Essential Eight for Small Business: The 2026 Transition Guide

Still the baseline insurers and tenders expect. Also being replaced. Here is what to do about both.

Resources / Essential Eight Guide

The Essential Eight is still the standard Australian small businesses are measured against, and it is being replaced. In June 2026 the Australian Signals Directorate announced the framework will evolve into a new Essentials series, with the current Essential Eight carrying over as its first chapter. Insurers and tenders have not stopped asking for it in the meantime. This guide covers what the Essential Eight asks of a small business today, what is changing and when, and why nothing you implement now is wasted.

8 controls

the ASD's baseline for stopping most real-world attacks

Level 1

the maturity level most small businesses actually need

~24 months

until the Essential Eight name is retired for the Essentials series

What the Essential Eight is, in plain English

The Essential Eight is the Australian Signals Directorate's list of the eight security controls that stop the large majority of real-world attacks. It is government guidance, not legislation, and it is published for free at cyber.gov.au.1 Here is each control translated for a small team, ordered by where we suggest starting:

Control What it means for a small business
Multi-factor authentication A second check (an app prompt or code) on top of passwords. The single highest-value control on the list.
Regular backups Backups that run automatically, are kept where ransomware cannot reach them, and are actually test-restored.
Patch applications Your software updates itself promptly, especially browsers, email and anything internet-facing.
Patch operating systems Windows and macOS updates applied within a defined window, not deferred indefinitely.
Restrict administrative privileges Day-to-day accounts are not administrators. Admin rights are separate, limited and reviewed.
Application control Only approved software runs on your machines. The hardest control for small teams; do it last.
Configure Microsoft Office macro settings Macros from the internet are blocked. Most businesses can block macros entirely and never notice.
User application hardening Browsers and PDF readers configured to remove risky features attackers rely on.

What does Maturity Level 1 actually ask of you?

Each control is measured at four maturity levels, from Level 0 (not implemented) to Level 3 (hardened against advanced attackers).2 Maturity Level 1 is the practical baseline for most small businesses: it means the basics are genuinely in place, not perfect, and it is what insurers and larger customers generally mean when they ask if you "do the Essential Eight". Level 2 becomes the expectation once you hold sensitive customer data or supply bigger organisations. Level 3 is rarely proportionate for a small team.

Why does it still matter right now?

Three forces keep the Essential Eight relevant regardless of what it is called next:

Cyber insurance. Australian insurers increasingly require evidence of Essential Eight controls, particularly MFA and backups, before issuing or renewing a policy. Weak answers mean higher premiums or refused cover.

Supply chains and tenders. Government buyers and large companies push security requirements down to their suppliers, and supplier questionnaires are usually worded straight from the Essential Eight.

It works. The list exists because these eight controls, done even to Level 1, close the attack paths that actually compromise small businesses: stolen passwords, unpatched software and unrecoverable data.

The 2026 announcement: the Essentials series

On 24 June 2026 the ASD opened national consultation on evolving the Essential Eight into a broader Essentials series.3 The current Essential Eight becomes the first chapter, called Essentials for enterprise IT, with further chapters to follow for other technology environments. The consultation ran to mid-July 2026, and the frameworks are expected to run side by side for around a year before the Essential Eight name is retired.

The important part for a small business: the ASD has said existing users can expect strong alignment with their current controls and investments, and the new guidance stays grounded in the same Information Security Manual. Translation: keep going. MFA, patching, backups and sensible admin rights are not being un-invented. The organisations that will handle the transition easily are the ones already at Maturity Level 1.

Want a certificate to show for it? Where SMB1001 fits

The Essential Eight describes what good looks like, but there is no official "Essential Eight certificate" a small business can hang on the wall. That gap is being filled by SMB1001, a private certification standard built specifically for small and medium businesses, with five tiers from Bronze to Diamond. It is not government-mandated, but it is gaining real traction in Australia: supply chains ask for it, and the Queensland Law Society has endorsed it for its members. A sensible pairing is to use the Essential Eight to decide what to implement, and SMB1001 when a customer or insurer wants proof.

What if your clients are global?

International customers may ask about NIST CSF 2.0 or the CIS Controls instead. The good news is the overlap is heavy: a small business at Essential Eight Maturity Level 1 has already covered most of CIS Implementation Group 1 and the core of the NIST framework's Protect and Recover functions. Implement once, answer everyone's questionnaire.

Where should you start this quarter?

If you do nothing else, do these, in order:

  1. Turn on MFA everywhere: email, accounting, banking, remote access. An afternoon of work, and the single biggest risk reduction available.
  2. Verify your backups: confirm what is backed up, that ransomware cannot reach the copies, and that a restore has actually been tested.
  3. Turn on automatic updates for operating systems and browsers, and set a monthly reminder for everything that cannot update itself.
  4. Separate admin accounts from daily-driver accounts, and count who has admin rights today. The number is usually a surprise.

Want a quick outside-in read on where you stand? Our free website security checker runs 20 passive checks in about a minute, no sign-up.

References

  1. Australian Signals Directorate, Essential Eight, cyber.gov.au.
  2. Australian Signals Directorate, Essential Eight Maturity Model, cyber.gov.au.
  3. Information & Data Manager, ASD Flags Next Generation of Essential Eight, June 2026.

Related resources

Website security checker: 20 passive checks on your site, free and instant.
Managed IT Services in Sydney: security implemented and managed for you, from $80 per user per month.
All resources: tools, guides and case studies.

Frequently asked questions

Is the Essential Eight mandatory for small businesses?

Not by law for private small businesses. But cyber insurers increasingly ask for it at policy renewal, and government or enterprise customers ask for it in tenders and supplier questionnaires, so in practice it is the measuring stick you will be held against.

Is the Essential Eight being replaced?

Yes, gradually. In June 2026 the Australian Signals Directorate opened consultation on evolving it into a new Essentials series, with the current Essential Eight becoming the first chapter, Essentials for enterprise IT. The two are expected to run side by side for around a year before the old framework is retired. Nothing you implement now is wasted: the ASD has said existing controls carry over with strong alignment.

What maturity level does a small business actually need?

Maturity Level 1 is the practical baseline for most small businesses. Level 2 is the expectation once you handle sensitive customer data or serve larger organisations. Level 3 targets organisations facing advanced threats and is rarely proportionate for a small team.

Will the work I put into the Essential Eight be wasted when the Essentials series arrives?

No. The new series is grounded in the same Information Security Manual, and the ASD has said organisations can expect strong alignment with their current controls and investments. The eight controls address fundamentals like patching, MFA and backups that no future framework will drop.

What is the difference between the Essential Eight and SMB1001?

The Essential Eight is government guidance that describes what good security looks like. SMB1001 is a private certification standard with five tiers that gives you a certificate to show customers and insurers. Many small businesses use the Essential Eight to decide what to implement and SMB1001 when a customer or contract asks for proof.

Where should a small business start?

Multi-factor authentication everywhere, tested backups, and automatic updates. Those three controls close the most common attack paths for the least money and effort, and every one of them counts toward Maturity Level 1.

General information only. This article does not account for your specific circumstances and is not legal, financial, or professional advice. For guidance on your situation, get in touch.

Not sure where you stand?

Tell us about your setup and we'll give you an honest read on your Essential Eight gaps, and what closing them would cost. One business day, no obligation.

Prefer to talk? Call (02) 9053 8789.