The Cyber Essentials 14-Day Patching Requirement
How security update management works under Danzell v3.3, including critical and high-risk patches.
Written by StandAssured editorial team
Reviewed by Apexward Certification Body assessor
Last reviewed: 9 August 2026
Requirements version: Danzell v3.3
Cyber Essentials expects organisations to apply relevant security updates promptly - typically within 14 days of release for applicable patches - and to remove or isolate unsupported software in scope.
Practical tips
- Maintain an inventory of devices, applications and cloud services in scope
- Automate updates where possible and track exceptions
- Prioritise critical and high-risk vulnerabilities
- Document how you handle systems that cannot be patched immediately