Skip to content
arrow_back
search
E8-PO-ML3.8 bolt ASD Essential Eight

Firmware vulnerabilities patched within one month if non-critical and no exploits

Apply patches for non-critical firmware vulnerabilities within a month if no exploits exist.

record_voice_over

Plain language

This control is about making sure that any weaknesses found in your computer's core software, known as firmware, are fixed within a month if they aren't urgent and no one has figured out how to exploit them yet. If you don't patch these weaknesses, hackers might find a way to attack your systems down the line, putting your business at risk.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

PO

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
bolt ASD Essential Eight E8-PO-ML3.8
priority_high

Why it matters

If non-critical firmware fixes are delayed beyond one month, new exploits may emerge, leaving devices exposed and risking outages or integrity compromise.

settings

Operational notes

Track firmware vendor advisories and exploit status; for non-critical issues with no working exploit, schedule and apply patches/mitigations within 30 days.

Mapping detail

Mapping

Direction

Controls