CYBER ESSENTIALS

The Cyber Essentials 14-Day Rule

Critical and high-risk security updates shouldn't wait.

Cyber Essentials 14-day security update rule

Keeping software up to date is one of the most important steps an organisation can take to protect itself from cyber-attack.

Under Cyber Essentials, organisations must ensure that high-risk or critical security updates are applied within 14 days of release, where the vulnerability meets the scheme's criteria and an update is available.

Why 14 days?

Because once a vulnerability becomes publicly known, attackers can move quickly to exploit it. The longer vulnerable software remains unpatched, the greater the opportunity for it to be used as a route into your organization.

A security update isn't simply an IT maintenance task. It's the removal of a known security weakness.

How the Rule Works

Cyber Essentials requires organisations to keep in-scope software supported and appropriately updated.

This includes operating systems, applications, browsers, internet-facing services, firmware and other software within the scope of the assessment.

The important distinction is that not every available software update has to be installed within 14 days.

The 14-day requirement applies to security updates addressing vulnerabilities that Cyber Essentials considers sufficiently serious, including vulnerabilities with a CVSS v3 base score of 7.0 or higher, where the vendor describes the issue as critical or high risk, or where there is no CVSS score but the vendor identifies it as critical or high risk.

Where those conditions apply and a security update is available, it should be installed within 14 days of release.

The clock starts when the fix becomes available

This is an important point.

The requirement isn't simply to discover the vulnerability within 14 days. The relevant security update needs to be applied within the required period.

That means organisations need processes capable of answering three basic questions:

  • What software are we running?
  • Is it affected by a qualifying vulnerability?
  • Has the appropriate security update been applied in time?

Without good visibility across your assets, answering those questions consistently can become surprisingly difficult.

Practical Checklist

Eight practical steps for staying inside the Cyber Essentials security update requirement.

1. Know what you have

Maintain visibility of the operating systems, applications and other software deployed across your organization. You can't reliably patch something you don't know exists.

2. Make sure software is supported

Software should be licensed and supported by the vendor. If a product has reached end-of-life and no longer receives security updates, upgrading or replacing it may be the only practical way to remain secure.

3. Monitor for security updates

Establish a process for identifying new security updates and vulnerabilities affecting the software you use. Don't rely on individual users noticing update notifications.

4. Prioritise critical and high-risk vulnerabilities

Identify updates that fall within the Cyber Essentials 14-day requirement and prioritise them accordingly. The most serious vulnerabilities shouldn't sit in the same queue as routine software updates.

5. Apply qualifying updates within 14 days

Where a vulnerability meets the Cyber Essentials criteria and an update is available, ensure it is deployed within the required timeframe. Where automatic updates are available and appropriate, enabling them can significantly simplify this process.

6. Don't forget applications

Patching isn't just about Windows, macOS or Linux. Browsers, productivity software, applications, internet-facing services, firmware and other components can all contain vulnerabilities that require attention.

7. Remove software you no longer need

Every unnecessary application creates another component that needs to be monitored, maintained and potentially patched. If you don't need it, remove it.

8. Verify - don't just assume

An update being approved or deployed doesn't necessarily mean every device successfully received it. Check that remediation has actually taken place.

Why This Matters

Cyber criminals routinely exploit known vulnerabilities.

Once details of a vulnerability become public, attackers may analyse the vulnerability, develop exploits and actively search the internet for organisations that remain exposed.

That creates a simple but important distinction:

Unknown vulnerability → difficult to anticipate

Known vulnerability + available fix + not patched → avoidable exposure

The 14-day rule is designed to reduce that window of opportunity.

Think of patching as closing an identified door

Imagine discovering that a particular lock used throughout your offices can be easily bypassed.

The manufacturer supplies a replacement.

You wouldn't regard ordering the new locks as solving the problem. The risk remains until the locks have actually been changed.

Security updates work in much the same way.

Identifying a vulnerability is only the beginning. Remediation is what reduces the risk.

How SecureX7 Helps

Continuous vulnerability and security posture assessment is fundamental to SecureX7.

From finding the problem to confirming the fix

Managing the 14-day rule manually becomes increasingly difficult as the number of users, devices and applications grows.

SecureX7 helps provide continuous visibility into your assets, vulnerabilities and security posture, allowing teams to identify issues that require attention and prioritise remediation based on risk.

Rather than relying solely on periodic checks and spreadsheets, SecureX7 can help you understand:

What is vulnerable → How serious it is → What needs attention → What action should be taken → Whether the issue has subsequently been resolved.

And because SecureX7 continually reassesses security posture, remediation doesn't have to end with someone simply ticking a box.

Find it. Prioritise it. Fix it. Verify it.

Remove what you don't need. Secure what you do. Fix known weaknesses quickly. Continuously verify your security posture.

SecureX7

SecureX7 is a natively built, AI-driven cyber security platform that helps organizations become operationally secure and continuously compliant, without complexity.

Popular articles