The Cyber Essentials 14-Day Patching Requirement

How security update management works under Danzell v3.3, including critical and high-risk patches.

Written by StandAssured editorial team
Reviewed by Apexward Certification Body assessor
Last reviewed: 9 August 2026
Requirements version: Danzell v3.3

Cyber Essentials expects organisations to apply relevant security updates promptly - typically within 14 days of release for applicable patches - and to remove or isolate unsupported software in scope.

Practical tips

  • Maintain an inventory of devices, applications and cloud services in scope
  • Automate updates where possible and track exceptions
  • Prioritise critical and high-risk vulnerabilities
  • Document how you handle systems that cannot be patched immediately