CYBER ESSENTIALS
The Cyber Essentials 14-Day Rule
Critical and high-risk security updates shouldn't wait.

Keeping software up to date is one of the most important steps an organisation can take to protect itself from cyber-attack.
Under Cyber Essentials, organisations must ensure that high-risk or critical security updates are applied within 14 days of release, where the vulnerability meets the scheme's criteria and an update is available.
Why 14 days?
Because once a vulnerability becomes publicly known, attackers can move quickly to exploit it. The longer vulnerable software remains unpatched, the greater the opportunity for it to be used as a route into your organization.
A security update isn't simply an IT maintenance task. It's the removal of a known security weakness.
How the Rule Works
Cyber Essentials requires organisations to keep in-scope software supported and appropriately updated.
This includes operating systems, applications, browsers, internet-facing services, firmware and other software within the scope of the assessment.
The important distinction is that not every available software update has to be installed within 14 days.
The 14-day requirement applies to security updates addressing vulnerabilities that Cyber Essentials considers sufficiently serious, including vulnerabilities with a CVSS v3 base score of 7.0 or higher, where the vendor describes the issue as critical or high risk, or where there is no CVSS score but the vendor identifies it as critical or high risk.
Where those conditions apply and a security update is available, it should be installed within 14 days of release.
The clock starts when the fix becomes available
This is an important point.
The requirement isn't simply to discover the vulnerability within 14 days. The relevant security update needs to be applied within the required period.
That means organisations need processes capable of answering three basic questions:
- What software are we running?
- Is it affected by a qualifying vulnerability?
- Has the appropriate security update been applied in time?
Without good visibility across your assets, answering those questions consistently can become surprisingly difficult.
Practical Checklist
Eight practical steps for staying inside the Cyber Essentials security update requirement.
1. Know what you have
Maintain visibility of the operating systems, applications and other software deployed across your organization. You can't reliably patch something you don't know exists.
2. Make sure software is supported
Software should be licensed and supported by the vendor. If a product has reached end-of-life and no longer receives security updates, upgrading or replacing it may be the only practical way to remain secure.
3. Monitor for security updates
Establish a process for identifying new security updates and vulnerabilities affecting the software you use. Don't rely on individual users noticing update notifications.
4. Prioritise critical and high-risk vulnerabilities
Identify updates that fall within the Cyber Essentials 14-day requirement and prioritise them accordingly. The most serious vulnerabilities shouldn't sit in the same queue as routine software updates.
5. Apply qualifying updates within 14 days
Where a vulnerability meets the Cyber Essentials criteria and an update is available, ensure it is deployed within the required timeframe. Where automatic updates are available and appropriate, enabling them can significantly simplify this process.
6. Don't forget applications
Patching isn't just about Windows, macOS or Linux. Browsers, productivity software, applications, internet-facing services, firmware and other components can all contain vulnerabilities that require attention.
7. Remove software you no longer need
Every unnecessary application creates another component that needs to be monitored, maintained and potentially patched. If you don't need it, remove it.
8. Verify - don't just assume
An update being approved or deployed doesn't necessarily mean every device successfully received it. Check that remediation has actually taken place.
Why This Matters
Cyber criminals routinely exploit known vulnerabilities.
Once details of a vulnerability become public, attackers may analyse the vulnerability, develop exploits and actively search the internet for organisations that remain exposed.
That creates a simple but important distinction:
Unknown vulnerability → difficult to anticipate
Known vulnerability + available fix + not patched → avoidable exposure
The 14-day rule is designed to reduce that window of opportunity.
Think of patching as closing an identified door
Imagine discovering that a particular lock used throughout your offices can be easily bypassed.
The manufacturer supplies a replacement.
You wouldn't regard ordering the new locks as solving the problem. The risk remains until the locks have actually been changed.
Security updates work in much the same way.
Identifying a vulnerability is only the beginning. Remediation is what reduces the risk.
How SecureX7 Helps
Continuous vulnerability and security posture assessment is fundamental to SecureX7.
From finding the problem to confirming the fix
Managing the 14-day rule manually becomes increasingly difficult as the number of users, devices and applications grows.
SecureX7 helps provide continuous visibility into your assets, vulnerabilities and security posture, allowing teams to identify issues that require attention and prioritise remediation based on risk.
Rather than relying solely on periodic checks and spreadsheets, SecureX7 can help you understand:
What is vulnerable → How serious it is → What needs attention → What action should be taken → Whether the issue has subsequently been resolved.
And because SecureX7 continually reassesses security posture, remediation doesn't have to end with someone simply ticking a box.
Find it. Prioritise it. Fix it. Verify it.
Remove what you don't need. Secure what you do. Fix known weaknesses quickly. Continuously verify your security posture.


