Skip to content
arrow_back
search
E8-PA-ML1.6 bolt ASD Essential Eight

Apply non-critical patches for online services within two weeks

Install updates for online services within two weeks if not critical and no exploits exist.

record_voice_over

Plain language

This control is about making sure that any minor issues in online services are fixed within two weeks. Even if these issues aren't critical, ignoring them could mean leaving a door open for potential attackers. Regular updates keep your systems safe by patching vulnerabilities before they can be exploited.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Patch applications

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
bolt ASD Essential Eight E8-PA-ML1.6
priority_high

Why it matters

Delaying non-critical patches for online services can allow later exploit chaining, turning low-risk flaws into outages or unauthorised access.

settings

Operational notes

Maintain a fortnightly patch review for internet-facing services; apply vendor non-critical patches within 14 days when no exploits are known.

Mapping detail

Mapping

Direction

Controls