Cyber Essentials question · Security update management
Are high-risk and critical security updates applied within 14 days of the vendor releasing them?
Why assessors ask this
Under the current question set the 14-day clock starts at the vendor's PUBLISH date, not when you notice — so monthly patching is now too slow.
What “good” looks like for Security update management
- Make a list of your software and check nothing is past its end-of-life date; replace anything that is.
- Turn on automatic updates everywhere you can.
- Make sure critical/high security updates are applied within 14 days of release.
See where you stand in 5 minutes
Answer the Cyber Essentials questions in plain English and get a per-control readiness verdict — free, no login needed, and we don't store your answers.
Start the free readiness check →Part of the Security update management control.
This is a free readiness / gap report to help you prepare — it is not a certification, and we are not an IASME Certification Body. To certify, you apply through an accredited Certification Body.