Unsupported Software Findernotice of vendor support

Cyber Essentials Plus: what it asks of unsupported software

Cyber Essentials Plus keeps every Cyber Essentials requirement and adds the assessor-run checks. PM-02 asks that software and operating systems no longer supported by the vendor are removed from in-scope devices or isolated with compensating controls; PM-01 carries the 14-day window for high and critical updates.

Scheme
Cyber Essentials Plus (NCSC and IASME)
When it is placed
Placed when you choose Cyber Essentials Plus. It keeps the Cyber Essentials requirements and adds the assessor-run checks.
Held text
Cyber Essentials Plus (NCSC and IASME) on the standards site, read 30 Sep 2026

Findings that cite it

4 of 10

The clauses cited

2 clauses
Cyber Essentials Plus PM-01High and Critical Vulnerability Patching

High and Critical Vulnerability Patching. Security updates rated high or critical must be applied within 14 days of release for operating systems and supported applications, or vulnerable software removed.

What an assessor asks to see: Patch deployment reports; Internal authenticated scan results; Exception register with risk owner sign off
Where software lists usually fall short: Scan shows 14+ day breaches; No scan of servers; Patches deferred without documented risk acceptance
Source: Cyber Essentials Plus (NCSC and IASME), read 30 Sep 2026
Cyber Essentials Plus PM-02Unsupported Software Removal

Unsupported Software Removal. Software and operating systems that are no longer supported by the vendor must be removed from in scope devices or isolated with compensating controls.

What an assessor asks to see: Software inventory with vendor support status; EOL remediation plan; Isolation network diagrams
Where software lists usually fall short: Windows 7 or unsupported Server still in scope; EOL Java runtimes on user devices; No inventory accuracy check
Source: Cyber Essentials Plus (NCSC and IASME), read 30 Sep 2026

See the specimen list runCheck your own list