Essential Eight assessment and uplift
The maturity level you believe you hold, and the one your configuration demonstrates.
These are usually two different numbers. A control gets switched on once, an exception gets granted and never reviewed, a patch cadence slips — and the self-assessed ML2 on your tender response stops being true. CyberBakery tests what is actually enforced, closes the gaps that move your rating, and produces evidence an assessor can follow.
Sydney-based · ML0–ML3 · Assessment, uplift delivery and continuous monitoring
Where the Essential Eight actually stands
Verified against cyber.gov.au — [DATE TO CONFIRM BEFORE PUBLISH]
- Current releaseEssential Eight Maturity Model, November 2023Still the live, assessable baseline. Every obligation and questionnaire that cites the Essential Eight still points at this document.
- 15 June 2026ASD opens consultation on an Essentials seriesA proposed evolution grounded in the Information Security Manual. First chapter: Essentials for enterprise IT.
- 12 July 2026Consultation closedFeedback from government, industry and regulators now feeds the drafting of the first chapter.
- No published dateRetirement timeline remains unpublishedA twelve-month deprecation and twenty-four-month retirement has been widely reported from a named official's remarks. ASD has published no retirement date. We treat the two differently.
We re-verify this panel monthly. Ask us what changed this month.
Half of what you have read about the Essentials series is not ASD policy.
Several vendors are now telling Australian organisations the Essential Eight has been retired, and a few are using that to sell a pause, a pivot or a product. It is worth being precise, because the distinction between what ASD published and what a named official said in an interview is the difference between a defensible plan and an expensive guess.
Published by ASD
The Essential Eight Maturity Model of November 2023 is the current release and remains in force.
A proposed Essentials series exists, grounded in the Information Security Manual.
The first chapter is Essentials for enterprise IT.
Consultation ran through the Cyber Security Partnership Program portal and closed 12 July 2026.
Existing controls and investments are expected to align strongly with the new guidance.
Reported, not published
Deprecation beginning at roughly twelve months.
Full retirement at roughly twenty-four months.
The order in which subsequent chapters will be released.
Design intent around whether maturity levels survive in their current form.
Not known by anyone
The final control set for Essentials for enterprise IT. No draft has been published.
Whether the number eight survives at all.
Whether ML0–ML3 carries over, changes shape, or is replaced.
How the obligations and questionnaires that cite the Essential Eight will be reworded, and when.
What is actually changing, side by side.
Left is the document you are assessed against today. Right is what ASD has said about its successor — and, just as importantly, what it has not said. Every gap below is a real gap in the public record, not an omission on our part.
Essential Eight Maturity Model
November 2023 · current release · in force
Essentials series
Proposed · first chapter in drafting
Status
Published, current and assessable. The document your rating is measured against today.
A proposal consulted on between 15 June and 12 July 2026. No draft guidance has been released.
Foundation
A standalone set of eight mitigation strategies, first published in 2017 and revised since.
Grounded in the Information Security Manual, positioning it inside ASD's wider guidance rather than beside it.
Structure
One document covering one environment type.
A series of domain chapters, opening with Essentials for enterprise IT.
Scope
Written for enterprise IT networks. ASD notes other environments may need alternative strategies.
Intended to cover contemporary environments more directly — cloud, SaaS and operational technology among them.
Control set
Eight mitigation strategies, prescriptively specified.
Not published.
Whether eight survives as a number is unknown.
Approach
Prescriptive technical controls on a fixed ladder, calibrated to adversary tradecraft.
Described by ASD as prioritised and threat-informed, with greater flexibility in how organisations implement.
Maturity model
Four levels, ML0 to ML3, assessed per strategy. Your overall rating is your weakest strategy.
Not published.
Whether levels carry over, change shape or disappear is unknown.
Assessment method
A published assessment process guide, so results mean the same thing between assessors.
Not published.
Standing in obligations
Referenced directly across government policy, defence supply-chain requirements, critical-infrastructure reporting, tender questionnaires and insurance forms.
Not published.
Every one of those references will need rewording at some point, on a timetable nobody has announced.
What it means today
Assess against this. It is the only version anyone can hold you to.
Plan for it, do not wait for it. ASD has said existing investment is expected to carry across.
What we advise, plainly
Keep executing. Do not pause an active uplift, de-scope it, or move budget out of the current cycle on the strength of an announcement that has produced no draft control set. Every control you implement now carries across, and the parallel-running window is the right time to lock in a verified maturity rating as the baseline for whatever gap analysis the new guidance eventually requires. The one thing worth changing today is emphasis: frame your evidence around control outcomes and demonstrated risk reduction rather than solely around a level number. That is the direction ASD has signalled, and it reads better to a prime either way.
Eight strategies. Four that fail assessment most often.
Every control below is assessed against what your environment actually enforces, not against what the policy says it should.
Maturity is assessed per strategy, and your rating is the lowest one.
This is the detail most self-assessments get wrong. Seven strategies at ML2 and one at ML1 is an ML1 organisation.

Assessed against enforcement, then actually fixed.
Our assessment method follows the ASD Essential Eight Assessment Process Guide, so the result means the same thing to an auditor as it does to you. We then do the remediation work, not just describe it.
A rating verified eleven months ago is a claim, not evidence.
Between assessments, environments move. A new server misses the patch group, an exception is granted for a project and never revoked, an admin account gets created outside the process. Our posture management platform watches the eight strategies continuously and tells you when your assessed rating stops being true.
What it watches
What you get from it
What you can hand to an assessor without rewriting it first.
The output of an assessment is only useful if someone else can follow it. Every finding traces to the configuration that produced it, and every remediation traces back to the finding it closed.
Assessment output
Written to be read by a technical assessor and summarised for a board in the same document.
Evidence pack
Structured for reuse across the obligations and questionnaires that cite the Essential Eight, rather than rebuilt for each one.
Start with a rating you can actually defend.
Essential Eight assessment
A rating per strategy, tested against enforcement, following the ASD assessment process guide.
Uplift delivery
We implement the remediation to your target level, alongside your team or your existing MSP.
Transition readiness review
Lock in a verified baseline now, so the eventual gap analysis against the Essentials series starts from evidence rather than assumption.
Posture management
Continuous monitoring so your rating stays true between assessments instead of quietly decaying.
We assess for a living, so we know what evidence survives scrutiny.
Essential Eight, answered plainly.
Is the Essential Eight being retired?
ASD has proposed replacing it with an Essentials series and consulted on the first chapter, which closed on 12 July 2026. ASD has not published a retirement date. A twelve-month deprecation and twenty-four-month retirement timeline has been widely repeated, but that traces to a named official's public remarks rather than to published policy. The November 2023 Maturity Model remains the current, assessable release.
Should we pause our uplift until the new framework lands?
Why is our self-assessed rating usually higher than yours?
How is the overall maturity level calculated?
Do you do the remediation, or just the report?
Does an Essential Eight rating help with our other obligations?

When you need method to the chaos
Find out whether your maturity rating would survive an assessment.
A short scoping conversation establishes which target level your obligations actually require, what is in scope, and where the gaps usually sit in an environment like yours.
Related services


