
Patch discipline is the invisible backbone of every UK SME that passes Cyber Essentials on the first attempt and renews a cyber insurance policy without hard questions. In 2026 the bar moved. Cyber Essentials v3.3, published by NCSC in April, tightened the fix window for high-severity vulnerabilities from 14 days to five working days. Businesses running informal, best-effort patching are now failing certification and paying more for insurance.
This guide walks a UK SME through what a real managed patching cadence looks like in 2026: the v3.3 five-day rule and its practical implications, the three patch categories every SME handles differently, a week-in-the-life of managed patching, the evidence cyber insurers now expect at renewal, and the common failures that show up in Cyber Essentials pre-assessments.
What changed in Cyber Essentials v3.3
The headline change is speed. High-severity vulnerabilities (CVSS 7.0 and above) now need to be fixed within five working days of vendor release. Critical vulnerabilities (CVSS 9.0 and above) follow the same window. The old 14-day window that many UK SMEs treated as a monthly patch cycle no longer meets the standard.
The rule applies across all in-scope devices, cloud services and on-premise infrastructure. There is no informal exception for “we usually patch on the second Tuesday”. An assessor asking to see evidence expects a dated log, not a verbal reassurance.
The three patch categories every UK SME handles differently
Not all patches move at the same speed or carry the same risk. A working managed patching operation splits them into three streams with different cadences and different testing depth.
- Operating system patches (Windows, macOS, Windows Server, Linux). his is the highest-volume and most predictable patching cycle. Microsoft Patch Tuesday runs monthly, while macOS releases typically follow a quarterly pattern. Therefore, test updates in a pilot ring first before deploying them in waves.
- Application patches (browsers, PDF readers, VPN clients, Teams, Zoom, Adobe, Java). Highest exploit velocity. Attackers move fastest against browser and PDF vulnerabilities. Aim for pilot-to-full-deployment inside two working days.
- Firmware and infrastructure (routers, switches, firewalls, printers, wireless access points, phone systems). Although this category has the lowest volume, it has the highest missed cadence. As a result, UK SMEs routinely fall behind because nobody takes ownership of the review.
A real week-in-the-life of managed patching
What does five-day compliance look like week to week? Roughly this cadence, adapted to fit the vendor release calendar.
- Monday: vulnerability intelligence. Review NCSC advisories and CVE announcements from the weekend. Score new items against the five-day window. Log any pending exceptions.
- Tuesday: patch review and test. Microsoft Patch Tuesday releases land. Test the rollup in a staging environment or a low-risk pilot device group.
- Wednesday: pilot ring deployment. Deploy to 5 to 10% of endpoints (IT users, willing volunteers). Monitor for issues.
- Thursday: broader deployment. Extend to 25 to 50% of endpoints once the pilot ring is clean. Log any compatibility issues for the exception process.
- Friday: full estate. Complete deployment to remaining endpoints. Run the compliance report. Flag any device that failed to receive the patch for helpdesk follow-up.
- Weekly outputs: compliance percentage per device class, exception log with dated justification, next-week schedule shared with the client contact.
Why 14-day patching is no longer enough
The five-day window is not arbitrary. Real-world exploit-to-active-attack timelines have compressed hard. In 2022, the average time from vulnerability disclosure to observed exploitation was around 14 days. In 2026, NCSC and vendor threat intelligence consistently show it at three to five days for anything ransomware operators find profitable.
Previously, the 14-day window worked because threat actors were slower than defenders. However, that gap has now closed. Ransomware crews now monitor Patch Tuesday feeds and prioritise unpatched estates within hours of vendor announcements. NCSC has been signalling this direction in its patch-wave guidance for two years, and v3.3 catches the standard up with the reality.
The evidence pack UK cyber insurers now expect
Insurance renewal in 2026 is a documentation exercise. Underwriters have moved from broad-scope policies to asking for specific evidence of controls. Patching sits near the top of that list.
- Monthly patch compliance report. Per device class, showing percentage compliance and time-to-patch metrics for the previous quarter.
- Exception log. Any device or system where a patch was deferred, with dated justification and a target remediation date. Ideally under 5% of the estate at any given time.
- Emergency patch playbook. Documented process for out-of-band vulnerabilities (the next Log4j, PrintNightmare, or ProxyShell). Underwriters know these events happen. They want the plan.
- Firmware update cadence. Router, switch, firewall and Wi-Fi access point patching is often the missing piece in an otherwise tidy patch programme.
- Backup restore test evidence. In addition, backup testing sits alongside patching and is often included in the same insurance review. A tested restore also proves that the recovery path works if a patch introduces a regression.
Common patching mistakes UK SMEs make
- Waiting for a “convenient time” to patch. In a small business this means the patches never land, because there is never a convenient time.
- Self-managed WSUS with no reporting layer. However, WSUS deploys patches without automatically showing compliance rates unless you use additional tooling. As a result, assessors see the actual compliance figure rather than the intention behind the process.
- No pilot ring.Rather than deploying patches to everyone at once, roll them out in phases. As a result, you can reduce the risk of large-scale failures that delay the next month’s patch cycle.
- Ignoring firmware on network kit. The last three years of high-profile breaches point heavily at unpatched routers, firewalls and VPN concentrators.
- Trusting auto-update on BYOD. Similarly, personal devices that access company data need managed configuration if you want a reliable patching process. Otherwise, relying on automatic updates is more of an assumption than evidence.
- No exception approval process. Every patch programme has legitimate exceptions. What matters is that they are documented, dated and time-limited, not verbal.
How to measure whether your patch programme is working
Although cyber insurers and Cyber Essentials assessors often focus on the headline compliance percentage, it only tells part of the story. Instead, three underlying metrics provide a much clearer indication of whether the programme is truly healthy.
- Time-to-patch on critical vulnerabilities. Median hours from vendor release to full estate deployment for CVSS 9.0+ issues. Target: under 24 hours for cloud-managed endpoints, under 72 hours for full estate.
- Compliance percentage per device class. Split reporting into servers, workstations, mobile devices and network kit. The average hides where the gaps sit.
- Exception log velocity. Another important metric is how quickly logged exceptions are closed. For example, if an exception remains open for more than 30 days without justification, it can become a red flag on an assessor’s checklist.
A working monthly report contains all three, plus a 12-month trend line. Underwriters and CE assessors read the trend as heavily as the current number.
Emergency patching: the out-of-band playbook
Regular monthly cadence handles most vulnerabilities. However, a working patch programme stands apart from a paper one because it can respond within hours, not days, when an out-of-band vulnerability appears.
Log4j in December 2021, PrintNightmare in June 2021 and ProxyShell in August 2021 all needed action inside 48 hours. Two more of that scale hit through 2025 and 2026. The pattern will continue.
A working emergency-patch playbook covers: named person on rota, NCSC and vendor advisory subscriptions monitored, standing authority to deploy without change board approval for critical CVEs, a communications template to send to leadership within four hours of vendor disclosure, and a post-event review to catch what missed.
Where patch discipline connects to the rest of your security stack
Patching does not sit in isolation. In a well-run UK SME security posture in 2026, it connects to three adjacent controls.
- Cyber Essentials v3.3. Five-day critical patch window is one of the five control areas. A working patch cadence is the fastest route to certification.
- Cyber insurance renewal. Patch compliance evidence is now standard on renewal questionnaires. See the cyber insurance renewal 2026 piece for the full evidence stack.
- Endpoint detection and response. EDR catches what patches missed. But EDR is not a substitute for patching as both matter and our beyond antivirus piece covers where each fits.
Talk to us about your patching cadence
Finally, if you would like a second pair of eyes on your current patching setup before your next Cyber Essentials assessment or cyber insurance renewal, get in touch. We can review what your existing cadence covers, identify any gaps and explain what a practical five-day patching window could look like for your team.
