Cyber Essentials Plus
Security Update Management

Cyber Essentials Plus CEP-PM-03: Authenticated Vulnerability Scan of Sample Devices

An authenticated vulnerability scan of a representative sample of end user devices and servers must show no high or critical CVEs older than 14 days with CVSS 7.0 or above.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Security Update Management

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.