Nano Solutions

Patch operating systems

Patch operating systems is the Essential Eight mitigation strategy requiring vulnerabilities in operating systems on workstations, servers and network devices to be remediated within defined timeframes, and unsupported operating systems to be replaced. Internet-facing systems carry a 48-hour clock for critical or actively exploited vulnerabilities.

Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).

On this page 4 sections
  1. The timeframes
  2. What November 2023 relaxed
  3. Why edge devices have the shortest timeframe
  4. Commonwealth implementation

Patch operating systems at a glance

What each maturity level requires

Requirements are cumulative: Level Three means everything in Levels One and Two as well. Each level links to that requirement on the matrix.

  1. ML1 Maturity Level One

    Patch operating systems, Maturity Level One: Patch internet-facing OS — critical or exploited / otherwise
  2. ML2 Maturity Level Two

    Patch operating systems, Maturity Level Two: Carries Maturity Level One No new requirements
  3. ML3 Maturity Level Three

    Patch operating systems, Maturity Level Three: Patch drivers and firmware — critical or exploited / otherwise
New requirements start here Carries the level below Score yourself with the self-assessment, or look a term up in the glossary.

Patch operating systems sits beside patch applications in the Essential Eight, and the two have different clocks.

The timeframes

Asset Critical, or working exploit Otherwise Scanning
Internet-facing servers and network devices 48 hours Two weeks Daily
Workstations, non-internet-facing servers and network devices One month (48 hours at Level Three) One month Fortnightly
Drivers and firmware (Level Three only) 48 hours One month Fortnightly

Unsupported operating systems must be replaced, at every maturity level. Running only the latest or previous release is a Maturity Level Three requirement.

See the requirements matrix for every control at each maturity level.

What November 2023 relaxed

ASD's own explanation, in the Essential Eight maturity model changes:

To counter-balance changes made to strengthening patching timeframes for higher risk scenarios, patching of operating systems for less important devices, such as workstations, non-internet-facing servers and non-internet-facing network devices, have been rebalanced from within two weeks to within one month.

ASD tightened the timeframe for critical or exploited vulnerabilities on internet-facing systems and relaxed it for less exposed devices. The changes document presents the two changes as a risk-based counter-balance.

Why edge devices have the shortest timeframe

The internet-facing tier includes edge devices, which feature prominently in recent ASD incident reporting. ASD's Annual Cyber Threat Report 2024–2025 records:

In FY2024–25, ASD's ACSC observed more than 120 incidents associated with attacks on edge devices, of which 96% were successful.

ASD also describes the threat actor APT40 as "known for its rapid exploitation of security vulnerabilities, often within hours or days of the publication of proofs of concept". Together, these findings show why internet-facing systems have the shortest patching timeframe.

Commonwealth implementation

ASD's Commonwealth Cyber Security Posture in 2025 puts operating system patching at 62% of Commonwealth entities at Maturity Level Two or above in 2024–25, up from 51% the year before. It was the third-highest result among the eight strategies.

Automated asset discovery remains part of the control. It must run at least fortnightly so that vulnerability scanning covers systems added to the environment.

Sources

All ASD source documents →

Common questions

Did November 2023 make operating system patching stricter?

For internet-facing systems, yes: a 48-hour timeframe was introduced for critical or actively exploited vulnerabilities. For workstations and non-internet-facing servers and network devices, ASD relaxed the timeframe from two weeks to one month. The associated scanning moved from weekly to fortnightly. ASD described this as a counter-balance.

When do drivers and firmware come into scope?

Only at Maturity Level Three. Levels One and Two require no driver or firmware scanning or patching under this strategy. Level Three adds fortnightly scanning and the same 48-hour / one-month split that applies to operating systems.

Do we have to run the latest operating system?

Only at Maturity Level Three, and even then the requirement is "the latest release, or the previous release" — so being one version behind is compliant. At all levels, operating systems the vendor no longer supports must be replaced.

Are network devices covered by this strategy?

Yes. The requirements apply to operating systems on workstations, servers and network devices. Internet-facing network devices, including firewalls and virtual private network (VPN) concentrators, are in the daily-scanning, 48-hour tier. ASD's threat reporting recorded over 120 incidents involving attacks on edge devices in FY2024–25, of which 96% were successful.

  • Essential Eight requirements matrix

    What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.

  • Patch applications

    The Essential Eight sets different patching timeframes for different assets. Online services enter the 48-hour tier from Maturity Level One.

Essential Eight

Need this assessed rather than explained?

We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.