Skip to content

Patch operating systems

Keeping Windows, macOS, Linux and your server operating systems up to date.

The case for it

What you lose without operating system patching.

Same reason as application patching, except that everything else depends on the operating system. Leave it unpatched and every application on top of it inherits the vulnerability. Losing the operating system is rarely just a bad day.

Where you need to be

What each maturity level asks of operating system patching.

The Australian Cyber Security Centre (ACSC) sets a requirement for this control at each maturity level, ML1 through ML3. Your overall Essential Eight score is your weakest control rather than an average, so a gap here pulls the whole score down.

ML1 The 2026 baseline

Operating system vendor patches are applied to internet-facing services within 2 weeks (48 hours if an exploit exists). Workstation, server and network-device OSs are patched within 1 month.

ML2 Regulated or audited

OS patches for internet-facing services with known exploits are applied within 48 hours. Workstations and servers are patched within 2 weeks. End-of-life operating systems are replaced.

ML3 Defence or sensitive

All OS patches applied within 48 hours of release when an exploit exists. The latest release (not just the latest patched version of an older release) is used for internet-facing services.

Not sure which level you should aim for?

Three questions about your regulatory position and the data you keep will point you at the right target.

Take the maturity picker

The rollout

Setting up operating system patching in your environment.

Operating system patching follows a managed schedule: Intune for Windows, equivalent tooling for macOS and Linux. Internet-facing services are patched within 48 hours when an exploit is known. Workstations and servers follow a two-week rhythm for routine patches, with out-of-band patching when something critical arrives between cycles. Operating systems past end of life are replaced, not kept alive with workarounds.

Free self-assessment

No email required.

Score yourself on all eight controls.

Eight questions, your estimated Essential Eight maturity level, and a branded PDF report you can share with your board, insurer, broker or auditor. Runs entirely in your browser. Nothing is sent to us unless you choose to book a call.

Take the self-assessment

Asked on client calls

Questions we get about operating system patching.

We have a Windows 10 machine our staff like. What happens at end-of-life?
What about our old server running a critical app?
Does patching break things?

The maturity level summaries on this page are a plain-English version of the ACSC's published Essential Eight Maturity Model. For the full text, see the ACSC Essential Eight Maturity Model .

The qualifier

Let's see if we're a fit.

Seven questions, one moment of your time. We'd rather tell you now than three months in.

Step 1 of 7

How big is your team?

Counting everyone: staff, contractors, anyone with an account.

See if we're a fit