August 2026. Patch management is not an IT chore — it is among the most examined controls at ISO 27001 surveillance. Auditors pick a CVE from the news and ask: when scanned, when patched, who approved?
SLAs that work for SMEs
- critical: 7 days (internet-facing);
- high: 30 days;
- medium: 90 days or next maintenance window;
- exceptions: risk acceptance in management review.
Evidence
Scan reports, tickets, change records. Link to ISMS and vulnerability policy. Cloud posture tools export monthly to evidence folder.
In 2026 unpatched critical CVEs on admin VPNs are a common major finding. MFA without patch does not help.
