What the rule actually says, when the clock starts, what falls in scope, and how to meet it without an audit-week scramble.
Patch management is one of the five technical controls at the heart of Cyber Essentials, and it is the one that trips up the most organisations. The requirement is often summarised as "the 14-day rule", but the detail matters: what counts, when the clock starts, and what happens if you miss it all changed for the stricter in the April 2026 update. This guide sets out the rule in plain terms for UK IT teams and service providers.
Cyber Essentials requires that high-risk and critical security updates are applied within 14 days of a fix being released. In the self-assessment this is captured by the patch-management questions (A6.4 and A6.5), which ask whether critical and high-risk updates are applied within 14 days to operating systems and firmware, and to all software respectively. A "No" to either is enough to fail the whole assessment.
An update falls inside the 14-day window if any of the following is true:
That last point catches a lot of people out. If a vendor ships a security fix with no severity attached, the safe assumption is that it is in scope. Updates rated "low" or "medium" by the vendor and scoring below 7.0 are not caught by the 14-day deadline, though you should still apply them in good time.
The clock starts on the vendor's release date - the day the patch becomes publicly available - not the day you learn about it, and not the day it lands in your management console. If a fix was released ten days ago and you only just imported it into Configuration Manager, you already have four days left, not fourteen.
This is why "we patch monthly on the second Tuesday" is no longer a defensible policy on its own. A vulnerability disclosed the day after your patch window can sit unremediated for nearly a month - well outside the 14 days - unless you have an out-of-band process for high and critical fixes.
The requirement applies across the whole assessment boundary:
Third-party applications are frequently the weak spot. Everyone patches Windows; far fewer have an equally reliable process for the dozens of non-Microsoft products that make up a real estate, each with its own release cadence.
Meeting the 14-day rule on paper is simple. Proving it continuously, across every device and every application, is where the effort lives:
Note: This guide is a practical summary, not a substitute for the official Cyber Essentials Requirements for IT Infrastructure published by IASME and the NCSC. Always check the current version of the requirements for the definitive wording that applies to your assessment.
Fourteen days from the vendor releasing the fix, for any update that is high-risk or critical.
No. It starts on the vendor's public release date, regardless of when you become aware of it or when it reaches your patching tool.
Treat it as in scope and apply it within 14 days. Unrated security updates are caught by the rule.
Since the April 2026 update, an in-scope update left unpatched beyond 14 days is an automatic failure - the earlier tolerance for a couple of patching gaps has been removed.
APaaS Assure maps every application to live vulnerabilities, holds each to the 14-day clock, and deploys the fix to Intune or Configuration Manager - so compliance is continuous, not a scramble.
Book a demo