Skip to content
arrow_back
search
E8-PO-ML3.7 bolt ASD Essential Eight

Apply critical firmware patches within 48 hours

Ensure firmware vulnerabilities are fixed quickly, within 48 hours if critical.

record_voice_over

Plain language

This control is about fixing critical security problems in the firmware of your equipment within 48 hours. If these updates aren't applied quickly, cybercriminals could exploit these weaknesses to access sensitive data or disrupt your business. Applying these patches promptly helps keep your systems secure.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

PO

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
bolt ASD Essential Eight E8-PO-ML3.7
priority_high

Why it matters

Delaying critical firmware patches beyond 48 hours can leave devices exposed to known exploits, enabling compromise and disruption of services.

settings

Operational notes

Track vendor firmware advisories and exploit intel; prioritise critical updates and apply within 48 hours, with testing and rollback plans for devices.

Mapping detail

Mapping

Direction

Controls