Please list your email applications installed on end user devices and server.
Section A6: Security Update Management · Cyber Essentials Montpellier
What this question is really asking
List all email clients installed on end-user devices and servers. Email is the primary malware delivery channel — your email clients must be supported, updated, and configured to block active content in messages where possible. Both desktop clients and browser-based email access must be addressed.
What satisfies this requirement
A list is requiredVersion required. e.g. MS Exchange 2016, Outlook 2019.
What to prepare before your assessor visit
The most common omission is the email client on smartphones. If staff access corporate email on personal or corporate mobiles via a native mail app or Outlook for iOS/Android, those clients must be on supported, patched versions. Corporate email access from an older Android device running an outdated email client version is a genuine finding — one that often goes unnoticed until assessment.
How this question sits across CE versions
Related policy templates
Getting certified means having documentation to back it up. These policy templates cover the controls this question tests.
Does your organisation meet this requirement?
Answer 30 plain-English questions and find out exactly where you stand across all 5 Cyber Essentials control areas — with a prioritised list of what to fix first.