grc-scan

Security update management

Keeping software supported and patched, so known vulnerabilities are closed before attackers use them.

🔍 What a scan can verify

Our in-depth scan can detect known CVEs, out-of-date software and deprecated TLS versions, and version banners that reveal end-of-life software.

📝 What stays self-declared

We can't see your patch cadence across every device, whether auto-updates are on, or whether unsupported software has been fully removed — you tell us those.

What Cyber Essentials asks for this control

How to get ready

  • Make a list of your software and check nothing is past its end-of-life date; replace anything that is.
  • Turn on automatic updates everywhere you can.
  • Make sure critical/high security updates are applied within 14 days of release.

Check your security update management — and the other four controls

Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.

Start the free readiness check

← Back to all five Cyber Essentials controls.

This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.