Published 18 July 2026
Essential Eight and your cyber insurance renewal in 2026
Cyber insurance renewals have a rhythm: the broker's email arrives, the questionnaire is longer than last year, and somewhere in it is a question about your Essential Eight maturity. This year there's a new wrinkle — the Essential Eight is being retired. So does it still matter for your renewal?
The short answer: yes. The retirement is a staged transition running to roughly mid-2028, and for the 2026–27 renewal cycle, insurer questionnaires still reference the Essential Eight. Prepare exactly as you would have before the announcement — with one extra reason to keep your documentation current rather than one-off.
Why the Essential Eight retirement doesn't change this renewal
Frameworks don't govern insurance questionnaires; paperwork does. The questionnaire your broker sends exists because an underwriter wrote it, and it gets rewritten on the insurer's schedule, not ASD's. Until the Essentials series is finalised (ASD's consultation announcement indicates the first chapter is expected late 2026) and each insurer updates its forms — a process likely to span the whole transition — the questions stay Essential Eight-shaped.
There's also a practical reason nothing changes: ASD has been explicit that Essential Eight controls map across to the new framework. MFA, tested backups, patching, and restricted admin rights are what underwriters care about. Those don't stop mattering because the framework reorganises around them.
What insurers commonly ask about — including the bits the Essential Eight never covered
Here's something that surprises many businesses at renewal: the questionnaire has always asked for more than the Essential Eight. Questions vary by insurer — we've covered what Australian cyber insurers commonly require in full — but renewal questionnaires commonly cover:
- Multi-factor authentication — often the first question, and often specific: email, remote access, admin accounts, cloud consoles.
- Backups — not just "do you have them" but whether they're protected from tampering and when you last tested a restore.
- Patching — whether you have a defined cadence, especially for critical fixes.
- Admin privileges — who has them, and whether day-to-day work happens on standard accounts.
- An incident response plan — a documented, current plan for the first days of an incident. Notably, this isn't one of the eight Essential Eight controls at all.
- Email authentication — SPF, DKIM and DMARC records, because so many claims start with a spoofed email. Also not an Essential Eight control.
- Staff security-awareness training — recurring, not a one-off induction video. Again: not in the Essential Eight.
The pattern: the Essential Eight is the spine of the questionnaire, not the whole of it. A business that treats "Essential Eight done" as "renewal ready" usually discovers the gap in the middle of form-filling — the worst possible time.
The evidence brokers typically want to see
Answering the questionnaire is one thing; being asked to back an answer up is another. The documents brokers and underwriters commonly request from small businesses are unglamorous: written security policies (access control, backups, acceptable use), something showing your current control posture, and an incident response plan. Two properties matter more than polish — that they exist in writing, and that they're current. A policy dated three years ago can read worse than no policy, because it suggests documentation happens once and is forgotten. Controls drift; questionnaires are increasingly written to detect that.
A worthwhile habit: whenever you answer a questionnaire, keep a copy of what you attested alongside the evidence behind each answer. Your answers form part of the basis on which cover is offered, so accuracy matters — and next year's renewal becomes an update rather than an archaeology dig.
Preparing without a consultant
For a typical small business, renewal preparation is self-serve:
- Establish where you stand. Our free Essential Eight self-assessment gives you an indicative Level 0–3 per control in about 20 minutes, against the current ACSC model.
- Close the loud gaps first. MFA coverage and untested backups are the most commonly cited weak points — and your overall maturity equals your weakest control, so one gap holds down the whole score.
- Get the documents in order — the policies, the incident response plan, the evidence summary. This is exactly what Veritas Cyber generates from your self-assessment answers, as a subscription so it stays current rather than snapshotting one good day in 2026.
- Answer the questionnaire honestly. If a control is partial, say it's partial. An accurate "in progress" serves you far better at claim time than an optimistic "yes".
The honest boundaries, stated plainly: a self-assessment is not a certification or an audit, no maturity level guarantees cover or any particular premium, and insurers make their own underwriting decisions. What good preparation actually buys you is speed, consistency, and fewer surprises mid-renewal.
How much lead time to leave
More than you think. Fixing a gap isn't instant: rolling MFA out to every staff member, running and documenting a backup restore test, or writing an incident response plan each take days to weeks — and some fixes (like changing how admin accounts are handled) need coordination with your IT provider. If your self-assessment turns up two or three gaps, starting the week the renewal form arrives means answering "no" to questions you could have answered "yes" to with a two-month head start.
A comfortable rhythm for a small business: self-assess about three months before renewal, spend the middle month closing the loudest gaps, and use the final month to get documents current and questionnaire answers drafted. That also matches how controls actually behave — they drift quietly across a year, so an annual pre-renewal check is the natural moment to catch it.
FAQ
Does my insurer still want Essential Eight evidence now that it's being retired?
In practice, yes. The retirement is a staged transition over roughly two years, and insurer questionnaires, contracts, and broker checklists that reference the Essential Eight keep operating on it until each is updated. For a 2026–27 renewal, expect the same Essential Eight-shaped questions as last year.
What do cyber insurers commonly ask for at renewal in Australia?
Questionnaires vary by insurer, but commonly cover multi-factor authentication coverage, endpoint protection, backup arrangements and testing, patching cadence, admin-privilege restrictions, staff security-awareness training, email authentication, and whether you have a documented incident response plan.
Is a self-assessment enough for my renewal?
That's the insurer's call, not ours. Most small-business questionnaires rely on your own attestations, and a current, documented self-assessment makes answering them faster and more consistent. It is not a certification or audit, and some insurers ask for independent validation at higher cover levels.
What happens to renewals once the Essentials series replaces the Essential Eight?
Insurers will update their questionnaires gradually as the new framework lands. Because ASD says Essential Eight controls map across to the Essentials series, evidence of well-documented controls now should remain useful — the substance carries over even where the labels change.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).