Compliance

Application control, mapped to the frameworks that ask for it

App Control for Business, the Windows feature still called WDAC by most teams, is what nine different frameworks are describing when they ask you to restrict what can execute.

The framework is evolving. The control remains essential.

On 24 June 2026 the Australian Signals Directorate confirmed the Essential Eight will be retired and replaced by the Essentials series, structured as chapters for enterprise IT, operational technology and cloud rather than one list of eight mitigations. Both remain live documents through the transition.

Whatever form the new guidance takes, the need to control which executables, libraries and scripts can run remains. Application control continues to be a core preventive control for Windows environments.

The work you invest in Windows App Control now will remain valuable as frameworks and compliance requirements evolve.

What was announced

  1. 24 June 2026

    ASD confirms the Essential Eight will be replaced by the Essentials series.

  2. Around 12 months

    Deprecation of the Essential Eight begins. Both documents stay live until then.

  3. Around 24 months

    The Essential Eight is expected to be fully retired.

The same control, under nine different names

Control references checked against each standard

FrameworkWhat it asks forWhat you show an assessor
  • ASD Essential Eight

    transitioning

    One of the eight, maturity levels one to three

    What it asks for

    Restrict which executables, libraries, scripts and installers are allowed to run, and keep it that way.

    What you show an assessor

    Which binary types the policy covers, on which device groups, and the events proving the policy is applied and enforcing.

  • ASD Essentials series

    The incoming replacement

    What it asks for

    Not yet fully published, but application control is not the part of the Essential Eight anybody expects to be dropped.

    What you show an assessor

    The same policy estate and the same evidence trail. Framework mapping changes, the control does not.

  • ISO/IEC 27001:2022

    Annex A 8.19

    What it asks for

    Control the installation of software on operational systems, with an approved list and a record of changes.

    What you show an assessor

    The approved software list as an enforced policy rather than a spreadsheet, plus who approved each addition and when.

  • NIST SP 800-53 Rev 5

    CM-7(5), authorised software, allow by exception

    What it asks for

    Identify the software authorised to execute, verify its integrity, and deny everything else.

    What you show an assessor

    Rules expressed by signer, publisher or hash, which is the integrity verification the control asks for, and the deny by default posture underneath them.

  • CIS Controls v8

    Control 2, inventory and control of software assets

    What it asks for

    Allowlist authorised software, and separately allowlist authorised libraries and scripts.

    What you show an assessor

    Coverage per binary type, since libraries and scripts are separate safeguards and a policy without the relevant rule options does not cover them.

  • NCSC Cyber Assessment Framework

    B4.b Secure Configuration

    What it asks for

    That only permitted software can be installed. The indicator is written about installation rather than execution.

    What you show an assessor

    Application control answers the indicator and exceeds it, since it refuses execution rather than only restricting installation. Show the policy scope and the enforcement events.

  • NCSC Cyber Essentials

    Control 5 Malware protection, application allow listing option

    What it asks for

    One malware protection mechanism per device. Allow listing is an accepted option in its own right, for all devices in scope, not a supplement to anti-malware.

    What you show an assessor

    That only approved applications can execute, and how approval is granted. Code signing is the mechanism the requirements name first.

  • NZ Information Security Manual

    Chapter 14 Software security, 14.2 Application Allow listing

    What it asks for

    Application allow listing on systems in scope, as a control section in its own right rather than folded into malware protection. Mandated for New Zealand government agencies through PSR INFOSEC, which requires ICT systems to comply with the NZISM certification and accreditation process.

    What you show an assessor

    The same evidence as every other row: which binary types the policy covers, on which device groups, and the events proving it is applied and enforcing.

  • PCI DSS 4.0

    Scope dependent

    What it asks for

    Run only necessary and approved software in the cardholder data environment, and log changes to it.

    What you show an assessor

    A defensible boundary around the in scope device group, with policy versions and approvals retrievable for the assessment window.

PoliEze helps organisations implement, govern and evidence the application control requirements found across security and compliance frameworks.

Bring us the framework you are being assessed against

We will tell you what application control has to cover to satisfy it, and what evidence an assessor will want. If the honest answer is that your internal applications need signing first, we would rather say that.