ConnectWise
;

8/4/2026 | 8 Minute Read

The end of the Essential Eight? What Australia’s new Essentials framework means for MSPs and MSSPs

Topics:

Contents

    Build cyber resilience

    Deliver integrated security services that reduce risk and strengthen customer resilience.

    The Australian Signals Directorate (ASD) has announced plans to evolve (and eventually retire) the Essential Eight in favour of a broader Essentials series designed for modern IT environments. While the transition will take place over several years, it signals an important shift in how Australian organisations should approach cybersecurity. 

    For managed service providers (MSPs) and managed security service providers (MSSPs), this is an opportunity to move beyond compliance conversations and help customers build stronger cyber resilience across cloud, SaaS, identity, endpoint, and operational technology environments. 

    What is changing with the ASD Essential Eight?

    According to ASD’s consultation paper, the Essential Eight was originally designed for internet-connected enterprise IT networks. While it has provided a valuable baseline for improving cybersecurity across government and industry, today’s cloud-first, hybrid environments require broader guidance. 

    The proposed Essentials series expands that foundation with recommendations tailored to modern technology environments while maintaining alignment with existing Essential Eight investments. 

    Here’s what’s changing:

    • Broader coverage: Guidance will extend beyond traditional enterprise IT to include environments such as cloud and operational technology (OT), with separate guidance expected for different technology domains.
    • Greater flexibility: Instead of a single maturity model, the new framework emphasizes threat-informed guidance that can be applied across diverse environments.
    • A phased transition: According to iTnews, ASD expects both frameworks to coexist during a transition period, with depreciation of the Essential Eight potentially beginning in approximately 12 months and full retirement around 24 months.

    For MSPs and MSSPs, that means there is time to prepare. However, now is the time to begin evolving customer conversations, service offerings, and reporting to align with the next generation of cybersecurity guidance. 

    Why ASD is evolving the Essential Eight

    While the Essential Eight gave organisations a clear security baseline, it also created a level of false confidence. Too often, maturity levels became the end goal rather than the starting point for building a resilient security program. As the threat landscape has evolved, attackers increasingly exploit identity, cloud misconfigurations, SaaS permissions, exposed remote access, third-party integrations, and the visibility gaps that exist across hybrid environments. An organisation can achieve a maturity target and still struggle to detect a compromise, contain identity abuse, recover critical data, or understand where its most critical assets reside. 

    The fundamentals of good cybersecurity haven’t changed. Controls such as patching, multi-factor authentication (MFA), application control, backups, and privileged access management remain essential. What has changed is how those controls are applied and validated across cloud, SaaS, hybrid, and operational technology environments. 

    The proposed Essentials series reflects this reality by placing greater emphasis on flexible, threat-informed guidance rather than a single maturity model. Instead of treating compliance as the destination, the new approach encourages organisations to build measurable cyber resilience across their entire environment.

    What the Essential Eight changes mean for MSPs and MSSPs

    For MSPs and MSSPs, ASD’s evolving guidance creates both a challenge and an opportunity.

    Many security programs, customer assessments, and compliance conversations have been built around Essential Eight maturity. As that framework evolves, partners will need to update how they assess risk, package services, measure success, and communicate value to customers.

    The bigger opportunity, however, is to shift the conversation beyond compliance.

    Rather than asking, “Are you Essential Eight compliant?” MSPs can begin asking a more meaningful question: “Are you protected against the threats most likely to impact your business?”

    That changes the focus from maturity scores to measurable security outcomes. Instead of simply mapping controls to a framework, partners can help customers understand whether they can:

    • Detect threats across cloud, endpoint, and identity environments
    • Reduce exposure through continuous vulnerability and configuration management
    • Respond quickly to security incidents
    • Recover critical systems and data with confidence
    • Continuously strengthen their security posture as risks evolve

    This reflects how organisations operate today. Most small and midsized businesses (SMBs) rely on Microsoft 365®, SaaS applications, hybrid infrastructure, remote workforces, and outsourced IT. As customers, insurers, and regulators increasingly prioritise cyber resilience over framework compliance, MSPs have an opportunity to position themselves as strategic security advisors, not just compliance providers.

    Preparing for Australia’s new cybersecurity framework

    MSPs and MSSPs should use the transition period to get ahead of the market rather than wait for the  

    Essential Eight to be formally retired.

    The work already completed around multi-factor authentication, patching, backups, application control, privileged access, and system hardening will remain relevant. The priority now is to build a bridge between those existing services and the broader security outcomes likely to shape Australia’s next cybersecurity framework.

    MSPs and MSSPs should focus on four areas:

    • Map current services to future security domains. Align Essential Eight offerings with broader areas such as enterprise IT, cloud, operational technology, identity, endpoint security, backup, detection and response, and emerging technologies such as AI.
    • Update assessments and reporting. Review customer reports and remove language that presents Essential Eight maturity levels as the final destination. Reporting should show how services reduce exposure, improve detection, accelerate response, and strengthen recovery.
    • Modernise service packaging. Position individual controls as part of broader security outcomes. For example, connect backup to cyber recovery, MFA to identity protection and privileged access, and endpoint detection and response (EDR) to managed detection and response (MDR).
    • Strengthen the customer narrative. Shift conversations from “Are you compliant?” to “Are you defensible, recoverable, and improving over time?”

    This also means reviewing advisory approaches, sales messaging, and customer success conversations now. The partners that adapt early will be better positioned as customers, insurers, regulators, and procurement teams begin changing how they evaluate cybersecurity maturity and resilience.

    The next evolution of cybersecurity starts now

    The Essential Eight has helped organisations build a strong cybersecurity foundation. As Australia’s guidance evolves, MSPs and MSSPs have an opportunity to move beyond compliance and help customers build lasting cyber resilience across cloud, identity, SaaS, and hybrid environments.

    Build cyber resilience with ConnectWise

    The ConnectWise Platform™ helps MSPs deliver measurable security outcomes by bringing together capabilities such as identity and endpoint security, MDR, security information and event management (SIEM), vulnerability management, backup and cyber recovery, and centralised monitoring.

    Whether you’re helping customers strengthen their Essential Eight posture today or preparing for Australia’s next cybersecurity framework, ConnectWise provides the integrated platform to help reduce risk, improve visibility, and strengthen cyber resilience.

    Learn more about ConnectWise cybersecurity solutions >>

    FAQs

    What is happening to the Essential Eight?

    The Australian Signals Directorate (ASD) has proposed evolving the Essential Eight into a broader Essentials series designed for modern technology environments. While the Essential Eight is expected to remain available during a transition period, the new guidance is intended to provide more flexible, threat-informed recommendations for enterprise IT, cloud, operational technology, and other environments.

    Is the Essential Eight being retired?

    ASD has proposed a phased transition rather than an immediate replacement. According to iTnews, both the Essential Eight and the new Essentials guidance are expected to coexist during the transition, with depreciation of the Essential Eight potentially beginning in approximately 12 months and full retirement around 24 months. Organisations should continue their current Essential Eight initiatives while preparing for the broader framework.

    Why is ASD replacing the Essential Eight?

    The Essential Eight was originally developed for internet-connected enterprise IT networks. Today’s organisations operate across cloud platforms, SaaS applications, hybrid infrastructure, remote workforces, and operational technology environments. The proposed Essentials series is intended to provide guidance that better reflects today’s technology landscape while maintaining the core cybersecurity principles that underpin the Essential Eight.

    Should organisations stop following the Essential Eight?

    No. Organisations should continue implementing foundational security controls such as patch management, multi-factor authentication (MFA), application control, backups, and privileged access management. These controls remain essential to a strong cybersecurity program and will continue to form the foundation of the proposed Essentials series.

    What do the Essential Eight changes mean for MSPs and MSSPs?

    The transition presents an opportunity for MSPs and MSSPs to move beyond compliance-based conversations and position themselves as strategic security advisors. Rather than focusing solely on Essential Eight maturity, partners can help customers improve cyber resilience through services such as identity security, managed detection and response (MDR), vulnerability management, cloud security, backup and cyber recovery, and continuous security monitoring.

    How should MSPs prepare for Australia’s new cybersecurity framework?

    MSPs should use the transition period to review customer assessments, reporting, and service offerings. Existing Essential Eight services remain valuable, but they should be positioned within broader security outcomes such as cyber resilience, identity protection, threat detection, incident response, and recovery. Beginning that transition now will help partners stay ahead as customer expectations and cybersecurity guidance continue to evolve. 

    Related Articles