IronSights
←All insights

compliance

Your contracts still say Essential Eight Maturity Level 2

The Essential Eight is deprecated from mid-2027 and retired by mid-2028. The contracts, tenders and insurance attestations that name it do not update themselves. Where those clauses hide, what happens to them, and why finding them now is an administrative task rather than an argument.

Ryan BallootBy Ryan Balloot, Managing Director29 September 20269 min read
ByRyan Balloot29 September 20269 min read

The is being retired. Your customer contracts have not heard about it. Neither has the insurance application you signed at the last renewal, or the tender response sitting in a procurement portal somewhere, and none of them will update themselves.

Most of the commentary since 's June announcement has been about the controls: whether your patching work still counts, what the will ask for, whether to keep going. Those questions have reasonable answers and we have covered them elsewhere. The question almost nobody is asking is narrower and has a harder edge to it. Somewhere in your business there is probably a signed document that names a specific Essential Eight , and at some point between mid-2027 and mid-2028 that document will point at a standard that no longer exists.

That is not a technical problem. It is a contractual one, and it is the only part of this transition with a commercial consequence already attached.

Where the Essential Eight is actually written down

The framework escaped the IT department years ago. It now turns up in places that have nothing to do with your security program and everything to do with getting paid.

Customer contracts are the common one, particularly anything signed with a government buyer, a bank, an insurer or a large corporate. A clause requiring you to "maintain Essential Eight Maturity Level 2" or to "align with the ASD Essential Eight" is standard drafting in Australian supply agreements now.

Tender and panel conditions are the next. Procurement templates across Commonwealth, state and local government reference the Essential Eight routinely, and so do the prequalification schemes that sit underneath them. If you are on a panel, the obligation may sit in the panel deed rather than in any individual order.

Then there are the documents that are easy to forget. Supplier security questionnaires you completed and signed. applications and renewals where you attested to a maturity level. Funding and grant agreements. Data sharing agreements with health, education or financial sector partners. Subcontractor flow-down clauses, where you have passed an obligation to someone else and remain accountable for it.

None of these were written with a retirement date in mind. They name a framework the way you would name a law, on the assumption it will still be there.

Deprecation and retirement do not touch a contract

Worth being precise about what ASD has actually said, because the dates matter more than the language around them.

On 24 June 2026, Chris Horlyck, ASD's Head of Cyber Security Resilience, confirmed the Essential Eight will be deprecated in approximately 12 months and fully retired at around 24. That puts deprecation near mid-2027 and retirement near mid-2028. The replacement is the Essentials series, a set of domain specific frameworks rather than one universal checklist, with enterprise IT, cloud and operational technology as the confirmed domains. Consultation closed on 12 July 2026 and the final version has not been published.

Deprecation and retirement are decisions about a document ASD maintains. They do nothing at all to a clause in your contract. A signed obligation to maintain Maturity Level 2 stays exactly as binding the day after retirement as the day before. What changes is that the thing it refers to has stopped being maintained, and reasonable people start disagreeing about what the clause now requires.

There is no mechanism that migrates these obligations. No regulator is going to reissue your contracts. If a clause names the Essential Eight, somebody has to decide what happens to it, and that somebody is you and your counterparty.

Four ways a clause can land

When a contract names a retired standard, the argument usually settles into one of a few positions, and which one you end up in depends heavily on how the clause was drafted.

The obligation may read straight across to the equivalent Essentials guidance, which is the outcome ASD's transition plan points toward and the one most parties will accept. It may need renegotiating, if the clause is specific enough that reading a different framework into it would change what you owe. It may be treated as satisfied and frozen, on the argument that you met the standard as it existed at the time. Or it may quietly lapse into ambiguity that nobody tests until something goes wrong, which is the worst version because it surfaces during an incident or a claim rather than at a renewal.

The drafting decides this. A clause written as "maintain ASD Essential Eight Maturity Level 2" is a narrow obligation pointing at a named artefact. A clause written as "maintain a maturity level equivalent to ASD Essential Eight Maturity Level 2 or its successor framework" already has its answer. Clauses in the second form are rare, because until June nobody thought they needed one.

Why this is cheaper to deal with now

An obligation you find in 2026 is an administrative task. You raise it at the next renewal, agree a successor reference, and move on. Nobody is under pressure and nothing is at stake in the conversation.

The same obligation found in 2028 is a different exercise. By then the Essential Eight is gone, your counterparty's procurement team has its own view of what you agreed to, and the discussion is happening because something prompted it. A renewal that stalls, a security questionnaire that comes back rejected, a claim where the insurer reads your attestation more narrowly than you did. Contractual ambiguity is only ever expensive at the moment it is discovered, and you do not control when that is.

There is also a practical asymmetry. You are probably not the only party with this problem, which means your counterparties are going to start asking the same question. Being the one who raises it first, with a clear position and evidence behind it, is a considerably better place to negotiate from than being asked.

What to do before mid-2027

Find the clauses. Search your contract repository and your tender responses for "Essential Eight", "Essential 8", "E8", "ASD" and "maturity level". Panel deeds need the same sweep and are the ones most often missed. Include the documents that live outside the contract system, which in most businesses means completed security questionnaires and insurance paperwork sitting in somebody's mailbox. Build a list of every obligation, who it is owed to, what level it names and when the agreement next comes up for renewal.

Sort that list by renewal date, not by customer size. The agreements renewing before mid-2027 are the ones where you get a free conversation, because you are already opening the document. Anything renewing after retirement is where you may need to raise the subject on its own.

Decide your standing position before you are asked. For most businesses that position is straightforward: you will continue to meet the control outcomes the clause was written to secure, and you will map them to the successor framework once ASD publishes it. That is a defensible answer and it does not commit you to anything you were not already doing.

Get evidence of where you actually sit while the framework is still current. This is the part with a genuine deadline attached. An assessment completed against the Essential Eight in 2026 is evidence against the standard your contracts name, which is worth more than a retrospective assessment done after retirement against a framework your counterparty never agreed to. It also tells you whether the level you attested to is the level you hold, which is an uncomfortable question worth answering privately first. Under the Essential Eight your maturity level is your worst performing strategy, so seven strong controls and one weak one is Maturity Level 1, not Level 2.

Then flag it with the people who sign things. Whoever handles your contracts and insurance renewals needs to know that a named framework in a draft is now a question rather than boilerplate, and that "or its successor framework" is cheap to add today.

If you want evidence of where you sit while the Essential Eight is still the current standard, we run fixed-price Essential Eight assessments with a board-ready report and a remediation roadmap. That report is the document you hand to a counterparty who asks what your clause actually means, and it is worth more signed in 2026 than reconstructed in 2028.

Frequently asked questions

Does the Essential Eight still apply right now?

Yes. It remains the current standard and nothing changes until deprecation begins around mid-2027. Both the Essential Eight and the Essentials guidance are expected to run together through the transition.

Will my existing Essential Eight work be wasted?

No. The controls carry across to the Essentials series, which is being built around the same control outcomes rather than replacing them. The structure changes more than the substance.

What happens to Commonwealth entities mandated under PSPF Policy 14?

Policy 14 requires Maturity Level 2 and has not been amended. It will presumably be updated once ASD publishes the final Essentials series. Worth noting that as of the 2025 Commonwealth Cyber Security Posture report only 22 per cent of Commonwealth entities had reached the level they are mandated to hold.

Should we add "or successor framework" wording to new contracts?

It costs nothing and removes the problem before it exists. For agreements you are drafting now, referencing the control outcomes rather than the framework name is even cleaner.

Does the Cyber Security Act 2024 change any of this?

No. The Act does not mention the Essential Eight anywhere in its text, and the reporting obligations that sit alongside it run on a separate track. Retiring the framework has no effect on the payment reporting requirement.

Where this leaves you

The security work was never the exposed part of this transition. The controls are sound, they carry across, and the sensible response to the framework changing is to keep implementing them.

The exposure is in the paperwork. Contracts, tenders, questionnaires and insurance attestations that name a standard with a retirement date, held by people who are not tracking ASD announcements. Finding those documents is a short exercise this year and an argument in two years, and the difference between those two outcomes is entirely a matter of when you go looking.

Essential Eight

Find out which maturity level you actually hold.

We assess your environment against each of the eight controls, show you where you sit today, and set out what closing the gap involves. You get the findings whether or not you engage us for the uplift.