Telappliant
Cyber Security Guide · 28 May 2026

End-of-life devices and the risk to your Cyber Essentials certification

Unsupported operating systems, firmware and network kit are the most common reason UK businesses fail assessment. Here is how to stay ahead of it.

By the Telappliant team

Stack of unsupported end-of-life network hardware awaiting replacement

Unsupported software is the single most common reason UK organisations fail Cyber Essentials. It is also the most avoidable, because end-of-life dates are published years in advance. The problem is rarely the laptops everyone remembers; it is the kit nobody owns.

What the standard requires

Cyber Essentials expects all software in scope, including operating systems, firmware on network devices, browsers and applications, to be licensed, supported and receiving security updates. Anything past its vendor end-of-support date must be removed from scope, replaced, or segregated so it cannot reach the internet.

The devices that catch people out

  • Windows 10 machines left in a store cupboard or used by a single part-time role
  • Firewalls and switches running firmware the vendor no longer patches
  • Old wireless access points and unmanaged network hardware
  • IP phones and door entry panels with abandoned firmware
  • Android and iOS devices past their final OS release accessing company mail
  • Servers running an operating system version beyond mainstream support
  • Line-of-business applications tied to an unsupported runtime or database

How the failure shows up at assessment

In the self-assessment it usually appears as an honest answer to the software support question that the assessor cannot pass. In Cyber Essentials Plus the audit sample finds the device directly, and a single unsupported machine in scope is enough to fail the whole assessment. Remediation then happens under time pressure with a re-test fee attached.

Why insurers and clients care too

Cyber insurance applications ask the same question, and a claim involving an unsupported system is a straightforward route to a reduced or refused payout. Enterprise procurement questionnaires increasingly ask for evidence of a lifecycle policy, not just a certificate.

A refresh plan that avoids the annual scramble

  • Maintain a live asset inventory with vendor end-of-support dates against every item
  • Review the twelve-month horizon quarterly, not the month before assessment
  • Budget refresh as a rolling annual line rather than a periodic capital shock
  • Move devices that cannot be replaced into an isolated VLAN with no internet path
  • Use cloud desktops for the handful of users tied to legacy applications
  • Record the decision and the compensating control for anything you knowingly keep

If your assessment is imminent

Scope carefully and honestly. Devices genuinely removed from the network and from company data are out of scope; devices quietly left plugged in are not. It is far cheaper to replace two machines now than to fail, remediate and re-test.

Next steps

Frequently asked questions

Was this article helpful?

Further reading

Related guides

More practical guidance from the Telappliant team on the same topic.

Talk to a technology partner

Get direct access to the people who manage, support and improve your technology. Our teams work together across our locations, so whether the issue is IT, communications, connectivity or security, we can bring in the right expertise without passing you between separate providers.

  • One integrated support team
  • Expertise across IT, communications, connectivity and security
  • Connected support across our locations
Technology team reviewing plans together before a consultation
Call us Book consultation