Danzell A6.7

Where you have a business need to use unsupported software, have you moved the devices and software out of scope of this assessment?

Section A6: Security Update Management  ·  Cyber Essentials Danzell

Danzell tightened the isolation requirements — the isolated system must be demonstrably segregated from internet-accessible systems, not just described as separate.

What this question is really asking

If you have a genuine business need to continue running unsupported software, describe the isolation measures in place. Acceptable mitigations include network segmentation from internet-facing systems, application whitelisting, enhanced monitoring, and formal risk acceptance. Continuing to run unsupported software without any mitigation is not acceptable.

What satisfies this requirement

Yes or No — if Yes, a written description is also required

Unsupported software must be on a sub-set with no internet access. If out-of-scope sub-set remains internet-connected, must select 'Partial Organisation' in A2.1.

Check how you answer this in the CE Explorer
Free tool — all 288 questions mapped across every CE version.
Open CE Explorer

What to prepare before your assessor visit

Isolation for unsupported software is one of the more nuanced areas of the standard. 'Network segmentation' needs to be technically specific — which device enforces the segment? What are the firewall rules between the isolated system and the rest of your network? Can the isolated system reach the internet, even indirectly? Assessors will want to see the actual configuration, not a description of intent. The isolated system must be demonstrably segregated from internet-accessible systems.

How this question sits across CE versions

Danzell You are here
Where you have a business need to use unsupported software, have you moved the devices and software out of scope of this assessment?
Montpellier evolved View →
Where you have a business need to use unsupported software, have you moved the devices and software out of scope of the assessment?
Willow minor View →
Where you have a business need to use unsupported software, have you moved the devices and software out of scope of this assessment?

Does your organisation meet this requirement?

Answer 30 plain-English questions and find out exactly where you stand across all 5 Cyber Essentials control areas — with a prioritised list of what to fix first.