Rule explainer
The Cyber Essentials 14-day critical patch rule, explained
Under the current standard, critical and high-severity security updates need to be identified and installed within 14 days of release, across every device and piece of software in scope. This is an automatic-fail rule: there's no partial credit for "we patch monthly" if a critical patch was available more than 14 days before your monthly cycle runs.
The businesses that get caught out aren't usually ignoring patching altogether. They have a process, it's just built around a slower cadence (monthly change control, quarterly reviews) that doesn't match the 14-day window for the most severe updates specifically.
The practical fix is to separate critical/high patches from your normal update cycle: automate what you can, and add an explicit 14-day check for anything that can't auto-update. Run the free 5-minute readiness check to see if your current process would pass this rule.