Cyber Essentials: what it asks of unsupported software
Cyber Essentials asks that all software on in-scope devices is licensed and supported by the vendor, meaning it still receives security updates, and that unsupported software is removed or segregated (SU.1 and SU.4). High and critical updates go on within 14 days of release (SU.3) and automatic updates are on where the option exists (SU.2). The self-assessment questions on security update management (section A6) are named, not quoted, because we do not hold the questionnaire text.
- Scheme
- Cyber Essentials (NCSC and IASME)
- When it is placed
- Placed when you say you hold or are going for Cyber Essentials. Choose Cyber Essentials Plus and the Plus requirements attach too. Segregation is a scope decision you make: the pages say what the requirement asks and never that a device is out of scope.
- Held text
- Cyber Essentials (NCSC and IASME) on the standards site, read 30 Sep 2026
The Cyber Essentials self-assessment questions on security update management section A6 are named, not quoted: we do not hold the questionnaire text. See Cyber Essentials and unsupported software.
Findings that cite it
7 of 10- 1 Past vendor security support, still installed
- 2 Extended or paid support only
- 3 Ends before your next assessment
- 6 One product at several versions, the oldest unsupported
- 7 Not in the lifecycle record
- 9 Unsupported with no exception recorded
- 10 Evergreen product behind the current release
The clauses cited
4 clausesCyber Essentials SU.1Software Licensed and SupportedSoftware Licensed and Supported. All software on in-scope devices must be licensed and supported by the vendor (i.e. receiving security updates). Unsupported software must be removed or segregated.
Cyber Essentials SU.2Automatic Updates Enabled Where PossibleAutomatic Updates Enabled Where Possible. Automatic updates must be enabled on devices and software where the option exists, to ensure security updates are applied without delay.
Cyber Essentials SU.3Critical and High Updates within 14 DaysCritical and High Updates within 14 Days. All high or critical security updates (CVSS 7.0+ or vendor critical/high rating) must be applied within 14 days of release.
Cyber Essentials SU.4Remove Out-of-Support SoftwareRemove Out-of-Support Software. Remove software that is no longer receiving security updates from in-scope devices, or fully segregate it from the rest of the network.