Cyber Essentials Plus: what it asks of unsupported software
Cyber Essentials Plus keeps every Cyber Essentials requirement and adds the assessor-run checks. PM-02 asks that software and operating systems no longer supported by the vendor are removed from in-scope devices or isolated with compensating controls; PM-01 carries the 14-day window for high and critical updates.
- Scheme
- Cyber Essentials Plus (NCSC and IASME)
- When it is placed
- Placed when you choose Cyber Essentials Plus. It keeps the Cyber Essentials requirements and adds the assessor-run checks.
- Held text
- Cyber Essentials Plus (NCSC and IASME) on the standards site, read 30 Sep 2026
Findings that cite it
4 of 10- 1 Past vendor security support, still installed
- 2 Extended or paid support only
- 9 Unsupported with no exception recorded
- 10 Evergreen product behind the current release
The clauses cited
2 clausesCyber Essentials Plus PM-01High and Critical Vulnerability PatchingHigh and Critical Vulnerability Patching. Security updates rated high or critical must be applied within 14 days of release for operating systems and supported applications, or vulnerable software removed.
What an assessor asks to see: Patch deployment reports; Internal authenticated scan results; Exception register with risk owner sign off
Where software lists usually fall short: Scan shows 14+ day breaches; No scan of servers; Patches deferred without documented risk acceptance
Source: Cyber Essentials Plus (NCSC and IASME), read 30 Sep 2026
Cyber Essentials Plus PM-02Unsupported Software RemovalUnsupported Software Removal. Software and operating systems that are no longer supported by the vendor must be removed from in scope devices or isolated with compensating controls.
What an assessor asks to see: Software inventory with vendor support status; EOL remediation plan; Isolation network diagrams
Where software lists usually fall short: Windows 7 or unsupported Server still in scope; EOL Java runtimes on user devices; No inventory accuracy check
Source: Cyber Essentials Plus (NCSC and IASME), read 30 Sep 2026