Compliance
Application control, mapped to the frameworks that ask for it
App Control for Business, the Windows feature still called WDAC by most teams, is what nine different frameworks are describing when they ask you to restrict what can execute.
The framework is evolving. The control remains essential.
On 24 June 2026 the Australian Signals Directorate confirmed the Essential Eight will be retired and replaced by the Essentials series, structured as chapters for enterprise IT, operational technology and cloud rather than one list of eight mitigations. Both remain live documents through the transition.
Whatever form the new guidance takes, the need to control which executables, libraries and scripts can run remains. Application control continues to be a core preventive control for Windows environments.
The work you invest in Windows App Control now will remain valuable as frameworks and compliance requirements evolve.
What was announced
24 June 2026
ASD confirms the Essential Eight will be replaced by the Essentials series.
Around 12 months
Deprecation of the Essential Eight begins. Both documents stay live until then.
Around 24 months
The Essential Eight is expected to be fully retired.
The same control, under nine different names
Control references checked against each standard
ASD Essential Eight
transitioningOne of the eight, maturity levels one to three
What it asks for
Restrict which executables, libraries, scripts and installers are allowed to run, and keep it that way.
What you show an assessor
Which binary types the policy covers, on which device groups, and the events proving the policy is applied and enforcing.
ASD Essentials series
The incoming replacement
What it asks for
Not yet fully published, but application control is not the part of the Essential Eight anybody expects to be dropped.
What you show an assessor
The same policy estate and the same evidence trail. Framework mapping changes, the control does not.
ISO/IEC 27001:2022
Annex A 8.19
What it asks for
Control the installation of software on operational systems, with an approved list and a record of changes.
What you show an assessor
The approved software list as an enforced policy rather than a spreadsheet, plus who approved each addition and when.
NIST SP 800-53 Rev 5
CM-7(5), authorised software, allow by exception
What it asks for
Identify the software authorised to execute, verify its integrity, and deny everything else.
What you show an assessor
Rules expressed by signer, publisher or hash, which is the integrity verification the control asks for, and the deny by default posture underneath them.
CIS Controls v8
Control 2, inventory and control of software assets
What it asks for
Allowlist authorised software, and separately allowlist authorised libraries and scripts.
What you show an assessor
Coverage per binary type, since libraries and scripts are separate safeguards and a policy without the relevant rule options does not cover them.
NCSC Cyber Assessment Framework
B4.b Secure Configuration
What it asks for
That only permitted software can be installed. The indicator is written about installation rather than execution.
What you show an assessor
Application control answers the indicator and exceeds it, since it refuses execution rather than only restricting installation. Show the policy scope and the enforcement events.
NCSC Cyber Essentials
Control 5 Malware protection, application allow listing option
What it asks for
One malware protection mechanism per device. Allow listing is an accepted option in its own right, for all devices in scope, not a supplement to anti-malware.
What you show an assessor
That only approved applications can execute, and how approval is granted. Code signing is the mechanism the requirements name first.
NZ Information Security Manual
Chapter 14 Software security, 14.2 Application Allow listing
What it asks for
Application allow listing on systems in scope, as a control section in its own right rather than folded into malware protection. Mandated for New Zealand government agencies through PSR INFOSEC, which requires ICT systems to comply with the NZISM certification and accreditation process.
What you show an assessor
The same evidence as every other row: which binary types the policy covers, on which device groups, and the events proving it is applied and enforcing.
PCI DSS 4.0
Scope dependent
What it asks for
Run only necessary and approved software in the cardholder data environment, and log changes to it.
What you show an assessor
A defensible boundary around the in scope device group, with policy versions and approvals retrievable for the assessment window.
PoliEze helps organisations implement, govern and evidence the application control requirements found across security and compliance frameworks.
Bring us the framework you are being assessed against
We will tell you what application control has to cover to satisfy it, and what evidence an assessor will want. If the honest answer is that your internal applications need signing first, we would rather say that.