Security update management
Keeping software supported and patched, so known vulnerabilities are closed before attackers use them.
🔍 What a scan can verify
Our in-depth scan can detect known CVEs, out-of-date software and deprecated TLS versions, and version banners that reveal end-of-life software.
📝 What stays self-declared
We can't see your patch cadence across every device, whether auto-updates are on, or whether unsupported software has been fully removed — you tell us those.
What Cyber Essentials asks for this control
- Is all of your software still supported by its vendor (nothing past its end-of-life date)?
Unsupported software no longer gets security fixes — it must be removed. This is an automatic fail.
Mandatory item — a “No” here fails this whole control.
- Are high-risk and critical security updates applied within 14 days of the vendor releasing them?
Under the current question set the 14-day clock starts at the vendor's PUBLISH date, not when you notice — so monthly patching is now too slow.
- Are automatic updates turned on wherever they're available?
Auto-update is the most reliable way to stay inside the 14-day window.
How to get ready
- Make a list of your software and check nothing is past its end-of-life date; replace anything that is.
- Turn on automatic updates everywhere you can.
- Make sure critical/high security updates are applied within 14 days of release.
Check your security update management — and the other four controls
Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.
Start the free readiness check →← Back to all five Cyber Essentials controls.
This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.