Skip to content
arrow_back
search
E8-PA-ML1.5 bolt ASD Essential Eight

Apply critical application patches within 48 hours

Ensure critical software updates are installed within 48 hours to prevent security risks.

record_voice_over

Plain language

This control is about making sure that any critical updates for your software are applied within 48 hours of being released. This matters because if there's a known security weakness in your software, hackers could take advantage of it to access your systems. By quickly installing these updates, you protect your organisation from potential attacks.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Patch applications

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
bolt ASD Essential Eight E8-PA-ML1.5
priority_high

Why it matters

Delayed application of critical patches exposes online services to rapid exploitation, risking data breaches, ransomware and major operational disruption.

settings

Operational notes

Track vendor advisories for online services and, where rated critical or exploited, deploy patches/mitigations within 48 hours using an emergency change process.

Mapping detail

Mapping

Direction

Controls