Blog › Article
The fourteen-day window in practice
"Apply high-risk and critical updates within fourteen days" sounds like one rule. In practice it's three questions — which updates count, when the clock starts, and how you'd know — and Windows only answers the easy one reliably.
Which updates count
The scheme's wording is more precise than most summaries of it. In-scope software must be updated, including any manual configuration changes needed to make the update take effect, within fourteen days of release, where:
- the vendor describes the fix as critical or high risk;
- the fix addresses a vulnerability with a CVSS v3 score of 7 or above; or
- the vendor gives no details of how severe the vulnerabilities are.
That third condition is the one people miss, and it matters more than it looks. An update whose severity you can't establish isn't exempt. It's in.
Since 27 April 2026 (the Danzell question set) this is also two automatic-fail questions: A6.4 for operating systems, routers and firewalls, and A6.5 for applications.
When the clock starts
From the vendor's release, not from when your patching tool approved the update, not from when the machine downloaded it, and not from the next maintenance window. Every delay you add — deferral rings, approval steps, weekend windows — comes out of the same fourteen days.
Firmware and configuration changes count too. If a vendor's fix is "apply this update and then change this setting", the fix isn't done until both are.
Why Windows can't always tell you the severity
Windows Update exposes a severity field for each update, called
MsrcSeverity, with values of Critical, Important, Moderate or Low. It looks
like exactly what a fourteen-day check needs. The problem is that on current Windows
builds it often comes back empty — and inconsistently: the same update can report a
severity on one machine and nothing on another.
The likely reason is structural. Microsoft ships Windows fixes as monthly cumulative updates: one package that bundles many fixes of different severities. Severity is rated per vulnerability in Microsoft's Security Update Guide, not per package, so the package itself frequently carries no single rating. And if a bundled update contains even one critical or high-risk fix, the whole update falls under the fourteen-day rule. A tool that reads the field and treats an empty value as "not critical" will quietly ignore the updates that matter most.
An empty severity isn't a low severity. Under the scheme's own wording, an update whose severity the vendor doesn't state is treated as in scope. Any tool measuring the fourteen-day window has to do the same, or it will report machines as fine that an assessor would fail.
The date problem
Measuring age needs a release date, and that's less straightforward than it sounds. The date Windows reports for an update can move if Microsoft revises it, which makes an old fix look newer than it is. And a machine managed by WSUS or a patching tool answers against what that tool has approved, not against what Microsoft released — so a machine can report nothing missing while being weeks behind Microsoft.
The honest measure is the age of the oldest missing security update, counted from the vendor's release, on each machine. One number per machine, and the number an assessor is really asking about.
Applications are harder still
Windows at least has a single update mechanism. Applications don't. Browsers update themselves, some tools update only when opened, and some never update unless someone installs a new version. Each vendor publishes severity in its own way, if at all. Many estates that fail the fourteen-day rule won't fail on Windows; they'll fail on a browser or a PDF reader nobody was watching.
What this means in practice
- Measure from release, not approval. Know the release date of the oldest missing security update on every machine.
- Treat unknown severity as high. It's what the scheme says, and it's the only safe default.
- Add up your pipeline. Deferral plus approval plus maintenance window must land inside fourteen days in the worst case, not the typical one.
- Don't trust "nothing to install". A managed machine can be current against its own server and behind Microsoft.
- Watch applications separately. Windows being current says nothing about the browser.
- Keep the history. An assessor, or your own declaration, may need evidence that the rule held over time, not just on the day.
Quick answers
Does the fourteen-day rule apply to all updates?
To updates the vendor rates critical or high risk, those fixing vulnerabilities scored CVSS 7 or above, and those where the vendor gives no severity at all.
When does the fourteen days start?
When the vendor releases the update, not when your tools approve or install it.
Do application updates count?
Yes. Applications have their own automatic-fail question, alongside the one for operating systems, routers and firewalls.