Table of Contents

Free Active Directory Auditing Tool

Try it now
cyber essentials patching requirements

Cyber Essentials Patching Requirements: Meeting the 14-Day Rule

Table of Contents

The Cyber Essentials patching requirements have the straightforward aim of preventing attackers from exploiting known vulnerabilities for which fixes are available. The Security Update Management technical control includes a clear timeframe, designed to balance security with practicality; organizations must apply certain fixes within 14 days of release. Under the Danzell question set introduced in v3.3, organizations that don’t meet this requirement automatically fail the assessment.

Unfortunately, meeting the 14-day rule is more complicated than simply turning on Windows Update. Understanding where the 14-day rule applies, and how to build a compliant patching process, are therefore key for organizations looking to certify with Cyber Essentials.

What are the Cyber Essentials Patching Requirements?

Under Cyber Essentials v3.3, all software within the certification scope must be kept up to date. That means organizations need to make sure software is:

  • Licensed and supported by a vendor that continues to provide vulnerability fixes.
  • Removed when it becomes unsupported or removed from scope using a defined sub-set that prevents all internet traffic to and from it.
  • Configured to use automatic updates wherever possible.
  • Updated with qualifying vulnerability fixes within 14 days of release.

Cyber Essentials requires a vulnerability fix to be applied within 14 days when any of the following conditions apply:

  • The vendor describes the vulnerability as critical or high risk (such as Chrome’s “critical” or “high” security updates).
  • The vulnerability has a CVSS v3 base score of 7.0 or above.
  • The vendor releases the update without providing a severity level for the vulnerabilities it fixes.

Cyber Essentials recommends applying all released updates within 14 days where possible, but this is not mandatory for those that fall outside the criteria above. However, if a vendor releases a single update that addresses several vulnerabilities with different severity ratings, the presence of even one critical or high-risk vulnerability means the whole update must be installed within 14 days.

What Counts as a Vulnerability Fix?

Cyber Essentials recognizes that vendors use different methods to address security issues, so the requirement covers whatever mechanism the vendor prescribes to correct a known vulnerability. This includes patches, security updates, registry fixes, scripts and configuration changes.

For example, a vendor discovers a vulnerability in its VPN appliance but doesn’t immediately release a new software package. Instead, its security advisory instructs customers to disable the affected feature and apply a specific configuration change. If that change corrects the vulnerability, implementing it would count as applying the vulnerability fix for Cyber Essentials purposes.

desktop screen with warnings
How many of your end-users are using a compromised password in AD?

What Devices and Systems do the Patching Requirements Apply to?

The Security Update Management control specifically applies to servers, desktop computers, laptops, tablets, mobile phones, firewalls, and routers. It also applies to cloud services, with the control highlighting infrastructure-as-a-service (IaaS), platform-as-a-service (PaaS) and software-as-a-service (SaaS).

Cyber Essentials generally covers devices and software that can accept incoming connections from internet-connected devices, establish outbound connections via the internet, or control traffic between those devices and the internet. IT teams therefore need visibility of the software running across the full certification scope.

What About Third-Party Applications?

Cyber Essentials doesn’t distinguish between software supplied with a device and applications installed later. The Security Update Management requirements apply to all software in scope, including commercial off-the-shelf applications, extensions, scripts and libraries.

For example, imagine an organization has fully patched Windows laptops, but those laptops also run a third-party PDF reader. The vendor releases an update that fixes a vulnerability rated CVSS 8.0. Because the application is installed on in-scope devices and the vulnerability meets the Cyber Essentials severity threshold, the organization must ensure that update is applied within 14 days. The fact that Windows itself is fully patched does not change that requirement.

How Can You Meet Cyber Essential Patching Requirements?

The simplest way to meet the Cyber Essentials patching requirements consistently is to make them part of your standard operating process, rather than reacting to each new vulnerability as it appears. The following controls provide a practical starting point, alongside clear evidence that they are working as intended:

1. Know What is in Scope

Start with a clear view of the devices, software, firmware and cloud services covered by your Cyber Essentials assessment. This should include everything in scope, including third-party applications and less obvious software components, not just operating systems.

Support status should also form part of this review, so teams can identify software that is approaching end of life and upgrade, replace or remove it before it becomes a certification issue.

2. Enable Automatic Updates Where Possible

For software with a built-in update mechanism, this removes a significant amount of manual work from the patching process.

However, while automatic updating is useful, it isn’t a substitute for oversight. Organizations still need to know when fixes are released and whether they have been installed successfully. If an update fails and the vulnerability remains unpatched beyond the 14-day deadline, the organization won’t meet the Cyber Essentials patching requirement.

Organizations can mitigate this risk by configuring deployment so critical fixes reach all devices within seven days, aligning with the NCSC’s wider vulnerability management advice. That leaves a buffer for devices that are offline, updates that fail or patches that need to be redeployed.

3. Control Third-Party Applications

An organization may have tightly controlled operating system updates while collaboration tools, utilities and other applications follow completely different update processes.

A defined application allow-list can make this easier to manage. Every approved application should have a clear update route, which usually means it is either:

  • Configured to update automatically.
  • Managed through a platform that supports third-party patching.
  • Documented as an exception with a named owner and a defined remediation process.

Simplify the Patching Process with Specops

Organizations often need to manage a mix of corporate devices, personal devices and different operating systems, some of which sit outside traditional IT management. Keeping patches current across such a complex environment is difficult, particularly when you also need to demonstrate that your Cyber Essentials controls are working.

Solutions such as Specops Device Trust can help reduce that burden by giving security teams greater visibility and control across Windows, macOS, Linux and mobile devices. Policies can be applied by user, group or device type, with checks covering areas including operating system configuration and third-party application updates. This allows teams to ensure updates reach every device and enforce policies designed around requirements such as Cyber Essentials.

Specops Device Trust continuously checks device posture at login and throughout active sessions. Where an issue is found, one-click remediation allows users to resolve problems without waiting for IT support. This includes guided support for personal devices so organizations can remain compliant without invading privacy.

Grace periods then give users time to apply required updates before access is restricted, helping balance security requirements with day-to-day productivity.

Specops Device Trust also works alongside existing MDM platforms such as Microsoft Intune, adding continuous verification that devices remain compliant with your defined policies.

If you’d like to see how Specops Device Trust could support patch management in your environment, book a demo today.

Cyber Essentials Patching FAQs

Does every update have to be installed within 14 days?

No. The 14-day deadline applies when the vendor rates a vulnerability as critical or high risk, it has a CVSS v3 base score of 7.0 or above, or the vendor provides no severity information. It’s recommended to apply all updates within 14 days where possible.

Are automatic updates required for Cyber Essentials?

Yes, where possible. If the software supports automatic updating, Cyber Essentials requires it to be enabled. Organizations should still check that updates have been installed successfully, as devices can miss automatic updates for reasons like being offline or requiring a restart.

What if you need to test a patch before deployment?

You can test updates before wider deployment, but testing does not extend the Cyber Essentials deadline. Qualifying vulnerability fixes still need to be applied within 14 days of release, so you must fit testing and rollout inside that window. The NCSC recommends phased deployments as a way to test updates while keeping rollout moving.

What happens if there is a vulnerability but no patch yet?

The 14-day requirement applies to vulnerabilities for which a fix is available, so there is no 14-day patching deadline if the vendor hasn’t yet provided a fix. However, organizations should monitor the vendor closely for updates or other prescribed fixes. Remember that a Cyber Essentials vulnerability fix can be a configuration change, script or other vendor-approved mechanism rather than a conventional patch.

Does the requirement apply to cloud services?

Yes. Cloud services that fall within the scope of your Cyber Essentials certification must also meet the scheme’s security update management requirements. The responsibility depends on the service model: with SaaS, the provider will usually handle patching, while IaaS and PaaS leave more responsibility with the customer.

Last updated on September 28, 2026

darren james

Written by

Darren James

Darren James is a Senior Product Manager at Specops Software, an Outpost24 company. Darren is a seasoned cybersecurity professional with more than 20 years of experience in the IT industry. He has worked as a consultant across various organizations and sectors, including central and local governments, retail and energy. His areas of specialization include identity and access management, Active Directory, and Azure AD. Darren has been with Specops Software for more than 12 years and brings his expertise to the support and development of world-class password security and authentication solutions. 

Back to Blog

Related Articles


Free Active Directory Auditing Tool!