ASD is rolling out a new framework called Essentials for Enterprise IT, expected to land in October 2026 with a 24-month transition period. Nothing is officially released yet, but based on the draft proposals and briefing sessions held so far, the shape of the new model is becoming clear — and it's a genuinely different way of thinking about control assurance, not just a rebrand.
Here's a breakdown of what's changing, what's staying, and the questions still worth asking before this framework becomes the new standard.
The current Essential Eight is built around 152 controls, organised into three maturity levels, assessed on a strict pass/fail basis. Every control at your target level needs to be in place — no partial credit, no room for context.
Essentials for Enterprise IT flips that structure on its head:

Rather than a flat, one-size-fits-all list, the new model borrows heavily from risk-based standards like ISO 27001- bringing governance requirements into the framework for the first time, along with entirely new practice areas such as risk management and supply chain management that Essential Eight never touched.
Perhaps the most meaningful shift is a subtle one. Assessors will now need to evaluate controls on both design effectiveness and operating effectiveness - a standard already familiar to auditors in most other assurance frameworks, but new territory for how Essential Eight has traditionally been assessed.
In plain terms: it's no longer enough to ask "do you have this control?" The question becomes "is it actually working the way it's supposed to?" That's a more honest and more demanding bar, and it likely reflects a recognition that plenty of organisations have been ticking boxes without the underlying control doing much real-world work.
With a new model comes new terminology - and some of it is going to take getting used to.
Organisations will now need to define "Protect Surfaces" - essentially, the assets, systems, or processes they're applying controls to - and then scope which controls apply where. It's a reasonable idea in principle: instead of a blanket, black-and-white approach, organisations get to define what's in scope and why. The term itself is up for debate, though - "asset," "system," or "system boundary" (as used in IRAP assessments) would arguably do the same job in language businesses already understand.
Once Protect Surfaces are defined, organisations have a choice in how they roll out controls across them:
Neither is inherently right or wrong - it's a genuine strategic choice depending on where an organisation's risk is concentrated and how its teams are structured.
Maturity Levels are being replaced by "Implementation Levels." The three levels build progressively on each other:
Running underneath all three levels are two enduring priorities: governance and culture, and visibility and response.
Given how deeply "maturity level" is embedded in the vocabulary of every organisation that's ever run an Essential Eight assessment, expect some confusion during the transition. "Implementation Level" carries different meaning and context, and it's an easy phrase to misuse or misunderstand.
The new model is described as principle-based - circa. 58 principle-based controls in total, replacing the old checklist of 152 controls. This is a sound approach for larger, more mature organisations with established governance and risk thinking. For smaller businesses without that muscle already built, principles-based frameworks can be genuinely harder to operationalise than a straightforward checklist.
A new concept enters the vocabulary: software needs to be "trustworthy." It's not yet clear whether this is a bar organisations need to formally prove they've cleared, or an aspirational target - and if a control is only partially effective, does that make the software "untrusted" by definition? This is one to watch as more detail emerges.
Despite all the talk of scoping, contextualisation, and principles you can "grow into," there's still a score at the end of the day - and the draft documents give a clear (if not yet officially confirmed) picture of how it's calculated.
The four-tier rating scale - Not Assessed, Not Effective, Partially Effective, Effective - mirrors the scale IRAP assessors already use. Based on the sample scoring shown in the draft materials, it appears the calculation works like this:
Total score ÷ total possible points = percentage effectiveness
That means, in practice, an organisation working toward Implementation Level 2 might see something like 100% effectiveness on Governance and Culture, but only 61% on Privileged Environments - a far more nuanced picture than a simple pass/fail ever gave, but one that puts a lot of weight on assessors rating consistently across the board.
However, if two assessors interpret "Partially Effective" differently, scores stop being comparable - which is exactly the kind of inconsistency a scoring framework is supposed to prevent.
If your organisation has already sunk time and budget into Essential Eight compliance, the good news is that work isn't wasted. ASD's own framing of the transition puts it this way:
Existing investment in Essential Eight builds directly into the new model. While the way controls are structured and measured is changing, existing controls remain highly relevant — they'll now contribute to multiple Protect Surfaces and be assessed on the outcomes they achieve, forming part of a more comprehensive, integrated approach.
In other words: your current controls carry forward, but expect to re-map, re-scope, and re-score them under the new structure.
With nothing officially released yet, plenty remains genuinely unclear:
Essentials for Enterprise IT represents a genuine philosophical shift - from a rigid, binary checklist to a scoped, principles-based model that measures how well controls actually work, not just whether they exist.
That's a positive evolution in a lot of ways: it brings governance into scope, allows for context, and replaces an artificial pass/fail cliff-edge with a more honest gradient.
But the transition won't be free. New terminology will cause confusion, small businesses may find the framework harder to operationalise than the old checklist, and the entire model hinges on assessors applying the new rating scale consistently.
With 24 months of transition ahead and the official release still pending, there's time to get these details right — but only if the right questions keep getting asked.
This article is based on draft proposals and briefing sessions and reflects the current understanding of Essentials for Enterprise IT ahead of its official release. Details are subject to change before ASD's formal announcement.
At the helm of our privately owned, global RegTech firm are industry experts who understand that security controls should never get in the way of business growth. We empower companies large and small to remain resilient against potential threats with easily accessible software solutions for implementing information security governance, risk or compliance measures.
We don't just throw a bunch of standards at you and let you try and figure it out! We have designed a thoughtful way of supporting all businesses consider, articulate and develop security controls that suit the needs of the organisation and provide clever reporting capability to allow insights and outcomes from security assessments to be leveraged by the business and shared with third parties.
Our platform places customers at the heart of our design process, while providing access to expert knowledge. With simple navigation and tangible results, we guarantee that all data is securely encrypted at-rest and in transit with no exceptions – meeting international standards with annual security penetration testing and ISO 27001 Certification.