which makes it the one most operators choose. Note that ASD has announced it will retire the Essential Eight within about two years, replacing it with a domain-split "Essentials" series that includes a chapter for operational technology. It was designed for corporate Windows fleets, so several of the eight need substantial qualification in a control system environment.
The eight strategies
Application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.
Each is rated against Maturity Levels 0 to 3. The levels are cumulative within each strategy, and an organisation is generally reported at the lowest level it achieves across all eight.
Why it is being retired
ASD has announced it will withdraw the Essential Eight within about two years, deprecating it at around the twelve-month mark. The replacement is a series called Essentials, split by domain: enterprise IT first, then operational technology, then cloud, with a possible further chapter on agentic AI.
The stated reason is that the Essential Eight was written for on-premises corporate Windows fleets before cloud adoption was normal, so its controls do not map cleanly onto software-as-a-service or shared-responsibility environments.
Where it fits badly in OT
A control system estate breaks the assumptions the model rests on. The software is vendor-supplied and vendor-certified, patching is gated by outage windows and warranties, many endpoints are controllers rather than computers, and the most common way in is a maintenance contractor's remote session rather than a user at a desk.
Application control fits conceptually because the software set is static, but a false positive stops a process. Operating system patching frequently cannot be performed at all where the process software was certified against a specific version. Backups need to cover controller logic and engineering project files, not only data.
What it means for a CIRMP nomination
The Essential Eight is one of the frameworks a responsible entity can nominate. Entities in the nine asset classes named by the Enhanced CIRMP Rules have until June 2028 to comply with their nominated framework, which is roughly when the Essential Eight is withdrawn.
Durability is therefore now a selection criterion alongside fit and effort. Existing Essential Eight work is not wasted: ASD has indicated the new series will align closely with the current controls.
Read more
- The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination
ASD will retire the Essential Eight within about two years, replacing it with a domain-split Essentials series that includes an operational technology chapter. The Enhanced CIRMP Rules give you until June 2028 to comply with a nominated framework. Those two clocks overlap, and it changes what you should nominate.
- Essentials for Operational Technology: What We Know, and Why It Matters
ASD is replacing the Essential Eight with a domain-split Essentials series, and one chapter is written for operational technology. No draft exists yet. What is confirmed, what is not, why an outcomes-based model fits OT better than a maturity ladder, and what to do before it lands.
See also
- CIRMP Critical Infrastructure Risk Management Program The risk management program that responsible entities must establish and maintain under the SOCI Act.
- IEC 62443 The international series of standards for the security of industrial automation and control systems.
- AESCSF Australian Energy Sector Cyber Security Framework A cyber security framework maintained by AEMO for the Australian energy sector, adapted from the US DOE C2M2.
- MIL Maturity Indicator Level The maturity scale used by C2M2 and by the AESCSF, running from MIL-0 to MIL-3.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.