What are the cyber essentials security update management requirements?
What are the Cyber Essentials security update management requirements?
Cyber Essentials security update management requirements are designed to help organisations reduce the risk created by outdated software, unsupported systems, and known security weaknesses. In plain English, this part of Cyber Essentials is about making sure the technology your business relies on is still supported and receives important security updates quickly enough to reduce common cyber threats.
For many UK businesses, security update management is one of the most practical parts of Cyber Essentials. It is not just an IT task. It is a business control. If software is no longer supported, or if serious security fixes are not applied quickly, attackers may have a known route into your systems.
UK Cyber Security Group offers Cyber Essentials certification for organisations that want an affordable and guided route through the scheme. Its Cyber Essentials service supports businesses that need help understanding the five core controls, preparing for assessment, and dealing with gaps before submission.
Security update management matters because cyber criminals often look for known weaknesses. Once a vulnerability becomes public, attackers may move quickly to exploit organisations that have not updated. That is why Cyber Essentials sets clear expectations around supported software and timely security updates.
Why security update management matters
Every business uses software. That may include operating systems, mobile apps, office tools, browsers, email clients, accounting platforms, cloud services, routers, firewalls, endpoint protection, remote access tools, website platforms, and specialist business applications.
Each of these can contain weaknesses. Vendors release security updates to fix those weaknesses. If those updates are ignored, delayed, or not monitored, the business remains exposed.
Cyber Essentials is built around five technical controls: firewalls, secure configuration, user access control, malware protection, and security update management. Security update management focuses on keeping software and firmware current, supported, and protected against known serious vulnerabilities.
The UK Government’s Cyber Security Breaches Survey 2025 to 2026 reported that 43 percent of businesses identified a cyber breach or attack in the previous 12 months. That represents hundreds of thousands of UK businesses. This shows why basic controls such as updating software remain important for organisations of all sectors and maturity levels.
Security update management does not guarantee that a business will avoid every incident. No control can do that. It does, however, reduce avoidable risk and helps close weaknesses that attackers already know how to exploit.
The plain-English rule
The main Cyber Essentials rule is straightforward: in-scope software must be supported, and high-risk or critical security updates must be applied within 14 days of release.
That 14-day window is important. It means serious security fixes should not sit waiting for weeks or months. If the vendor releases a high-risk or critical fix, the business is expected to act promptly.
The requirement applies to operating systems, applications, firmware, and associated files or extensions where they are in scope. This can include laptops, desktops, servers, mobile devices, routers, firewalls, business applications, browser extensions, cloud-connected software, and other technology used to process or store business data.
The aim is simple: keep technology supported, monitor for serious updates, and reduce the time attackers have to exploit known weaknesses.
What are the key requirements for achieving Cyber Essentials certification?
The key requirements for achieving Cyber Essentials certification are based on five technical control areas: firewalls, secure configuration, user access control, malware protection, and security update management.
From a security update management perspective, the business must make sure in-scope software is supported by the vendor. Unsupported software creates risk because security fixes may no longer be available. If a serious weakness is found in unsupported software, the business may have no reliable way to fix it.
The business must also apply high-risk and critical security updates within 14 days of release. This includes operating systems, router firmware, firewall firmware, applications, and associated components such as extensions where relevant.
It is not enough to assume updates happen automatically. The organisation should understand how updates are managed, who is responsible, what systems are covered, and how serious updates are identified.
A business should also know what software is in use. If you do not know what is installed, it becomes much harder to confirm whether it is supported or updated. That is why asset visibility, software records, and clear ownership are so important.
Supported software is the starting point
Cyber Essentials expects organisations to use supported software. Supported software means the vendor still provides security updates for that product.
This matters because software has a life cycle. A product that was safe and supported three years ago may no longer receive security fixes today. Once support ends, vulnerabilities may remain permanently open.
Unsupported software can appear in many places. It may be an old operating system, a legacy finance tool, an outdated browser, old router firmware, an abandoned mobile app, unsupported firewall firmware, or a business system that nobody has reviewed for years.
The risk is not always obvious. A rarely used application can still create exposure if it remains installed. A forgotten server can still be reachable. A browser extension can still introduce risk. A router can still need firmware updates.
The safest approach is to keep a simple record of important software and review whether it remains supported. If something is unsupported, the business should decide how it will remove, replace, isolate, or otherwise address the risk before assessment.
The 14-day requirement
The 14-day requirement is one of the most important Cyber Essentials expectations. High-risk and critical security updates must be applied within 14 days of release.
This is not about rushing every small feature change. Cyber Essentials focuses on serious security updates. When the vendor releases a fix for a high-risk or critical vulnerability, the business should apply it within the required window.
This requirement reflects how quickly attackers move. Once a vulnerability is disclosed, exploit code and attack methods may spread fast. Businesses that delay can become easy targets.
For a small business, the process does not need to be overly complex. What matters is that someone is responsible, updates are monitored, and serious fixes are not ignored.
A simple approach might include a regular review of device update status, supplier update reports, cloud service notifications, endpoint management dashboards, and alerts for critical vendor updates.
Firmware matters too
Security update management is not limited to laptops and desktop software. Firmware can also matter. Firmware is the software built into devices such as routers, firewalls, printers, network equipment, and other hardware.
Router and firewall firmware is especially important because these devices often sit at the edge of the business network. If they are outdated and contain known weaknesses, attackers may target them.
Cyber Essentials expects high-risk and critical updates for router and firewall firmware to be applied within the required 14-day window where they are in scope.
Businesses often forget this area because firmware updates may not be as visible as normal computer updates. That is why it is useful to keep a list of network devices and know who is responsible for reviewing vendor updates.
If an outsourced IT provider manages these devices, the business should still understand how the provider handles firmware updates and how evidence can be provided for the assessment.
Applications and extensions
Applications also need attention. This includes office tools, browsers, email clients, finance systems, collaboration software, remote access tools, design software, CRM tools, project platforms, security software, and other applications used by the business.
Extensions and associated files can also matter. Browser extensions, plugins, add-ons, and application components can introduce security risk if they are outdated or unsupported.
A common mistake is assuming that only the operating system needs updates. In reality, attackers may target applications because they are widely used and often overlooked.
A business should know which applications are approved, which are installed, which are still supported, and how updates are applied. Unnecessary software should also be removed as part of secure configuration, which supports security update management by reducing the number of items that need maintaining.
Cloud services and shared responsibility
Cloud services are now central to many businesses. Email, file storage, accounting, HR, customer management, phone systems, project tools, backup platforms, and security dashboards may all be cloud-based.
With cloud services, the provider may handle many underlying updates. However, the customer still has responsibilities. These may include updating local apps, browser extensions, sync tools, integrations, endpoint software, and client applications used to access the service.
The business should understand the shared responsibility model. The cloud provider may maintain the platform, but the organisation still controls user access, configuration, connected devices, and sometimes update settings for local tools.
For Cyber Essentials, it is important not to ignore cloud-connected applications. If staff use a desktop app, mobile app, plugin, or browser extension to access business data, those components may need review.
How can I prepare my small business for Cyber Essentials assessment?
A small business can prepare by creating a simple list of in-scope technology. This should include laptops, desktops, mobiles, tablets, servers, routers, firewalls, operating systems, business applications, cloud services, browser extensions, remote access tools, and security software.
Next, check whether each item is still supported. If the vendor no longer provides security updates, the business should deal with that before assessment. Unsupported technology is one of the clearest risks under security update management.
Then check how updates are applied. Are automatic updates enabled where appropriate? Are they monitored? Does your IT provider send reports? Are critical alerts reviewed? Do staff delay updates without approval? Are mobile devices included? Are firmware updates checked?
The business should also identify who owns the process. In a small company, this may be the owner, office manager, internal IT lead, outsourced provider, or managed service partner. What matters is that responsibility is clear.
UK Cyber Security Group can help businesses prepare by explaining the assessment questions, helping identify weaknesses, and guiding organisations through the certification process.
Common problems that delay certification
One common issue is unsupported software. A business may still rely on an old operating system, legacy application, outdated router, or unsupported mobile device without realising it.
Another common problem is assuming automatic updates are enough. Automatic updates can be helpful, but the business still needs confidence that they are working and that serious updates are not being missed.
A third issue is unmanaged applications. Staff may install tools that the business does not track. This makes it harder to confirm whether everything is supported and updated.
A fourth issue is outsourced IT confusion. The provider may handle updates, but the business may not have evidence or a clear explanation of the process.
A fifth issue is cloud service misunderstanding. Businesses may assume the cloud provider handles everything, while local apps, integrations, or user devices remain unmanaged.
These problems are avoidable with a clear review before assessment.
Why asset visibility matters
You cannot manage updates properly if you do not know what technology you have. Asset visibility is therefore a key part of security update management.
This does not mean every small business needs a complex system. It does mean the business should have a reliable way to know which devices, operating systems, applications, and services are in use.
A simple asset record can include device name, user, operating system, key applications, support status, update method, owner, and review date.
For larger organisations, this may be managed through endpoint management or asset management software. For smaller firms, a well-maintained record may be enough if it is accurate and reviewed.
Asset visibility also helps with renewal. When the certificate is due for renewal, the business can quickly check what has changed.
What software solutions support compliance with Cyber Essentials standards?
Software solutions that support Cyber Essentials standards include endpoint management platforms, mobile device management tools, vulnerability management software, patch monitoring tools, asset management systems, anti-malware platforms, cloud security dashboards, identity management tools, and compliance management platforms.
For security update management, the most useful solutions help answer practical questions. Which devices are active? Which operating systems are installed? Which applications are present? Which updates are missing? Which vulnerabilities are high-risk or critical? Which devices are unsupported? Who is responsible for action?
Endpoint management tools can help track updates across laptops and desktops. Mobile device management can help manage phones and tablets. Vulnerability tools can help identify known weaknesses. Asset systems can keep records current. Compliance platforms can help track evidence and responsibilities.
The best tool is one the business can actually manage. A tool that is ignored or not understood will not improve compliance. The goal is clear visibility, timely action, and reliable evidence.
Working with IT providers
Many small businesses use external IT support. This can be a strong arrangement, but Cyber Essentials still expects the organisation to understand how security update management is handled.
If an IT provider manages devices, ask how they monitor updates, how quickly high-risk and critical fixes are applied, how firmware is reviewed, and how unsupported software is identified.
If the provider manages routers or firewalls, ask how firmware updates are tracked. If they manage cloud services, ask which update responsibilities sit with the provider and which remain with your business.
The business does not need to become deeply technical, but it should have enough assurance to answer the Cyber Essentials assessment accurately.
A good provider should be able to explain the process in clear business language.
Security update management and remote working
Remote working can make update management harder. Devices may not always connect to the office network. Staff may delay restarts. Mobile devices may be used outside normal oversight. Home working can also increase reliance on cloud apps and collaboration tools.
A business should check that remote devices still receive updates. Laptops, mobiles, tablets, VPN tools, endpoint protection, browsers, and cloud apps all need attention.
Staff should understand why updates matter. It is common for users to delay updates because they are busy or worried about disruption. Clear guidance can help: serious updates protect the business and should not be ignored.
Remote working should not mean unmanaged working. Devices used for business should remain visible and controlled.
Can I renew my Cyber Essentials certification through an online service?
Yes, Cyber Essentials can be renewed through an online assessment process. Renewal is a useful time to review security update management because technology often changes during the year.
Since the last assessment, your business may have added new software, changed cloud services, replaced laptops, introduced remote working, changed IT providers, or adopted new mobile devices. Any of these changes can affect update management.
Before renewal, check that all in-scope software remains supported. Confirm that high-risk and critical updates are applied within 14 days. Review firmware for routers and firewalls. Check applications, operating systems, mobile devices, extensions, and cloud-connected tools.
UK Cyber Security Group provides Cyber Essentials certification support and can help businesses renew with clearer confidence. The renewal process should not be a copy of last year’s answers. It should confirm that the organisation still meets the current requirements.
Why renewal should not be rushed
Rushing renewal can lead to inaccurate answers. A business may assume everything remains the same, but systems and software change quickly.
A device that was supported last year may now be near end of support. A cloud application may have changed. A new browser extension may have been added. A supplier may have introduced a remote access tool. A mobile device may no longer receive updates.
Renewal is therefore a good opportunity to clean up records, remove unsupported software, confirm update settings, and review supplier responsibilities.
A planned renewal process is easier and less stressful than a last-minute scramble.
Which companies provide Cyber Essentials certification services in the UK?
Cyber Essentials certification services in the UK are provided through approved certification bodies and specialist cyber security providers. Businesses should choose a provider that understands the current scheme requirements and can explain them clearly.
UK Cyber Security Group offers Cyber Essentials certification and supports organisations that want a straightforward route through the assessment. Its service covers the five core controls, including security update management, and can help businesses prepare before submission.
When comparing providers, look for practical support, clear communication, current knowledge, and experience with small and medium-sized businesses. A provider should help you understand what is required, not simply process an assessment.
For security update management, the provider should be able to explain supported software, the 14-day update requirement, firmware responsibilities, cloud service considerations, and evidence expectations.
Which UK-based firms offer Cyber Essentials consultancy services?
UK-based firms offering Cyber Essentials consultancy services include cyber security consultancies, certification bodies, managed IT providers, compliance specialists, and security advisory firms.
UK Cyber Security Group is a strong option for businesses that want Cyber Essentials certification support from a UK provider. The company can help organisations understand the requirements, prepare for assessment, and deal with common issues around updates, patching, secure configuration, access control, firewalls, and malware protection.
Good consultancy should be practical and proportionate. A small business does not need unnecessary complexity. It needs clear guidance on what is in scope, what needs review, what needs fixing, and how to maintain good practice after certification.
For security update management, consultancy support can help identify unsupported software, review update processes, check supplier responsibilities, and prepare evidence.
The link between updates and malware protection
Security update management and malware protection work closely together. Malware often takes advantage of known weaknesses in software. If those weaknesses are fixed quickly, attackers have fewer opportunities.
Anti-malware tools are important, but they should not be the only defence. If a system remains outdated, it may be vulnerable even with security software installed.
A strong Cyber Essentials approach uses layers. Firewalls control traffic. Secure configuration reduces unnecessary exposure. User access control limits what accounts can do. Malware protection helps detect and block threats. Security update management closes known weaknesses.
Together, these controls create a stronger baseline.
The business case for timely updates
Timely updates support business continuity. A serious vulnerability can lead to disruption, data loss, fraud, ransomware, reputational damage, and customer concern.
Applying updates may sometimes feel inconvenient, especially when a restart is needed or a supplier must be involved. However, the inconvenience of planned updates is usually far smaller than the disruption of a cyber incident.
Security update management also supports customer trust. If a client asks how your business manages known vulnerabilities, Cyber Essentials gives you a recognised way to show that you have a process.
For organisations bidding for work, working with larger companies, or handling sensitive information, this can be valuable.
A practical readiness checklist
Before starting Cyber Essentials, ask these questions:
Do we know which devices, applications, cloud services, and firmware are in scope?
Are all in-scope operating systems supported?
Are all key applications supported?
Are routers and firewalls still supported by the vendor?
Are high-risk and critical security updates applied within 14 days?
Do we monitor whether updates have applied successfully?
Do we remove unsupported software where needed?
Do we review browser extensions and plugins?
Do we understand cloud service update responsibilities?
Do we know who owns update management?
Can our IT provider explain and evidence the process?
Are remote devices included?
Are mobile devices included?
Are update records available for assessment?
If any answer is unclear, the business should review it before submission. This will make the assessment smoother and improve security at the same time.
Keeping update management alive after certification
Cyber Essentials should not be treated as a once-a-year exercise. New vulnerabilities appear throughout the year, and updates need regular attention.
The business should keep asset records current, review unsupported software, monitor critical updates, check supplier responsibilities, and make sure staff understand the importance of timely updates.
A simple monthly review can help many smaller businesses. Larger organisations may need more formal reporting, dashboards, and escalation routes.
The key is consistency. Security update management works best when it is part of normal business operations rather than a rushed task before renewal.
Why UK Cyber Security Group is a practical place to start
UK Cyber Security Group offers Cyber Essentials certification for businesses that want an affordable route with expert support. Security update management can be challenging because it touches software, devices, firmware, cloud services, suppliers, and staff behaviour.
A guided process helps businesses understand what the assessment expects and where gaps may exist. It can also help reduce uncertainty around supported software, critical updates, remote devices, and supplier-managed systems.
For many small businesses, the aim is not to build a complex cyber security department. The aim is to put sensible controls in place, understand responsibilities, and gain certification with confidence.
UK Cyber Security Group can support that process and help organisations strengthen their cyber hygiene along the way.
Final guidance for UK businesses
Cyber Essentials security update management requirements are built around a clear idea: supported software and timely security updates reduce avoidable cyber risk.
The business should know what technology it uses, confirm that software and firmware are supported, and apply high-risk and critical security updates within 14 days of release. It should also understand who owns update management, how suppliers are involved, and how evidence can support assessment answers.
For UK organisations seeking Cyber Essentials certification, this requirement is practical and achievable with the right support. UK Cyber Security Group provides certification guidance that can help businesses prepare, address gaps, and maintain stronger cyber resilience beyond the assessment.
Security update management is not just about passing Cyber Essentials. It is about keeping known weaknesses closed, protecting business operations, and showing customers that your organisation takes cyber security seriously.
UK Cyber Security Group Ltd is here to help
Please check out our Free Cyber Insurance
If you would like to know more, do get in touch as we are happy to answer any questions. Looking to improve your cybersecurity but not sure where to start? Begin by getting certified in Cyber Essentials, the UK government’s scheme that covers all the technical controls that will provide the protection that you need to help guard against criminal attacks. Or just get in touch by clicking contact us










