Skip to content

Published 18 July 2026

Essential Eight and your cyber insurance renewal in 2026

Cyber insurance renewals have a rhythm. The broker's email arrives, the questionnaire is longer than last year, and somewhere in it there's a question about your Essential Eight maturity. This year there's a twist: the Essential Eight is being retired. So does it still matter for your renewal?

Short answer: yes. The retirement is a staged transition running to roughly mid-2028, and for the 2026–27 renewal cycle, insurer questionnaires still reference the Essential Eight. Prepare exactly as you would have before the announcement. If anything, you now have one more reason to keep your documentation current instead of doing it once.

Why the Essential Eight retirement doesn't change this renewal

Frameworks don't run insurance questionnaires. Paperwork does. The questionnaire your broker sends exists because an underwriter wrote it, and it gets rewritten on the insurer's timetable, not ASD's. Until the Essentials series is finalised (ASD's consultation announcement indicates the first chapter is expected late 2026) and each insurer updates its forms, the questions stay Essential Eight-shaped. That updating is likely to take the whole transition.

There's a practical reason too. ASD has been explicit that Essential Eight controls map across to the new framework. MFA, tested backups, patching and restricted admin rights are what underwriters care about. They don't stop mattering because the framework gets reorganised around them.

What insurers commonly ask about, including the bits the Essential Eight never covered

This one catches a lot of businesses out at renewal. The questionnaire has always asked for more than the Essential Eight. Questions vary by insurer (we've covered what Australian cyber insurers commonly require in full), but renewal questionnaires commonly cover:

  • Multi-factor authentication. Often the first question, and often specific: email, remote access, admin accounts, cloud consoles.
  • Backups. Not just "do you have them" but whether they're protected from tampering and when you last tested a restore.
  • Patching. Whether you have a set cadence, especially for critical fixes.
  • Admin privileges. Who has them, and whether day-to-day work happens on standard accounts.
  • An incident response plan. A written, current plan for the first days of an incident. Worth noting: this isn't one of the eight Essential Eight controls at all.
  • Email authentication. SPF, DKIM and DMARC records, because so many claims start with a spoofed email. Also not an Essential Eight control.
  • Staff security-awareness training. Recurring, not a one-off induction video. Again, not in the Essential Eight.

So the Essential Eight is the spine of the questionnaire, not the whole thing. A business that treats "Essential Eight done" as "renewal ready" usually finds the gap halfway through the form. Worst possible time.

The evidence brokers typically want to see

Answering the questionnaire is one thing. Being asked to back an answer up is another. The documents brokers and underwriters commonly request from small businesses are unglamorous: written security policies (access control, backups, acceptable use), something showing where your controls currently stand, and an incident response plan.

Two things matter more than polish. They need to exist in writing, and they need to be current. A policy dated three years ago can read worse than no policy, because it suggests documentation happens once and then gets forgotten. Controls drift, and questionnaires are increasingly written to pick that up.

A habit worth building: whenever you answer a questionnaire, keep a copy of what you attested next to the evidence behind each answer. Your answers form part of the basis on which cover is offered, so accuracy matters. And next year's renewal becomes an update, not an archaeology dig.

Preparing without a consultant

For a typical small business, renewal prep is something you can do yourself:

  1. Work out where you stand. Our free Essential Eight self-assessment gives you an indicative Level 0–3 per control in about 20 minutes, against the current ACSC model.
  2. Close the loud gaps first. MFA coverage and untested backups are the most commonly cited weak points. Your overall maturity equals your weakest control, so one gap holds down the whole score.
  3. Get the documents in order. The policies, the incident response plan, the evidence summary. This is exactly what Veritas Cyber generates from your self-assessment answers, as a subscription, so it stays current rather than capturing one good day in 2026.
  4. Answer the questionnaire honestly. If a control is partial, say it's partial. An accurate "in progress" serves you far better at claim time than an optimistic "yes".

The honest boundaries, plainly: a self-assessment is not a certification or an audit. A maturity level is not a guarantee of cover or any particular premium, and insurers make their own underwriting decisions. What good preparation actually gets you is speed, consistency and fewer surprises mid-renewal.

How much lead time to leave

More than you think. Fixing a gap isn't instant. Rolling MFA out to every staff member, running and documenting a backup restore test, writing an incident response plan: each of those takes days to weeks. Some fixes (like changing how admin accounts are handled) also need your IT provider on board. If your self-assessment turns up two or three gaps and you only start the week the renewal form arrives, you'll be answering "no" to questions a two-month head start would have turned into "yes".

A comfortable rhythm for a small business looks like this. Self-assess about three months out from renewal. Spend the middle month closing the loudest gaps. Use the last month to bring documents up to date and draft your questionnaire answers. That also fits how controls really behave: they drift quietly over a year, and a pre-renewal check each year is the natural moment to catch it.

FAQ

Does my insurer still want Essential Eight evidence now that it's being retired?

In practice, yes. The retirement is a staged transition over roughly two years, and insurer questionnaires, contracts and broker checklists that reference the Essential Eight keep running on it until each one is updated. For a 2026–27 renewal, expect the same Essential Eight-shaped questions as last year.

What do cyber insurers commonly ask for at renewal in Australia?

It varies by insurer. Questionnaires commonly cover multi-factor authentication coverage, endpoint protection, backup arrangements and testing, patching cadence, admin-privilege restrictions, staff security-awareness training, email authentication, and whether you have a documented incident response plan.

Is a self-assessment enough for my renewal?

That's the insurer's call, not ours. Most small-business questionnaires rely on your own attestations, and a current, documented self-assessment makes answering them faster and more consistent. It is not a certification or an audit, and some insurers ask for independent validation at higher cover levels.

What happens to renewals once the Essentials series replaces the Essential Eight?

Insurers will update their questionnaires gradually as the new framework lands. ASD says Essential Eight controls map across to the Essentials series, so evidence of well-documented controls now should stay useful. The substance carries over even where the labels change.

This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).