Skip to content
Technical Guides

Cyber Essentials and patch management (WSUS, Intune, third-party)

How to evidence Cyber Essentials v3.3 patching - 14-day SLA for high/critical CVEs, WSUS deployment patterns, Intune Update Rings, third-party patching (Action1, PDQ, NinjaOne), and the audit artefacts assessors want.

Software updater with refresh arrows icon and

Author

Jay Hopkins

Editor

Edited by Jack Wickham

Published

Last reviewed

Read time

7 min read

Share

Section 01

Cyber Essentials and patch management (WSUS, Intune, third-party)

Cyber Essentials v3.3 requires that required vulnerability fixes in operating systems, applications and firmware are applied within fourteen days of release when the vendor rates them high/critical, CVSS v3 is 7+ or vendor severity details are absent. Evidence of this is one of the most-sampled areas of the assessment - assessors will ask you to name a recent high-severity CVE, show when Microsoft / Apple / Google / Adobe released the patch, and prove your environment applied it within the window. The commonest failure is not missing the patch - it's not being able to prove it, because the tooling doesn't expose a clean "deployed date per device per CVE" report.

Section 02

1. What Cyber Essentials actually requires

  • Licensed supported software. Check exact version/edition, future vendor support end date and active qualifying extended-support entitlement. A blanket OS-family list can miss supported editions, Windows ESU or other paid lifecycle coverage.
  • Automatic updates enabled where possible. The scheme actively prefers automatic updates over manual patching.
  • Fourteen-day window for independent vendor high/critical, CVSS v3 7+ and absent-severity triggers. Vendor-approved configuration fixes can qualify; generic risk acceptance does not waive the requirement.
  • Firmware updates when released by vendors - this is newer emphasis in v3.3 and catches many estates out (BIOS, router firmware, NAS firmware).
  • Third-party applications - browsers, PDF readers, runtimes (Java, .NET), design tools. Not just the OS.

Section 03

2. WSUS - still viable, specific risks

Windows Server Update Services (WSUS) works for Cyber Essentials if disciplined:

  • Auto-approve Critical and Security Updates for the Windows classifications you care about
  • Computer groups by environment (production, test) with staged rollout: test → pilot → all
  • Target release cadence: approve on Patch Tuesday, deployed to pilot by Wednesday, all machines by next Monday - inside the 14-day window
  • Do not dismiss feature updates indefinitely; schedule them at least annually so devices don't fall off supported Windows versions
  • Dashboard: WSUS console + periodic export, or better, pipe data to a reporting layer (SCCM, Nexthink, or a scripted PowerShell export)

Known risks with WSUS:

  • Orphaned clients that stopped checking in weeks ago still show green in the console; compare WSUS inventory against AD last-logon
  • Third-party apps (Chrome, Firefox, Adobe Reader) are not covered by WSUS. Use effective native auto-updates or another managed deployment method for these; a separate paid tool is not compulsory.

Section 04

3. Intune / Windows Autopatch

For cloud-native Windows management, Intune Update Rings and Windows Autopatch can support deployment and evidence. Check current Microsoft licensing and the products covered before selecting this route; the scheme does not mandate an E3 licence.

Illustrative update-ring planning, not mandatory scheme settings:

  • Pilot ring (5% of devices): 0-day deferral, 0-day quality deferral
  • Broad ring (95%): 0-day feature deferral deferred, 2-day quality update deferral
  • Deadlines: 7 days for quality updates, reset via grace period

Windows Autopatch automates Microsoft 365 Apps, Edge, Teams, and Windows quality updates with a rolling ring structure. Inbuilt reporting gives you "patch status per device per month" which assessors accept as strong evidence.

Driver and Firmware updates now deploy via Intune for most Dell, HP, Lenovo, and Surface devices with the right policy payload - this covers the firmware clause.

Section 05

4. Third-party patching tools

WSUS and Intune don't patch most third-party apps. The cleanest options for UK SMEs:

  • Action1 - one example of an endpoint patching product; verify current coverage, licence and any free-tier limit
  • PDQ Deploy / Inventory - LAN-based, low cost
  • NinjaOne - RMM-class, covers Windows + Mac + third-party
  • Datto RMM / N-able N-central - MSP-grade RMMs with the same coverage
  • winget via scripted deployments - free but needs someone to own it

Cover all applicable installed software, not a mandatory top-ten quota. Prepare reliable update/version evidence appropriate to your estate. A per-device per-CVE console history is useful but is not the only accepted basic-certification evidence format.

Section 06

5. Firmware - the newer v3.3 focus

Cyber Essentials v3.3 explicitly calls out firmware. Most gaps here:

  • Laptop BIOS / UEFI - Dell Command | Update, HP Image Assistant, Lenovo System Update, Surface firmware via Intune. A monthly inventory review is optional operational practice; any qualifying vulnerability fix still needs deployment inside fourteen days.
  • Routers / firewalls - most UK SMEs run consumer-grade kit with stale firmware. Review vendor advisories and apply qualifying fixes within fourteen days. Quarterly refreshes or automatic management do not excuse overdue fixes. Ordinary private home routers are excluded; organisation-supplied routers are included.
  • NAS / storage - Synology / QNAP / TrueNAS often lag. Subscribe to vendor security bulletins.
  • Printers - surprisingly common attack surface. Quarterly firmware check.

Section 07

6. macOS and Linux patching

macOS: Managed Software Update via MDM (see Cyber Essentials for Jamf / Kandji / Intune).

Linux: unattended-upgrades on Debian/Ubuntu, dnf-automatic on RHEL/Fedora, with restarts or supported livepatch where needed to make the fix effective within the required window. A weekly restart is not a universal scheme prescription. Bonus: livepatch on Ubuntu Pro reduces reboot requirement on critical kernel CVEs.

Section 08

7. Evidence assessors expect

  • Patch tool screenshot or export showing patch level per device
  • Sample recent CVE: "Microsoft CVE-2026-xxxxx released 9 April, deployed across our estate by 18 April - here's the report"
  • Supported-OS inventory with no end-of-support OS present
  • Firmware cadence evidence - at minimum a policy document plus vendor update logs
  • Third-party coverage - list of business-critical apps with patch status

Section 09

8. Common failure points

1. "We don't track patches per CVE." Assessors sample specific CVEs; prepare reliable evidence of timely deployment. A particular console or per-CVE report format is not universally compulsory for basic certification.

2. End-of-support devices in scope. Check active qualifying Windows 10 ESU where applicable. Unsupported software must be removed from in-scope devices or excluded through a defined subset preventing all traffic to or from the internet; generic compensating controls do not suffice.

3. Third-party apps ignored. Chrome, Edge, Zoom, Adobe Reader are the usual offenders. A third-party patching tool solves this.

4. Firmware never updated. Router last updated 2022. Plan a firmware refresh before assessment.

5. One device a "special case" that doesn't get patched. Either remove from scope, isolate it, or get it on the patching program - exceptions fail the control.

Section 10

What Fig Group checks

Fig Group reviews update coverage and the evidence supporting your submission. Useful records include vendor release dates, deployed versions, lifecycle entitlement and coverage of applications and firmware. Use reports available from your tools; do not share live secrets or assume every CSV format can be imported automatically.

Start Cyber Essentials - from £299.99 + VAT | Pricing tiers | CE Plus with vulnerability scan

About the author

Jay Hopkins

Jay Hopkins

Managing Director, Fig Group

IASME-licensed Cyber Essentials AssessorIASME Cyber Assurance Assessor

Jay Hopkins is the Managing Director of Fig Group and an IASME-licensed Cyber Essentials assessor. He was previously Head of Technology for a global regulated firm. He works with UK organisations across regulated sectors on baseline compliance, supply-chain assurance, and AI-augmented security tooling.

Next step

Want to see how Fig Group handles this?

Discover how Fig Group helps organisations prepare for security assessments and maintain ongoing compliance.

Request a demo

Related solutions

Continue exploring Fig Group