Platform module
Patches by deadline, configurations by baseline
Cyber Essentials gives you 14 days for critical updates. Essential Eight sets maturity levels on patching. SOC 2 and ISO 27001 want a policy and proof you follow it. Certifyi tracks patch status per asset against your deadlines and keeps approved configuration baselines with the records behind each change.
Why patching and baselines are audited together. Both answer the question “is this system in the state you say it is?” Patch management proves known vulnerabilities are closed within your policy; configuration management proves settings match an approved baseline and that any change was approved. Frameworks: SOC 2 CC7.1 and CC8.1, ISO 27001 A.8.8 and A.8.9, Cyber Essentials update management, Essential Eight patch applications and operating systems, CMMC 3.4 and 3.14.
What it does
Patch
Patch status per asset
Missing updates from endpoint, cloud and container scanners, with severity and age against the deadline for that asset’s tier.
Prioritise
Deadlines that reflect risk
Critical internet-facing systems patched within days, internal tools within weeks; deadlines set per tier and evidenced on completion.
Baseline
Configuration baselines
Approved baselines for servers, cloud accounts, containers and endpoints, with the approval record attached.
Detect
Drift detection
Daily comparison against baselines; a change without an approved request shows as drift with an owner and a due date.
Hygiene
Unsupported software
Out-of-support operating systems and applications flagged, which is a hard fail in Cyber Essentials and Essential Eight.
Report
Evidence and reports
Patch compliance and baseline conformance by period, ready for the auditor and for customer questionnaires.
How it works
The same record your auditor, your vendors and your team already use.
Step 1
Inventory
Assets and their tiers come from the asset module.
Step 2
Baseline
Approved configuration per asset class, recorded with approver.
Step 3
Scan and patch
Scanners report missing patches; deadlines start automatically.
Step 4
Evidence
Completion and drift records accumulate for the audit period.
Questions about this module
What patch deadlines do frameworks require?
Cyber Essentials requires critical and high-risk updates within 14 days. Essential Eight Maturity Level 2 requires 48 hours for exploited vulnerabilities in internet-facing services. SOC 2 and ISO 27001 require a documented policy you can prove you follow.
Do we need agents on every server?
No. Cloud and container scanning is API-based; endpoint status comes from your existing endpoint protection or MDM integration.
How is a baseline approved?
The baseline is a versioned record with an approver and date. Changes to it go through change management, so the approval trail is complete.
See it on your own scope
Twenty minutes with a compliance lead. Bring your stack; we will show the module against your controls.