Skip to main content
    NixInfinity-AI
    Patching Rules

    Cyber Essentials Patching Requirements (14-Day Rule)

    Published 29 June 2026

    The 14-day rule in plain English

    When a vendor (Microsoft, Apple, Google, Mozilla, etc.) releases a security patch they classify as high or critical, you must install it across every in-scope device within 14 calendar days. This is one of the most commonly misunderstood Cyber Essentials controls.

    What counts as "high" or "critical"

    The classification follows the vendor's own labelling, not yours. If Microsoft labels a patch "Critical", it's critical. If a CVE has a CVSS score of 7.0 or above and is rated high/critical by the vendor, it falls under the rule.

    You do not need to install every patch within 14 days – low-severity and informational patches have no time limit under CE. But the vendor's classification, not yours, decides which patches are in scope.

    What's in scope for the 14-day rule

    • Operating systems (Windows, macOS, iOS, Android, Linux distros in use)
    • Browsers (Edge, Chrome, Safari, Firefox)
    • Browser plug-ins still in use
    • Office productivity suites (Microsoft 365 Apps, Google Workspace clients)
    • Business-critical applications (CRM, ERP, accounting, etc.)
    • Firmware on internet-facing routers/firewalls

    Evidence assessors expect

    One screenshot of "Windows Update is on" is not enough. Assessors want to see a process:

    • How updates are deployed (auto-update, WSUS, Intune, Jamf, manual)
    • How you know they're applied (compliance report, central console, sample screenshots)
    • What happens if a device falls behind (process to investigate and remediate)
    • Who is responsible (named role, not "IT")

    The strongest evidence you can provide

    1. A central compliance report from Intune, Jamf, JumpCloud or similar showing patch level for every device
    2. Screenshots from a representative sample of devices showing auto-update enabled and current
    3. A short written patching procedure (one page is fine) describing process, frequency and ownership
    4. Vendor settings: Windows Update for Business policy, macOS Software Update settings, browser auto-update on

    Specific configuration recommendations

    Windows

    • Windows Update for Business policy via Intune or local GPO
    • Quality updates: 0–3 day deferral max
    • Feature updates: 30–90 day deferral acceptable
    • Restart enforcement after 7 days

    macOS

    • System Settings → Software Update → Automatic updates ON
    • Install macOS updates and Security Responses ON
    • Push major version upgrades within the supported-OS window

    iOS / Android

    • Auto-update ON in device settings
    • Conditional Access policy blocking unsupported OS versions for sign-in (recommended)

    Microsoft 365 Apps

    • Set channel to Current Channel or Monthly Enterprise Channel
    • Avoid Semi-Annual Channel – it lags too far behind

    Internet-facing services: the tighter rule

    Under the 2026 IASME update, the 14-day rule for internet-facing services is more strictly enforced. If you self-host anything exposed to the internet (web app, VPN gateway, mail server), you must demonstrate that high/critical CVEs are patched within 14 days with documented evidence – usually a vulnerability scan dated within the assessment window.

    End-of-life software: the absolute rule

    Software past vendor end-of-support cannot be patched and is therefore an automatic CE fail. This includes Windows 7, Windows 8.1, old macOS versions, and any business application the vendor no longer supports. Either upgrade, replace, isolate from in-scope networks, or remove from scope.

    Common patching fails

    1. One device with auto-update disabled because "it interrupts my work"
    2. Server still on an unsupported OS version
    3. Browser plug-in (e.g. an old Java runtime) abandoned but still installed
    4. Mobile devices on stale Android versions because the carrier never pushes updates
    5. Business application 18 months past last vendor patch

    The 30-minute patching audit

    1. Pull the most recent patch compliance report from your MDM (or screenshot a sample of devices)
    2. Confirm Windows Update for Business / macOS auto-update / Office channel settings
    3. List every business-critical application and confirm vendor still supports it
    4. Document the patching procedure in writing (one page)
    5. If you self-host internet-facing services, run a vulnerability scan and save the report

    Need a hand getting certified?

    Speak to an IASME-licensed assessor. Pre-check, plain-English support, certificates issued £320 + VAT.

    Frequently Asked Questions