← Back to Insights Essential Eight

Patch management: why ML2 requires more than a scanning tool

By Aaron Kelder

Practice 2 — patch operating systems — and Practice 3 — patch applications — are among the most assessed Essential Eight strategies. Many organisations have tools in place but still stall at ML1.

The ML1 trap

Having a vulnerability scanner that produces weekly reports satisfies the baseline. ML2 requires evidence that patches are applied within ACSC timeframes and that exceptions are managed formally.

What assessors scrutinise

  • Extreme risk vulnerabilities patched within 48 hours
  • High risk within two weeks
  • Documented exceptions with compensating controls and expiry dates
  • Measured compliance rates — not just ticket counts

Moving forward

Start measuring your actual patch compliance rate per severity tier. If you cannot report that number today, that is your first remediation priority — before buying another scanning tool.