Ga naar inhoud

ISO 27001 ·

Patch and vulnerability management: surveillance favourite in 2026

August 2026. Patch management is not an IT chore — it is among the most examined controls at ISO 27001 surveillance. Auditors pick a CVE from the news and ask: when scanned, when patched, who approved?

SLAs that work for SMEs

  • critical: 7 days (internet-facing);
  • high: 30 days;
  • medium: 90 days or next maintenance window;
  • exceptions: risk acceptance in management review.

Evidence

Scan reports, tickets, change records. Link to ISMS and vulnerability policy. Cloud posture tools export monthly to evidence folder.

In 2026 unpatched critical CVEs on admin VPNs are a common major finding. MFA without patch does not help.

Deep dive in the knowledge base

Run the ISO 27001 readiness scan

See where you stand before investing in documents or consultants.

Start the readiness scan

← Back to overview