Skip to content

Patch applications

Keeping your software up to date so it has the latest security fixes.

The case for it

What you lose without application patching.

Most cyberattacks exploit known vulnerabilities in software. The patches have usually been available for months. The attackers aren't clever; the defenders are slow. Patching your applications quickly removes the easiest way into your business.

Where you need to be

What each maturity level asks of application patching.

The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.

ML1 The 2026 baseline

Internet-facing services are patched for critical vulnerabilities within 2 weeks (or 48 hours if an exploit exists). Office productivity suites, web browsers, email clients, PDF software, and security products are patched within 1 month.

ML2 Regulated or audited

Patches for internet-facing services with known exploits are applied within 48 hours. Office productivity suites and similar are patched within 2 weeks.

ML3 Defence or sensitive

All software patches are applied within 48 hours of release when an exploit exists. Applications no longer supported by vendors are removed.

Not sure which level you should aim for?

Three questions about your regulatory position and the data you keep will point you at the right target.

Take the maturity picker

The rollout

Setting up application patching in your environment.

Patching follows a schedule you agree with us, inside your Maintenance Window. Internet-facing services are patched within 48 hours when an exploit is known in the wild. Browsers and office software follow a monthly cycle, measured against the ACSC minimums. A patch that breaks something is rolled back automatically and investigated the same day. Nothing vulnerable stays running while someone reviews it.

Free self-assessment

No email required.

Score yourself on all eight controls.

Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.

Take the self-assessment

Asked on client calls

Questions we get about application patching.

What's the difference between this and OS patching?
What about line-of-business software that can't be patched?
Will my staff get constant reboot prompts?
How do you know what's installed on every device?

The maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit