Nano Solutions

Patch applications

Patch applications is the Essential Eight mitigation strategy requiring organisations to find and remediate vulnerabilities in application software within defined timeframes, and to remove applications no longer supported by their vendor. Online services carry the shortest timeframe: 48 hours where a vulnerability is critical or a working exploit exists.

Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).

On this page 4 sections
  1. The timeframes, by asset
  2. Removing what cannot be patched
  3. What changed in November 2023
  4. Why hosted software has the shortest timeframe

Patch applications at a glance

What each maturity level requires

Requirements are cumulative: Level Three means everything in Levels One and Two as well. Each level links to that requirement on the matrix.

  1. ML1 Maturity Level One

    Patch applications, Maturity Level One: Patch online services — critical, or a working exploit exists (ISM-1876)
  2. ML2 Maturity Level Two

    Patch applications, Maturity Level Two: Patch all other applications
  3. ML3 Maturity Level Three

    Patch applications, Maturity Level Three: Patch office suites, browsers, email clients, PDF and security products — critical or exploited
New requirements start here Carries the level below Score yourself with the self-assessment, or look a term up in the glossary.

Application patching uses different timeframes for different assets and vulnerabilities. Online services enter the 48-hour tier from Maturity Level One.

The timeframes, by asset

The Essential Eight does not have one application-patching window. The applicable timeframe depends on the asset, the vulnerability and, for some software, the maturity level.

Asset Critical, or working exploit Otherwise From
Online services 48 hours Two weeks Level One
Office suites, browsers and extensions, email clients, PDF software, security products Two weeks (48 hours at Level Three) Two weeks Level One
All other applications One month One month Level Two

Scanning intervals track the same logic: daily for online services, weekly for the productivity and security software set, and fortnightly for everything else from Level Two. Automated asset discovery runs at least fortnightly at every level.

Vulnerability scanners must use an up-to-date vulnerability database. ASD's Essential Eight assessment process guide suggests the database should ideally have been updated within 24 hours of the scan.

See the requirements matrix for every control at each maturity level.

Removing what cannot be patched

In addition to the patching timeframes, the strategy requires removing software the vendor no longer supports:

  • Level One: unsupported online services, and unsupported office suites, browsers, email clients, PDF software, Adobe Flash Player and security products
  • Level Three: all other unsupported applications

Unsupported software can make the strategy difficult in legacy environments. ASD acknowledges that implementing the Essential Eight on legacy systems is "often difficult" and "strongly encourages organisations to upgrade their legacy systems as a priority", with compensating controls in the interim. The Essential Eight maturity model FAQ covers the legacy case.

ASD's Commonwealth Cyber Security Posture in 2025 records that 59% of Commonwealth entities said legacy technology had affected their ability to implement the Essential Eight.

What changed in November 2023

Two tightenings and one clarification, in ASD's own words in the Essential Eight maturity model changes:

In response to an ASD assessment of the average time taken by malicious actors to exploit vulnerabilities, additional focus has been placed on higher priority patching scenarios… organisations should patch, update or otherwise mitigate vulnerabilities within 48 hours. This change impacts Maturity Level One through Maturity Level Three.

…the patching timeframe for these applications has been strengthened from within one month to within two weeks… This has also resulted in an associated strengthening in vulnerability scanning activities from at least fortnightly to at least weekly.

Guidance allowing one month to patch a browser at Maturity Level One uses the pre-2023 model.

Why hosted software has the shortest timeframe

If you run a SaaS product or host an application for a client, that application is an "online service" in ASD's terms. The definition covers "any service that is directly accessible over the internet, including those sitting behind a perimeter firewall". You are therefore in the 48-hour tier from Level One, with daily scanning.

For organisations that cannot sustain that pace, ASD recommends considering "mature and trustworthy cloud service providers", depending on the kind of cloud service and the security benefit it provides.

This is one of four ways the Essential Eight can affect a software supplier that is not directly mandated. The software vendors page covers the others.

Sources

All ASD source documents →

Common questions

Is the Essential Eight patching window 30 days?

No. There is no 30-day application patching requirement at Maturity Level One. Online services must be patched within 48 hours when a vulnerability is critical or has a working exploit, and within two weeks otherwise. Office suites, browsers, email clients, PDF software and security products get two weeks. One month applies only to "all other applications", and only from Maturity Level Two.

When does the 48-hour clock start?

There are two cases. For a vulnerability rated critical by the vendor, the maturity model measures 48 hours from the release of a patch, update or other vendor mitigation. When a working exploit is the trigger, ASD's FAQ says the requirement relates to "the announcement of a working exploit or that exploitation is already occurring, whichever occurs first".

What counts as a critical vulnerability?

ASD points to the vendor's own assessment, giving examples of vulnerabilities that facilitate "authentication bypasses that grant privileged access" or "remote code execution without user interaction". Where a vendor gives no rating, ASD suggests considering the vulnerability type, its CVSS score where available, and CISA's Known Exploited Vulnerabilities Catalog.

Does the 48-hour rule apply at Maturity Level One?

Yes. The 48-hour timeframe for critical or actively exploited vulnerabilities in online services applies at Levels One, Two and Three. ASD introduced it in November 2023 in response to its assessment of how quickly attackers exploit vulnerabilities.

  • Essential Eight requirements matrix

    What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.

  • The Essential Eight will not secure the software you ship

    Every one of the 108 software development controls in the Information Security Manual is tagged "Essential 8: N/A". The Essential Eight says nothing about how you build software. It still binds you in four specific ways, and something else governs the code itself.

  • Patch operating systems

    Operating system patching splits between internet-facing and other systems. The November 2023 update relaxed the workstation and non-internet-facing timeframe to one month.

Essential Eight

Need this assessed rather than explained?

We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.