Skip to content

ISO 27001 ·

Patch and vulnerability management: surveillance favourite in 2026

August 2026. Patch management is not an IT chore, it is among the most examined controls at ISO 27001 surveillance. Auditors pick a CVE from the news and ask: when scanned, when patched, who approved?

SLAs that work for SMEs

  • critical: 7 days (internet-facing);
  • high: 30 days;
  • medium: 90 days or next maintenance window;
  • exceptions: risk acceptance in management review.

Evidence

Scan reports, tickets, change records. Link to ISMS and vulnerability policy. Cloud posture tools export monthly to evidence folder.

In 2026 unpatched critical CVEs on admin VPNs are a common major finding. MFA without patch does not help.

Deep dive in the knowledge base

Need help with the next step?

Explore support for your next step at ISO Ready. ISO Ready and this knowledge base are operated by Oosterwal Consultancy.

Explore your next step at ISO Ready

← Back to overview

isocertificering.org is operated by Oosterwal Consultancy (oosterwal.com). ISO Ready (iso-ready.nl) has the same owner. Links to ISO Ready refer to our own commercial offering. About us (Dutch)

AI reading guide (llms.txt)