Unsupported Software Findernotice of vendor support

Cyber Essentials: what it asks of unsupported software

Cyber Essentials asks that all software on in-scope devices is licensed and supported by the vendor, meaning it still receives security updates, and that unsupported software is removed or segregated (SU.1 and SU.4). High and critical updates go on within 14 days of release (SU.3) and automatic updates are on where the option exists (SU.2). The self-assessment questions on security update management (section A6) are named, not quoted, because we do not hold the questionnaire text.

Scheme
Cyber Essentials (NCSC and IASME)
When it is placed
Placed when you say you hold or are going for Cyber Essentials. Choose Cyber Essentials Plus and the Plus requirements attach too. Segregation is a scope decision you make: the pages say what the requirement asks and never that a device is out of scope.
Held text
Cyber Essentials (NCSC and IASME) on the standards site, read 30 Sep 2026

The Cyber Essentials self-assessment questions on security update management section A6 are named, not quoted: we do not hold the questionnaire text. See Cyber Essentials and unsupported software.

Findings that cite it

7 of 10

The clauses cited

4 clauses
Cyber Essentials SU.1Software Licensed and Supported

Software Licensed and Supported. All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated.

What an assessor asks to see: SCCM/Intune software inventory; EOL/EOSL register; Segregation evidence for unsupported
Where software lists usually fall short: Windows 7/Server 2012 still in use; EOL Java runtimes
Source: Cyber Essentials (NCSC and IASME), read 30 Sep 2026
Cyber Essentials SU.2Automatic Updates Enabled Where Possible

Automatic Updates Enabled Where Possible. Automatic updates must be enabled on devices and software where the option exists, to ensure security updates are applied without delay.

What an assessor asks to see: Windows Update for Business policy; MacOS auto-update screenshot; WSUS/Intune config
Where software lists usually fall short: Auto-update deferred indefinitely; Users can opt out
Source: Cyber Essentials (NCSC and IASME), read 30 Sep 2026
Cyber Essentials SU.3Critical and High Updates within 14 Days

Critical and High Updates within 14 Days. All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release.

What an assessor asks to see: Patch compliance dashboard (Defender/Tenable/Qualys); 14-day SLA report; Exception register
Where software lists usually fall short: Patch backlog beyond 14 days; No CVSS-based tracking
Source: Cyber Essentials (NCSC and IASME), read 30 Sep 2026
Cyber Essentials SU.4Remove Out-of-Support Software

Remove Out-of-Support Software. Remove software that is no longer receiving security updates from in-scope devices, or fully segregate it from the rest of the network.

What an assessor asks to see: EOL removal log; Segregated VLAN evidence; Compensating control documentation
Where software lists usually fall short: EOL kept on production network; No plan to retire
Source: Cyber Essentials (NCSC and IASME), read 30 Sep 2026

See the specimen list runCheck your own list