◢ 24×7 SOC ONLINE · 1800 960 165
USA·AUSTRALIA·MIDDLE EAST
Home / Services / Govern / Essential Eight & Essentials Series

Essential Eight & the Essentials Series

Assess your Essential Eight maturity today and get ready for the ASD's new Essentials series - across your enterprise IT, cloud and OT environments.

Essentials series readiness
GOVERN
NIST Function · Govern

Ready for the Essential Eight today - and the Essentials series next

CyberSecOn recognises the critical importance of strong cybersecurity measures to protect your organisation from evolving threats. Our assessments evaluate your adherence to the Essential Eight controls, developed by the Australian Signals Directorate (ASD), and identify the practical steps to lift your maturity across your environment.

In 2026 the ASD began evolving the Essential Eight into the broader, outcomes-focused Essentials series. We assess you against the Essential Eight now and map a clear path to the Essentials series - so you stay ahead of the change across your IT, cloud and OT environments.

Talk to our team
Backed by ISO/IEC 27001 · Certified CREST · Accredited NIST · CMMC · ISO 27001 · GDPR Australia · USA · Middle East
A framework in transition

From the Essential Eight to the Essentials series

In 2026 the ASD opened consultation on the future of the Essential Eight and introduced the Essentials series - a broader, outcomes-focused family of guidance with a dedicated chapter for each technology domain, starting with enterprise IT.

Both
E8 & Essentials run side by side
~12 mo
E8 deprecation expected to begin
~24 mo
E8 expected to be retired
ML 1-3
Your maturity carries forward

The Essential Eight is not going away overnight. ASD has confirmed a transition period where both frameworks operate together, with strong alignment between your existing controls and the new guidance - so the work you have already done is not wasted. CyberSecOn assesses you against the Essential Eight today and maps a practical path to the Essentials series across your IT, cloud and OT environments.

How it works

The Essentials maturity model

Where do you sit today - and what does the next level take? Your Maturity Level work carries straight into the Essentials series.

0
Maturity Level 0
Ad hoc
Reactive gaps
1
Maturity Level 1
Partial
Some strategies in place
2
Maturity Level 2
Consistent
Consistently applied
3
Maturity Level 3
Proactive
Managed & maintained
The Essentials series

One framework, many environments

Rather than one framework for everything, the Essentials series adds a chapter per technology domain. We assess and prepare you across each - including where IT meets OT.

Enterprise IT

The first Essentials chapter - hardening, patching, MFA and control across your corporate IT estate.

Cloud

Outcomes-focused controls built for cloud-first and hybrid architectures (a future chapter).

Operational Technology

Extending the same rigour to OT, ICS and IoT environments (a future chapter) - our specialty.

Emerging Tech & AI

Readiness for future guidance, with AI and emerging technology flagged by ASD for later chapters.

Enterprise IT is the first chapter; cloud, OT and emerging-technology chapters are expected to follow as the Essentials series is finalised.

How we deliver

Our approach to the Essential Eight and Essentials series

The people, process and methodology behind the service - so you can see exactly how we protect you.

STEP 01

Assess where you stand today

  • Maturity baselineMeasure your current Essential Eight maturity across Levels 0 to 3, so you know your real starting position rather than an assumed one.
  • Evidence-based reviewConfirm that each control genuinely operates as intended, not simply that it exists on paper.
  • Outcomes assessmentTest your posture against the Essentials series outcomes-focused model, not just the eight fixed mitigation strategies.
  • Business contextWeigh the findings against your obligations, from tenders and cyber insurance to board and regulator expectations.
  • Clear findingsSet out where you stand today in plain language your technical team and your executive can act on together.
STEP 02

Map and extend across every environment

  • Enterprise IT chapterAlign your corporate IT to the first Essentials series chapter, carrying your existing Essential Eight work straight forward.
  • Cloud coverageExtend the assessment into your cloud services, ready for the Essentials series cloud chapter as it lands.
  • OT and ICS specialismApply our operational technology and industrial control system experience where corporate IT meets the plant floor, an area most providers leave out.
  • Whole-of-environment viewBring IT, cloud and OT into one assessment so no critical system sits outside your security programme.
  • Future chaptersPosition you for emerging chapters, including AI and new technology domains, without reworking what you have already built.
STEP 03

Prepare and keep you audit-ready

  • Gap analysisPinpoint the specific gaps between where you stand and your target maturity and Essentials readiness.
  • Prioritised roadmapSequence the work by risk and effort, so you address what matters most first and make steady, measurable progress.
  • Evidence packKeep your policies, patch records and configurations organised and ready to produce on request.
  • Audit and tender supportHave the documentation on hand for assessors, insurers and tender responses when the deadline arrives.
  • Ongoing readinessKeep your posture current as the Essentials series evolves, so each transition is a small step rather than a scramble.
Ready when you are

Let's talk about your Essential Eight and Essentials readiness

Book a free readiness review and we'll show you where you stand today, identify the gaps, and map a practical path to both the Essential Eight and the emerging Essentials series - across IT, cloud and OT.