Opens in a new tab

Vulnerability and CVE detection: closing the Cyber Essentials Plus window

Close up of server racks with a honeycomb grille pattern, illuminated by blue and red lights, showing computer hardware and internal components in a data centre designed for advanced vulnerability detection and CVE detection.

Continuous CVE detection tracks and prioritises vulnerabilities as they emerge, rather than catching them at the next scheduled scan. That distinction matters more than it used to. Cyber Essentials Plus requires critical and high-severity vulnerabilities to be patched within 14 days of a fix becoming available, and a vulnerability that surfaces the day after a quarterly scan can sit unresolved for months before anyone notices it exists.

This is not a general point about patch cadence speeding up industry-wide. It is the specific, named service that closes that gap: continuous tracking, prioritisation, and remediation timed against the Cyber Essentials Plus clock, running on top of endpoint protection and managed detection and response that already need to be in place.

Continuous CVE detection tracks vulnerabilities as they emerge rather than on a scan schedule

A vulnerability scan is a snapshot. It tells you what is exposed at the moment the scan runs, and nothing about what changes in the days or weeks afterward. Continuous CVE detection replaces that snapshot with an ongoing feed, matching every device and piece of software in your estate against newly disclosed vulnerabilities from the moment they are published rather than at the next quarterly checkpoint.

Point-in-time scans miss what happens between scans

A quarterly scan catches whatever was already known and unpatched on scan day. It says nothing about a critical vulnerability disclosed the following week. Given that Cyber Essentials Plus measures compliance against a 14-day patching window, a scanning cadence measured in months is structurally incapable of demonstrating that window is being met, regardless of how good the underlying patch management actually is.

The Cyber Essentials Plus 14-day window has a specific definition of critical

Cyber Essentials Plus does not treat every update the same way. The 14-day clock applies specifically to vulnerabilities the vendor rates as critical or high risk, or those with a CVSS v3 score of 7.0 or above, or where no severity rating has been published at all.

What counts as critical or high risk under the scheme

If a vendor bundles a critical or high-risk fix into an update alongside lower-severity fixes, the entire update falls under the 14-day requirement. It cannot be split apart to delay the lower-priority components. Under the current question set, two of the automatic-fail questions relate directly to this: one covering operating systems and firmware, the other covering all other software in scope.

The 14-day clock explained

The clock starts when the fix becomes available, regardless of when an assessor happens to check. A device found running unpatched software against a known critical vulnerability older than 14 days is treated as an automatic fail, with no scope for a lesser mark under the current rules. This is what makes continuous detection a compliance requirement in practice, even though the scheme itself does not formally mandate vulnerability scanning by name.

Continuous CVE detection depends on endpoint protection and MDR already being active

Continuous CVE detection is not a standalone product. It relies on endpoint protection to enforce what gets patched and when, and on managed detection and response to flag anything that looks like active exploitation before a patch can be applied.

Why this service cannot run in isolation

Detecting a vulnerability without the means to act on it quickly only tells you what is wrong, not what to do about it. A business considering this service needs endpoint protection and MDR already active across its estate. Without that foundation, continuous CVE detection becomes a list of known problems with no reliable way to close them inside the 14-day window.

Point-in-time scanning compared with continuous CVE detection

AspectPoint-in-time scanningContinuous CVE detection
FreqencyScheduled, typically monthly or quarterlyOngoing, matched against new disclosures as they happen
What it catchesVulnerabilities known at scan timeVulnerabilities from the moment they are disclosed
Fit with Cyber Essentials PlusStructurally unable to reliably prove the 14-day window is metBuilt to demonstrate the 14-day window is being tracked and closed
DependencyCan run standaloneRequires endpoint protection and MDR already active

In Dr Logic’s experience, most businesses that fail an authenticated Cyber Essentials Plus scan are not failing because of a single missed patch. They are failing because their scanning cadence cannot prove compliance with a 14-day rule in the first place, regardless of how quickly patches actually get applied once someone notices.

This matters most for businesses that already treat Cyber Essentials Plus as a baseline rather than a box to tick once a year, since the scheme’s assessors have become considerably less flexible about update management under the current question set. A business that previously passed its Plus assessment comfortably should not assume the same scanning cadence will pass again, given how much stricter the enforcement around the 14-day rule has become.

For a Mac-first business, this also means checking that continuous CVE detection genuinely covers macOS and iOS devices, not just the Windows estate. Some vulnerability management tools are built primarily around Windows patch management and only extend partial coverage to Apple hardware, which leaves exactly the devices most of these businesses rely on outside the compliance picture.

If your current patching process cannot demonstrate the 14-day window is being met, Dr Logic’s cyber security team can assess whether continuous CVE detection is the right next step, and confirm what needs to be in place first.

Related articles

FAQs

What is continuous CVE detection?

Continuous CVE detection is an ongoing service that matches devices and software against newly disclosed vulnerabilities as they are published, rather than waiting for a scheduled scan. It is designed to demonstrate compliance with time-bound patching requirements such as the Cyber Essentials Plus 14-day window.

How is continuous CVE detection different from a vulnerability scan?

A vulnerability scan is a snapshot taken at a scheduled interval, typically monthly or quarterly. Continuous CVE detection runs constantly, flagging new vulnerabilities as soon as they are disclosed rather than at the next scan date, which matters when compliance is measured against a fixed number of days.

What counts as a critical vulnerability under Cyber Essentials Plus?

A vulnerability counts as critical or high risk if the vendor rates it that way, if it scores 7.0 or above on the CVSS v3 scale, or if no severity rating has been published at all. Any of these trigger the scheme’s 14-day patching requirement.

Does Cyber Essentials Plus require vulnerability scanning?

Not formally by name, but in practice it is close to unavoidable. Demonstrating that critical and high-risk vulnerabilities are patched within 14 days is very difficult without an ongoing way of detecting them as they appear, rather than relying on periodic scans alone.

What needs to be in place before continuous CVE detection can run?

Endpoint protection and managed detection and response need to already be active across the business. Continuous CVE detection identifies vulnerabilities quickly, but it depends on these other services to act on what it finds within the compliance window.

A man with light brown hair, glasses, and a beard smiles at the camera. He is wearing a black shirt with the logo “DR Logic.” The background shows tall, modern glass buildings.
Shaun

CTO

Shaun is Chief Technology Officer at Dr Logic, overseeing the technical direction of the business and the infrastructure that underpins client environments. He brings hands-on experience across Apple device management, cloud architecture, and enterprise IT strategy, and his articles focus on the technology decisions that help growing businesses scale securely and efficiently.

Explore More Articles

Clear, Actionable Advice – No Jargon, No Pressure.

Get In Touch With an IT Expert

Scaling up, tackling downtime, or reviewing your setup? Contact us or book a quick call for expert advice on running your IT smarter and more securely.

Rather speak to us right now? Our phone number is: 020 3642 6540


Contact Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Book a Consultation Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.

Want IT to Work Smarter for You?

Get expert tips, security advice, and practical insights for Apple and hybrid teams – straight to your inbox.


Subscription Form

You can unsubscribe from these communications at any time. To learn more about how to unsubscribe and how we protect your personal data, please see our Privacy Policy.