Unsupported Software Findernotice of vendor support
Cyber Essentials

Cyber Essentials and unsupported software

What the Cyber Essentials requirements say about unsupported software, how the self-assessment asks about it, what segregated means, and a paste box that shows which lines of your inventory the requirement is about.

What the requirement says
All software on in-scope devices must be licensed and supported by the vendor, meaning it still receives security updates; unsupported software must be removed or segregated (SU.1, SU.4). High and critical updates go on within 14 days of release (SU.3), with automatic updates on where the option exists (SU.2).
The self-assessment questions
The Cyber Essentials self-assessment questions on security update management section A6 ask about licensed and supported software, removal of unsupported software and the 14-day window. They are named, not quoted: we do not hold the questionnaire text.
What counts as segregated
A sub-set of devices kept apart from the rest by a boundary (a firewall or a separate network segment) and excluded from the scope of the assessment. Whether to segregate, and where the boundary sits, is your scope decision; the requirements document, Cyber Essentials: Requirements for IT infrastructure NCSC, is named, not quoted. The finder never says a device is out of scope.
Cyber Essentials Plus
Keeps every requirement above and adds the assessor-run checks; PM-02 asks that unsupported software and operating systems are removed from in-scope devices or isolated with compensating controls.

Check your inventory against it

Paste the export on the finder with the first line cyber essentials: yes (or cyber essentials: plus). Every line past vendor support comes back with SU.1 and SU.4 beside it, every line on extended support only as a question about whether that support delivers security fixes, and every browser behind its current release with the 14-day window.

Cyber Essentials SU.1Software Licensed and Supported

Software Licensed and Supported. All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated.

What an assessor asks to see: SCCM/Intune software inventory; EOL/EOSL register; Segregation evidence for unsupported
Where software lists usually fall short: Windows 7/Server 2012 still in use; EOL Java runtimes
Source: Cyber Essentials (NCSC and IASME), read 30 Sep 2026
Cyber Essentials SU.4Remove Out-of-Support Software

Remove Out-of-Support Software. Remove software that is no longer receiving security updates from in-scope devices, or fully segregate it from the rest of the network.

What an assessor asks to see: EOL removal log; Segregated VLAN evidence; Compensating control documentation
Where software lists usually fall short: EOL kept on production network; No plan to retire
Source: Cyber Essentials (NCSC and IASME), read 30 Sep 2026
Cyber Essentials SU.3Critical and High Updates within 14 Days

Critical and High Updates within 14 Days. All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release.

What an assessor asks to see: Patch compliance dashboard (Defender/Tenable/Qualys); 14-day SLA report; Exception register
Where software lists usually fall short: Patch backlog beyond 14 days; No CVSS-based tracking
Source: Cyber Essentials (NCSC and IASME), read 30 Sep 2026
Cyber Essentials Plus PM-02Unsupported Software Removal

Unsupported Software Removal. Software and operating systems that are no longer supported by the vendor must be removed from in scope devices or isolated with compensating controls.

What an assessor asks to see: Software inventory with vendor support status; EOL remediation plan; Isolation network diagrams
Where software lists usually fall short: Windows 7 or unsupported Server still in scope; EOL Java runtimes on user devices; No inventory accuracy check
Source: Cyber Essentials Plus (NCSC and IASME), read 30 Sep 2026

See the specimen list runCheck your own list