Monitor

Blog › Article

16 August 2026 · Article

The fourteen-day window in practice

"Apply high-risk and critical updates within fourteen days" sounds like one rule. In practice it's three questions — which updates count, when the clock starts, and how you'd know — and Windows only answers the easy one reliably.

Which updates count

The scheme's wording is more precise than most summaries of it. In-scope software must be updated, including any manual configuration changes needed to make the update take effect, within fourteen days of release, where:

That third condition is the one people miss, and it matters more than it looks. An update whose severity you can't establish isn't exempt. It's in.

Since 27 April 2026 (the Danzell question set) this is also two automatic-fail questions: A6.4 for operating systems, routers and firewalls, and A6.5 for applications.

When the clock starts

From the vendor's release, not from when your patching tool approved the update, not from when the machine downloaded it, and not from the next maintenance window. Every delay you add — deferral rings, approval steps, weekend windows — comes out of the same fourteen days.

Firmware and configuration changes count too. If a vendor's fix is "apply this update and then change this setting", the fix isn't done until both are.

Why Windows can't always tell you the severity

Windows Update exposes a severity field for each update, called MsrcSeverity, with values of Critical, Important, Moderate or Low. It looks like exactly what a fourteen-day check needs. The problem is that on current Windows builds it often comes back empty — and inconsistently: the same update can report a severity on one machine and nothing on another.

The likely reason is structural. Microsoft ships Windows fixes as monthly cumulative updates: one package that bundles many fixes of different severities. Severity is rated per vulnerability in Microsoft's Security Update Guide, not per package, so the package itself frequently carries no single rating. And if a bundled update contains even one critical or high-risk fix, the whole update falls under the fourteen-day rule. A tool that reads the field and treats an empty value as "not critical" will quietly ignore the updates that matter most.

An empty severity isn't a low severity. Under the scheme's own wording, an update whose severity the vendor doesn't state is treated as in scope. Any tool measuring the fourteen-day window has to do the same, or it will report machines as fine that an assessor would fail.

The date problem

Measuring age needs a release date, and that's less straightforward than it sounds. The date Windows reports for an update can move if Microsoft revises it, which makes an old fix look newer than it is. And a machine managed by WSUS or a patching tool answers against what that tool has approved, not against what Microsoft released — so a machine can report nothing missing while being weeks behind Microsoft.

The honest measure is the age of the oldest missing security update, counted from the vendor's release, on each machine. One number per machine, and the number an assessor is really asking about.

Applications are harder still

Windows at least has a single update mechanism. Applications don't. Browsers update themselves, some tools update only when opened, and some never update unless someone installs a new version. Each vendor publishes severity in its own way, if at all. Many estates that fail the fourteen-day rule won't fail on Windows; they'll fail on a browser or a PDF reader nobody was watching.

What this means in practice

Quick answers

Does the fourteen-day rule apply to all updates?

To updates the vendor rates critical or high risk, those fixing vulnerabilities scored CVSS 7 or above, and those where the vendor gives no severity at all.

When does the fourteen days start?

When the vendor releases the update, not when your tools approve or install it.

Do application updates count?

Yes. Applications have their own automatic-fail question, alongside the one for operating systems, routers and firewalls.