Patch operating systems
Patch operating systems is the Essential Eight mitigation strategy requiring vulnerabilities in operating systems on workstations, servers and network devices to be remediated within defined timeframes, and unsupported operating systems to be replaced. Internet-facing systems carry a 48-hour clock for critical or actively exploited vulnerabilities.
Last checked against cyber.gov.au on . Current model: Essential Eight Maturity Model (November 2023).
On this page 4 sections
Patch operating systems at a glance
What each maturity level requires
Requirements are cumulative: Level Three means everything in Levels One and Two as well. Each level links to that requirement on the matrix.
-
ML1 Maturity Level One
Patch operating systems, Maturity Level One: Patch internet-facing OS — critical or exploited / otherwise -
ML2 Maturity Level Two
Patch operating systems, Maturity Level Two: Carries Maturity Level One No new requirements -
ML3 Maturity Level Three
Patch operating systems, Maturity Level Three: Patch drivers and firmware — critical or exploited / otherwise
Patch operating systems sits beside patch applications in the Essential Eight, and the two have different clocks.
The timeframes
| Asset | Critical, or working exploit | Otherwise | Scanning |
|---|---|---|---|
| Internet-facing servers and network devices | 48 hours | Two weeks | Daily |
| Workstations, non-internet-facing servers and network devices | One month (48 hours at Level Three) | One month | Fortnightly |
| Drivers and firmware (Level Three only) | 48 hours | One month | Fortnightly |
Unsupported operating systems must be replaced, at every maturity level. Running only the latest or previous release is a Maturity Level Three requirement.
See the requirements matrix for every control at each maturity level.
What November 2023 relaxed
ASD's own explanation, in the Essential Eight maturity model changes:
To counter-balance changes made to strengthening patching timeframes for higher risk scenarios, patching of operating systems for less important devices, such as workstations, non-internet-facing servers and non-internet-facing network devices, have been rebalanced from within two weeks to within one month.
ASD tightened the timeframe for critical or exploited vulnerabilities on internet-facing systems and relaxed it for less exposed devices. The changes document presents the two changes as a risk-based counter-balance.
Why edge devices have the shortest timeframe
The internet-facing tier includes edge devices, which feature prominently in recent ASD incident reporting. ASD's Annual Cyber Threat Report 2024–2025 records:
In FY2024–25, ASD's ACSC observed more than 120 incidents associated with attacks on edge devices, of which 96% were successful.
ASD also describes the threat actor APT40 as "known for its rapid exploitation of security vulnerabilities, often within hours or days of the publication of proofs of concept". Together, these findings show why internet-facing systems have the shortest patching timeframe.
Commonwealth implementation
ASD's Commonwealth Cyber Security Posture in 2025 puts operating system patching at 62% of Commonwealth entities at Maturity Level Two or above in 2024–25, up from 51% the year before. It was the third-highest result among the eight strategies.
Automated asset discovery remains part of the control. It must run at least fortnightly so that vulnerability scanning covers systems added to the environment.
Sources
- ASD — Essential Eight maturity model — Last updated 27 November 2023
- ASD — Essential Eight maturity model changes — 27 November 2023
- ASD — The Commonwealth Cyber Security Posture in 2025
Common questions
Did November 2023 make operating system patching stricter?
For internet-facing systems, yes: a 48-hour timeframe was introduced for critical or actively exploited vulnerabilities. For workstations and non-internet-facing servers and network devices, ASD relaxed the timeframe from two weeks to one month. The associated scanning moved from weekly to fortnightly. ASD described this as a counter-balance.
When do drivers and firmware come into scope?
Only at Maturity Level Three. Levels One and Two require no driver or firmware scanning or patching under this strategy. Level Three adds fortnightly scanning and the same 48-hour / one-month split that applies to operating systems.
Do we have to run the latest operating system?
Only at Maturity Level Three, and even then the requirement is "the latest release, or the previous release" — so being one version behind is compliant. At all levels, operating systems the vendor no longer supports must be replaced.
Are network devices covered by this strategy?
Yes. The requirements apply to operating systems on workstations, servers and network devices. Internet-facing network devices, including firewalls and virtual private network (VPN) concentrators, are in the daily-scanning, 48-hour tier. ASD's threat reporting recorded over 120 incidents involving attacks on edge devices in FY2024–25, of which 96% were successful.
Read next
-
Essential Eight requirements matrix
What each Essential Eight strategy requires at Maturity Levels One, Two and Three: timeframes, scanning intervals and controls introduced at higher levels. Sourced line by line from the November 2023 maturity model.
-
Patch applications
The Essential Eight sets different patching timeframes for different assets. Online services enter the 48-hour tier from Maturity Level One.
Essential Eight
Need this assessed rather than explained?
We assess your maturity across all eight strategies, show you where you actually stand, and do the remediation. We are not an ASD-endorsed assessor — nobody is, because no such endorsement exists.