Unsupported Software Findernotice of vendor support
For whoever answers the assessor's question about unsupported software

Paste your software inventory. See what the vendor no longer supports.

Unsupported Software Finder reads your software inventory line by line and finds every product and version past its vendor's end of support, and every one ending before your next assessment. Paste your software inventory export, one line per product and version. Every line comes back with its vendor support status, the end date and where that date comes from, and every unsupported item with the clause that fails on it: Cyber Essentials, Essential Eight, CIS 2.2, PCI DSS 12.3.4 and NIST SA-22. Nothing is installed and nothing touches your network.

Check your own listEight lines free, no account.
  1. Paste or drop your inventory export. It is read in your browser: nothing is installed, nothing scans your network, and nothing leaves your browser until you save.
  2. Product name and version per line is enough. Install count, device group and owner are optional. Export it from your endpoint management or asset tool as it is; the column names are recognised.
  3. Every support date shows its source and the date we last read it. A version the record does not list is unknown, never supported.
  4. It never says whether the estate meets an assessment. Every finding names the clause and says what the clause asks.
Specimen, 4 of 42 linesan invented regional manufacturer
Microsoft Windows 10 Enterprise 21H2 10.0.19044.3086
past vendor support
security support ended 11 Jun 2024; 6 installs
Windows Server 2012 R2 Standard 6.3.9600
extended support only
security support ended 10 Oct 2023; extended support to 13 Oct 2026; 3 installs
Microsoft Office LTSC Professional Plus 2021 16.0.14332.20763
ends within window
security support ends 13 Oct 2026; 41 installs
Google Chrome 138.0.7204.184
behind current release
release 138, the current release is 154; 120 installs

42 products, 22 past vendor support on 188 devices, 6 ending before the next assessment.

10 of 10 findings raised, 39 of 42 lines placed on a version in the record, 3 not in the record and counted apart.

An engineer in a pink shirt typing on a laptop in a server room aisle
Walk into the Cyber Essentials renewal, the Essential Eight review or the annual technology review with every end-of-support date already sourced, dated and tied to the clause it meets. It works from the export your endpoint tool already produces, in your browser, with nothing installed on a single device.
01

Paste the export as it comes

One product and version per row: product | version at least, or a header row with any of publisher, install count, device group, owner and exception. The column names endpoint, asset and remote management exports carry are read as they are.

02

Read the notice line by line

Each line is matched to the vendor's lifecycle record and cycle, and set against the as-at date: past vendor support, extended support only, ending before your assessment, ending within the window, or supported. The strip on every row draws its dates.

03

Take the clause to the assessment

Ten findings in a fixed order, each naming its lines and the clause from Cyber Essentials, the Essential Eight, CIS Controls v8, PCI DSS, NIST SP 800-53 or ISO/IEC 27001 you ticked. The upgrade plan and the assessor summary are where the answers go.

One product per row: Product | Version, or a header row with any of Publisher, Install Count, Device group, Owner, Exception. Tabs, pipes, commas or double spaces. First lines such as next assessment: 2027-03-31 or essential eight: ML2 set the options below.
Nothing is sent anywhere until you choose to save.
What you tell it (first lines of a paste set these too); nothing else is assumed

Why a pasted list, and not a scan

The question the assessor asks first is not about packets. It is: which software do you run, at which version, is the vendor still sending security updates for it, and if not, what have you done about it. The answer sits in the software inventory your endpoint or asset tool already exports. That is what this reads, in your browser, line by line, against the vendor lifecycle record, with the date that record was read.

The record and the rules are published in full: end of life dates for every product in the record, the whole end of life software list, what each scheme asks, what Cyber Essentials says about unsupported software, the software inventory template and where the dates come from. It reads the list only; a finding names the clause and says what it asks, never a ruling on a device.