Platform module

Patches by deadline, configurations by baseline

Cyber Essentials gives you 14 days for critical updates. Essential Eight sets maturity levels on patching. SOC 2 and ISO 27001 want a policy and proof you follow it. Certifyi tracks patch status per asset against your deadlines and keeps approved configuration baselines with the records behind each change.
Why patching and baselines are audited together. Both answer the question “is this system in the state you say it is?” Patch management proves known vulnerabilities are closed within your policy; configuration management proves settings match an approved baseline and that any change was approved. Frameworks: SOC 2 CC7.1 and CC8.1, ISO 27001 A.8.8 and A.8.9, Cyber Essentials update management, Essential Eight patch applications and operating systems, CMMC 3.4 and 3.14.

What it does

Patch

Patch status per asset

Missing updates from endpoint, cloud and container scanners, with severity and age against the deadline for that asset’s tier.

Prioritise

Deadlines that reflect risk

Critical internet-facing systems patched within days, internal tools within weeks; deadlines set per tier and evidenced on completion.

Baseline

Configuration baselines

Approved baselines for servers, cloud accounts, containers and endpoints, with the approval record attached.

Detect

Drift detection

Daily comparison against baselines; a change without an approved request shows as drift with an owner and a due date.

Hygiene

Unsupported software

Out-of-support operating systems and applications flagged, which is a hard fail in Cyber Essentials and Essential Eight.

Report

Evidence and reports

Patch compliance and baseline conformance by period, ready for the auditor and for customer questionnaires.

How it works

The same record your auditor, your vendors and your team already use.

Step 1

Inventory

Assets and their tiers come from the asset module.

Step 2

Baseline

Approved configuration per asset class, recorded with approver.

Step 3

Scan and patch

Scanners report missing patches; deadlines start automatically.

Step 4

Evidence

Completion and drift records accumulate for the audit period.

Questions about this module

Cyber Essentials requires critical and high-risk updates within 14 days. Essential Eight Maturity Level 2 requires 48 hours for exploited vulnerabilities in internet-facing services. SOC 2 and ISO 27001 require a documented policy you can prove you follow.

No. Cloud and container scanning is API-based; endpoint status comes from your existing endpoint protection or MDM integration.

The baseline is a versioned record with an approver and date. Changes to it go through change management, so the approval trail is complete.

See it on your own scope

Twenty minutes with a compliance lead. Bring your stack; we will show the module against your controls.
Scroll to Top