Hello "Essentials for Enterprise IT": What's Changing and Why It Matters

September 14, 2026

ASD is rolling out a new framework called Essentials for Enterprise IT, expected to land in October 2026 with a 24-month transition period. Nothing is officially released yet, but based on the draft proposals and briefing sessions held so far, the shape of the new model is becoming clear — and it's a genuinely different way of thinking about control assurance, not just a rebrand.

Here's a breakdown of what's changing, what's staying, and the questions still worth asking before this framework becomes the new standard.

From a Checklist to a Model

The current Essential Eight is built around 152 controls, organised into three maturity levels, assessed on a strict pass/fail basis. Every control at your target level needs to be in place — no partial credit, no room for context.

Essentials for Enterprise IT flips that structure on its head:

Rather than a flat, one-size-fits-all list, the new model borrows heavily from risk-based standards like ISO 27001- bringing governance requirements into the framework for the first time, along with entirely new practice areas such as risk management and supply chain management that Essential Eight never touched.

The Big Idea: Design AND Operating Effectiveness

Perhaps the most meaningful shift is a subtle one. Assessors will now need to evaluate controls on both design effectiveness and operating effectiveness - a standard already familiar to auditors in most other assurance frameworks, but new territory for how Essential Eight has traditionally been assessed.

In plain terms: it's no longer enough to ask "do you have this control?" The question becomes "is it actually working the way it's supposed to?" That's a more honest and more demanding bar, and it likely reflects a recognition that plenty of organisations have been ticking boxes without the underlying control doing much real-world work.

New Language, New Concepts

With a new model comes new terminology - and some of it is going to take getting used to.

Protect Surfaces

Organisations will now need to define "Protect Surfaces" - essentially, the assets, systems, or processes they're applying controls to - and then scope which controls apply where. It's a reasonable idea in principle: instead of a blanket, black-and-white approach, organisations get to define what's in scope and why. The term itself is up for debate, though - "asset," "system," or "system boundary" (as used in IRAP assessments) would arguably do the same job in language businesses already understand.

Scoping Your Controls: Two Ways to Approach It

Once Protect Surfaces are defined, organisations have a choice in how they roll out controls across them:

  • Option 1 - Surface-focus: Apply all principles to one Protect Surface at a time before moving to the next.
  • Option 2 - Principle-focus: Apply one principle across all Protect Surfaces before moving to the next principle.

Neither is inherently right or wrong - it's a genuine strategic choice depending on where an organisation's risk is concentrated and how its teams are structured.

Implementation Levels

Maturity Levels are being replaced by "Implementation Levels." The three levels build progressively on each other:

  • Implementation Level 1 (IL1) - builds trust and detection foundations to disrupt the most commonly observed attacker entry and escalation paths.
  • Implementation Level 2 (IL2) - hardens critical processes, services, and privileged environments.
  • Implementation Level 3 (IL3) - secures endpoints and internal enterprise applications.

Running underneath all three levels are two enduring priorities: governance and culture, and visibility and response.

Given how deeply "maturity level" is embedded in the vocabulary of every organisation that's ever run an Essential Eight assessment, expect some confusion during the transition. "Implementation Level" carries different meaning and context, and it's an easy phrase to misuse or misunderstand.

Principles

The new model is described as principle-based - circa. 58 principle-based controls in total, replacing the old checklist of 152 controls. This is a sound approach for larger, more mature organisations with established governance and risk thinking. For smaller businesses without that muscle already built, principles-based frameworks can be genuinely harder to operationalise than a straightforward checklist.

Trustworthy Software

A new concept enters the vocabulary: software needs to be "trustworthy." It's not yet clear whether this is a bar organisations need to formally prove they've cleared, or an aspirational target - and if a control is only partially effective, does that make the software "untrusted" by definition? This is one to watch as more detail emerges.

How Scoring Actually Works

Despite all the talk of scoping, contextualisation, and principles you can "grow into," there's still a score at the end of the day - and the draft documents give a clear (if not yet officially confirmed) picture of how it's calculated.

The four-tier rating scale - Not Assessed, Not Effective, Partially Effective, Effective - mirrors the scale IRAP assessors already use. Based on the sample scoring shown in the draft materials, it appears the calculation works like this:

  • Effective control = 1 point
  • Partially Effective control = ½ point
  • Not Effective control = 0 points

Total score ÷ total possible points = percentage effectiveness

That means, in practice, an organisation working toward Implementation Level 2 might see something like 100% effectiveness on Governance and Culture, but only 61% on Privileged Environments - a far more nuanced picture than a simple pass/fail ever gave, but one that puts a lot of weight on assessors rating consistently across the board.

However, if two assessors interpret "Partially Effective" differently, scores stop being comparable - which is exactly the kind of inconsistency a scoring framework is supposed to prevent.

What Happens to Existing Essential Eight Investment?

If your organisation has already sunk time and budget into Essential Eight compliance, the good news is that work isn't wasted. ASD's own framing of the transition puts it this way:

Existing investment in Essential Eight builds directly into the new model. While the way controls are structured and measured is changing, existing controls remain highly relevant — they'll now contribute to multiple Protect Surfaces and be assessed on the outcomes they achieve, forming part of a more comprehensive, integrated approach.

In other words: your current controls carry forward, but expect to re-map, re-scope, and re-score them under the new structure.

The Questions Still Worth Asking

With nothing officially released yet, plenty remains genuinely unclear:

  • Does this map to the ISM? If not, how does adopting this framework actually help organisations progress toward an IRAP assessment?
  • What's actually changing at the control level? Will controls like MFA be refined to focus on what matters most, rather than the current push to apply MFA everywhere regardless of risk?
  • Will there be a scoring guide? Without one, how will assessors and advisors rate consistently - particularly in that ambiguous "Partially Effective" middle band?
  • Is this still viable for small businesses? A principles-based, governance-heavy framework is a significant step up in complexity from a checklist.
  • Do we need an entirely new framework at all? Or could the same outcomes have been achieved by aligning to an existing standard already in wide use?

The Bottom Line

Essentials for Enterprise IT represents a genuine philosophical shift - from a rigid, binary checklist to a scoped, principles-based model that measures how well controls actually work, not just whether they exist.

That's a positive evolution in a lot of ways: it brings governance into scope, allows for context, and replaces an artificial pass/fail cliff-edge with a more honest gradient.

But the transition won't be free. New terminology will cause confusion, small businesses may find the framework harder to operationalise than the old checklist, and the entire model hinges on assessors applying the new rating scale consistently.

With 24 months of transition ahead and the official release still pending, there's time to get these details right — but only if the right questions keep getting asked.

This article is based on draft proposals and briefing sessions and reflects the current understanding of Essentials for Enterprise IT ahead of its official release. Details are subject to change before ASD's formal announcement.

Secure your business.

"assurance"

confidence or certainty in one's own abilities.

“The business has given us assurance that they have security in place to protect our information”

Our Difference

Established and lead by industry experts.

At the helm of our privately owned, global RegTech firm are industry experts who understand that security controls should never get in the way of business growth. We empower companies large and small to remain resilient against potential threats with easily accessible software solutions for implementing information security governance, risk or compliance measures.

We support businesses every step of the way.

We don't just throw a bunch of standards at you and let you try and figure it out! We have designed a thoughtful way of supporting all businesses consider, articulate and develop security controls that suit the needs of the organisation and provide clever reporting capability to allow insights and outcomes from security assessments to be leveraged by the business and shared with third parties.

Our customers are the heart of our company.

Our platform places customers at the heart of our design process, while providing access to expert knowledge. With simple navigation and tangible results, we guarantee that all data is securely encrypted at-rest and in transit with no exceptions – meeting international standards with annual security penetration testing and ISO 27001 Certification.