grc-scan

Cyber Essentials question · Security update management

Is all of your software still supported by its vendor (nothing past its end-of-life date)?

This is a mandatory item. Answering “No” fails the whole Security update management section — and the overall assessment — however strong everything else is.

Why assessors ask this

Unsupported software no longer gets security fixes — it must be removed. This is an automatic fail.

Priority fix

Priority: identify and remove (or replace) any unsupported, end-of-life software — running it is an automatic Cyber Essentials fail.

What “good” looks like for Security update management

  • Make a list of your software and check nothing is past its end-of-life date; replace anything that is.
  • Turn on automatic updates everywhere you can.
  • Make sure critical/high security updates are applied within 14 days of release.

See where you stand in 5 minutes

Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.

Start the free readiness check

Part of the Security update management control.

This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.