Cybersecurity moves fast. Since our SMB1001 webinar, the Essential Eight has been officially flagged for retirement and a new Essentials series is coming to replace it. Here's what it means, and why certification matters more than ever.
It's been a few months since we ran our SMB1001 webinar. So, how's it going? Managed to dodge all the cyber attacks so far? If the answer is "I think so" or "I haven't heard anything, so probably", that's exactly the problem. Cybersecurity isn't something you do once and forget about. It's an ongoing threat, and the businesses that stay protected are the ones treating it as an ongoing habit, not a one-off tick-box.
Here's what's shifted since we last talked about it.
The Essential Eight is being replaced
In June 2026, the Australian Signals Directorate (ASD) announced consultation on the future of the Essential Eight and introduced a broader framework called the Essentials series. Rather than one framework trying to cover every environment, the new model will be split into multiple chapters covering specific technology domains. The first chapter, Essentials for enterprise IT, is under consultation now, with future chapters expected to address cloud environments, operational technology, and emerging areas like AI.
The philosophy is shifting too. The Essential Eight was built around prescriptive controls and specific technologies. The Essentials series moves toward a more outcomes-focused approach, giving organisations more flexibility in how they achieve the security objectives.
The timeline: ASD expects to begin deprecating the Essential Eight around 12 months from now and retire it around 24 months after the new guidance is introduced. Both frameworks will run side by side during the transition.
What this means for Kiwi SMBs
If you've been working toward Essential Eight maturity, you're not starting over. ASD has confirmed strong alignment between existing controls and the new Essentials guidance. The work you've done still counts.
But it does reinforce a bigger point: the direction of travel is clear. Frameworks are getting more robust, expectations are getting sharper, and "we've got antivirus" isn't the answer it used to be. Clients, insurers, and regulators are increasingly asking businesses to prove they've done the basics, with evidence, not just assurances.
Have you actually done anything since the webinar?
This is the honest question worth sitting with for a minute. If the answer is no, that's OK. Most businesses we talk to are in the same spot. Between running the day-to-day and chasing the actual work, cybersecurity often becomes the thing you'll get to next quarter. Then the quarter after that.
The problem is that attackers aren't waiting for your next quarter. Phishing kits are getting sharper. AI is making impersonation attacks harder to spot. Ransomware is targeting smaller and smaller businesses because they're easier to breach and often less prepared to recover. Doing nothing is a decision. It's just usually not a very good one.
Why SMB1001 still matters, arguably more than ever
SMB1001 was built for exactly this moment. It's a practical, tiered cybersecurity certification designed for small and medium businesses. Proportionate to your size. Achievable without an enterprise budget. Clear about what "good" looks like.
Starting from just $95, it gives you three things:
- Clarity. You know where you stand, not where you assume you stand.
- Confidence. The gaps get fixed, in the right order.
- Credibility. You can prove your posture to clients, insurers, and prospects.
The tiered structure is the important bit. You don't have to jump straight to enterprise-grade security. You start where your business is, and step up as you grow, the same principle the new Essentials series is being built around.
How CloudTorque helps
We walk you through the whole thing. Assessment, remediation, certification, and everything that keeps you certified year on year. So, iIf you want a sense of where your business currently stands, talk to us - we're still offering free IT Planning Sessions.