Cyber Essentials and unsupported software
What the Cyber Essentials requirements say about unsupported software, how the self-assessment asks about it, what segregated means, and a paste box that shows which lines of your inventory the requirement is about.
- What the requirement says
- All software on in-scope devices must be licensed and supported by the vendor, meaning it still receives security updates; unsupported software must be removed or segregated (SU.1, SU.4). High and critical updates go on within 14 days of release (SU.3), with automatic updates on where the option exists (SU.2).
- The self-assessment questions
- The Cyber Essentials self-assessment questions on security update management section A6 ask about licensed and supported software, removal of unsupported software and the 14-day window. They are named, not quoted: we do not hold the questionnaire text.
- What counts as segregated
- A sub-set of devices kept apart from the rest by a boundary (a firewall or a separate network segment) and excluded from the scope of the assessment. Whether to segregate, and where the boundary sits, is your scope decision; the requirements document, Cyber Essentials: Requirements for IT infrastructure NCSC, is named, not quoted. The finder never says a device is out of scope.
- Cyber Essentials Plus
- Keeps every requirement above and adds the assessor-run checks; PM-02 asks that unsupported software and operating systems are removed from in-scope devices or isolated with compensating controls.
Check your inventory against it
Paste the export on the finder with the first line cyber essentials: yes (or cyber essentials: plus). Every line past vendor support comes back with SU.1 and SU.4 beside it, every line on extended support only as a question about whether that support delivers security fixes, and every browser behind its current release with the 14-day window.
Cyber Essentials SU.1Software Licensed and SupportedSoftware Licensed and Supported. All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated.
Cyber Essentials SU.4Remove Out-of-Support SoftwareRemove Out-of-Support Software. Remove software that is no longer receiving security updates from in-scope devices, or fully segregate it from the rest of the network.
Cyber Essentials SU.3Critical and High Updates within 14 DaysCritical and High Updates within 14 Days. All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release.
Cyber Essentials Plus PM-02Unsupported Software RemovalUnsupported Software Removal. Software and operating systems that are no longer supported by the vendor must be removed from in scope devices or isolated with compensating controls.