Still the baseline insurers and tenders expect. Also being replaced. Here is what to do about both.
Resources / Essential Eight Guide
The Essential Eight is still the standard Australian small businesses are measured against, and it is being replaced. In June 2026 the Australian Signals Directorate announced the framework will evolve into a new Essentials series, with the current Essential Eight carrying over as its first chapter. Insurers and tenders have not stopped asking for it in the meantime. This guide covers what the Essential Eight asks of a small business today, what is changing and when, and why nothing you implement now is wasted.
the ASD's baseline for stopping most real-world attacks
the maturity level most small businesses actually need
until the Essential Eight name is retired for the Essentials series
The Essential Eight is the Australian Signals Directorate's list of the eight security controls that stop the large majority of real-world attacks. It is government guidance, not legislation, and it is published for free at cyber.gov.au.1 Here is each control translated for a small team, ordered by where we suggest starting:
| Control | What it means for a small business |
|---|---|
| Multi-factor authentication | A second check (an app prompt or code) on top of passwords. The single highest-value control on the list. |
| Regular backups | Backups that run automatically, are kept where ransomware cannot reach them, and are actually test-restored. |
| Patch applications | Your software updates itself promptly, especially browsers, email and anything internet-facing. |
| Patch operating systems | Windows and macOS updates applied within a defined window, not deferred indefinitely. |
| Restrict administrative privileges | Day-to-day accounts are not administrators. Admin rights are separate, limited and reviewed. |
| Application control | Only approved software runs on your machines. The hardest control for small teams; do it last. |
| Configure Microsoft Office macro settings | Macros from the internet are blocked. Most businesses can block macros entirely and never notice. |
| User application hardening | Browsers and PDF readers configured to remove risky features attackers rely on. |
Each control is measured at four maturity levels, from Level 0 (not implemented) to Level 3 (hardened against advanced attackers).2 Maturity Level 1 is the practical baseline for most small businesses: it means the basics are genuinely in place, not perfect, and it is what insurers and larger customers generally mean when they ask if you "do the Essential Eight". Level 2 becomes the expectation once you hold sensitive customer data or supply bigger organisations. Level 3 is rarely proportionate for a small team.
Three forces keep the Essential Eight relevant regardless of what it is called next:
Cyber insurance. Australian insurers increasingly require evidence of Essential Eight controls, particularly MFA and backups, before issuing or renewing a policy. Weak answers mean higher premiums or refused cover.
Supply chains and tenders. Government buyers and large companies push security requirements down to their suppliers, and supplier questionnaires are usually worded straight from the Essential Eight.
It works. The list exists because these eight controls, done even to Level 1, close the attack paths that actually compromise small businesses: stolen passwords, unpatched software and unrecoverable data.
On 24 June 2026 the ASD opened national consultation on evolving the Essential Eight into a broader Essentials series.3 The current Essential Eight becomes the first chapter, called Essentials for enterprise IT, with further chapters to follow for other technology environments. The consultation ran to mid-July 2026, and the frameworks are expected to run side by side for around a year before the Essential Eight name is retired.
The important part for a small business: the ASD has said existing users can expect strong alignment with their current controls and investments, and the new guidance stays grounded in the same Information Security Manual. Translation: keep going. MFA, patching, backups and sensible admin rights are not being un-invented. The organisations that will handle the transition easily are the ones already at Maturity Level 1.
The Essential Eight describes what good looks like, but there is no official "Essential Eight certificate" a small business can hang on the wall. That gap is being filled by SMB1001, a private certification standard built specifically for small and medium businesses, with five tiers from Bronze to Diamond. It is not government-mandated, but it is gaining real traction in Australia: supply chains ask for it, and the Queensland Law Society has endorsed it for its members. A sensible pairing is to use the Essential Eight to decide what to implement, and SMB1001 when a customer or insurer wants proof.
International customers may ask about NIST CSF 2.0 or the CIS Controls instead. The good news is the overlap is heavy: a small business at Essential Eight Maturity Level 1 has already covered most of CIS Implementation Group 1 and the core of the NIST framework's Protect and Recover functions. Implement once, answer everyone's questionnaire.
If you do nothing else, do these, in order:
Want a quick outside-in read on where you stand? Our free website security checker runs 20 passive checks in about a minute, no sign-up.
Website security checker: 20 passive checks on your site, free and instant.
Managed IT Services in Sydney: security implemented and managed for you, from $80 per user per month.
All resources: tools, guides and case studies.
Not by law for private small businesses. But cyber insurers increasingly ask for it at policy renewal, and government or enterprise customers ask for it in tenders and supplier questionnaires, so in practice it is the measuring stick you will be held against.
Yes, gradually. In June 2026 the Australian Signals Directorate opened consultation on evolving it into a new Essentials series, with the current Essential Eight becoming the first chapter, Essentials for enterprise IT. The two are expected to run side by side for around a year before the old framework is retired. Nothing you implement now is wasted: the ASD has said existing controls carry over with strong alignment.
Maturity Level 1 is the practical baseline for most small businesses. Level 2 is the expectation once you handle sensitive customer data or serve larger organisations. Level 3 targets organisations facing advanced threats and is rarely proportionate for a small team.
No. The new series is grounded in the same Information Security Manual, and the ASD has said organisations can expect strong alignment with their current controls and investments. The eight controls address fundamentals like patching, MFA and backups that no future framework will drop.
The Essential Eight is government guidance that describes what good security looks like. SMB1001 is a private certification standard with five tiers that gives you a certificate to show customers and insurers. Many small businesses use the Essential Eight to decide what to implement and SMB1001 when a customer or contract asks for proof.
Multi-factor authentication everywhere, tested backups, and automatic updates. Those three controls close the most common attack paths for the least money and effort, and every one of them counts toward Maturity Level 1.
General information only. This article does not account for your specific circumstances and is not legal, financial, or professional advice. For guidance on your situation, get in touch.
Tell us about your setup and we'll give you an honest read on your Essential Eight gaps, and what closing them would cost. One business day, no obligation.
Prefer to talk? Call (02) 9053 8789.