Unsupported software is the quickest way to fail a Cyber Essentials assessment, and from 12 January 2027 every machine still running Windows Server 2016 becomes exactly that. The certification consequences arrive on a calendar date, not after a breach: the day free security updates stop, an operating system that passed last year’s assessment becomes a declaration you can no longer make honestly. ISO 27001 reaches the same destination by a different route — not an automatic fail, but a finding your auditor will write up if the risk is unmanaged.

This guide is the compliance companion to four earlier articles in this series. The Windows Server 2016 end of support risk guide covers the security exposure, the migration guide covers the technical routes, the ESU cost comparison prices the pay-to-stay option, and the upgrade assessment checklist scores each server. None of them answers the question this one does: what does unsupported software actually do to your certificates, and which fixes do assessors accept?

The short version: Cyber Essentials treats unsupported software as a binary — remove it, keep it supported through paid updates, or segregate it out of scope. ISO 27001 treats it as a risk to be managed with evidence. Both give you workable routes through January 2027, and every route works better started now than started in December 2026.

Why Unsupported Software Fails Cyber Essentials

unsupported software cyber essentials iso 27001 b three tier stepped pyramid

Cyber Essentials is built on five technical controls — firewalls, secure configuration, access control, malware protection and security update management — and the last of those is where unsupported software breaks the scheme’s logic. The security update management control requires that software on in-scope devices is licensed and supported, and that updates fixing vulnerabilities the vendor rates as high or critical are applied within 14 days of release. An operating system whose vendor has stopped publishing updates cannot meet either half of that sentence.

What the question set actually asks

The self-assessment asks you to confirm, in writing, that all software in scope is supported and receiving security updates. That declaration is signed by a board member or equivalent, which turns a technical oversight into a governance problem: certifying with known unsupported software in scope is not a grey area, it is an inaccurate declaration. The NCSC’s Cyber Essentials scheme is explicit that unsupported software must be removed from in-scope devices or moved out of scope by segregation. There is no third option where it simply stays and nobody asks.

The 14-day rule needs a living vendor

The patching clock only works when a vendor is still publishing patches. After 12 January 2027, Microsoft will keep finding flaws that affect Windows Server 2016 — its newer server products share ancestry with it, so researchers effectively keep auditing the old code — but fixes ship only to supported versions and to Extended Security Update subscribers. Everyone else accumulates known, published, unpatchable flaws. The NCSC’s obsolete products guidance describes exactly this position as the one to engineer your way out of, fast.

How the three schemes treat the same server

The table below compares how the UK’s most common certifications respond to the same unsupported software finding. The differences drive every decision later in this article.

SchemeRule appliedConsequence of unsupported software in scopeHow it is checked
Cyber EssentialsAll in-scope software licensed and supportedAssessment fails, or the declaration is inaccurateSigned self-assessment, verified by an assessor
Cyber Essentials PlusSame rule, independently testedAudit evidence contradicts the declaration; certification refusedHands-on technical verification of sampled devices
ISO 27001Risk-based; vulnerabilities managed under control 8.8Nonconformity if unmanaged; acceptable if treated with evidenceStage audits plus annual surveillance

Unsupported Software Under ISO 27001

unsupported software cyber essentials iso 27001 c two blocks clear gap

ISO 27001 never names products or deadlines, which is why some teams assume an ageing estate is safe territory there. It is not. The standard requires an information security management system that identifies risks and treats them, and unsupported software is one of the easiest risks in existence for an auditor to spot: the vendor has published the end date, the vulnerability feeds keep flowing, and the patch column in your report stays empty.

Control 8.8: management of technical vulnerabilities

Annex A control 8.8 requires organisations to obtain information about technical vulnerabilities, evaluate exposure, and take appropriate measures. A server that can no longer receive fixes makes that control unsatisfiable in its normal form — you can still know about the vulnerabilities, but “appropriate measures” narrows to compensating controls or removal. Our ISO 27001 readiness assessment checklist covers how assessors probe this control; an end-of-life operating system is among the first things they grep an asset register for.

Risk acceptance is not a free pass

ISO 27001 does allow risk acceptance, and this is the honest difference from Cyber Essentials: you may run unsupported software under ISO 27001 if the risk is formally assessed, treatment options were considered, compensating controls exist, and someone with authority signed the residual risk. What you may not do is stay silent. An unassessed end-of-life estate found during surveillance is a classic nonconformity; a documented, time-boxed migration plan with interim controls is usually a pass with an observation. The paperwork is the difference.

What a nonconformity costs you

A minor nonconformity means a corrective action plan with deadlines your certification body will chase. A major one — or minors left unresolved — can suspend the certificate itself, and contracts increasingly reference certification status directly. If your organisation holds both certificates, the comparison in our Cyber Essentials Plus vs ISO 27001 guide explains which clients care about which; losing either over a known, dated, fixable issue is a difficult conversation with a board that signed the declaration.

The Deadline Arithmetic: Dates and Runway

unsupported software cyber essentials iso 27001 d blank flag tall pole

Certification planning against end-of-life dates is arithmetic, not judgement. Every date below is published by Microsoft, and each one changes what you can honestly declare.

Dates locked into the calendar

DateEventCertification impact
11 January 2022Windows Server 2016 mainstream support endedNone yet — security updates continued
14 July 2026SQL Server 2016 extended support endedDatabases on that version are already unsupported software
12 January 2027Windows Server 2016 extended support endsThe OS becomes unsupported unless ESU is purchased
January 2028ESU year one expiresRenew at a higher price or lose supported status
January 2029ESU year two expiresFinal paid year begins
January 2030ESU year three expiresNo further route — the software is unsupported everywhere

How much runway is left

Counting from mid-August 2026, the gaps between today and each expiry date above work out as follows — and the first bar is the one your next recertification probably lands inside.

Months of supported status remaining per route (from August 2026)
Do nothing — support ends January 2027 5 months
ESU year one — to January 2028 17 months
ESU years one and two — to January 2029 29 months
All three ESU years — to January 2030 41 months

Five months is shorter than most annual certification cycles. If your Cyber Essentials renewal falls between January and August 2027 and a migration is not finished, you will be declaring against an estate containing unsupported software — which is why the decision belongs in this quarter, not next year.

ESU and Unsupported Software: Does Paying Count?

unsupported software cyber essentials iso 27001 e open blank book

Extended Security Updates change the compliance answer, and this is the point most often misunderstood. A server enrolled in ESU continues to receive the vendor’s critical and important security fixes, so for Cyber Essentials purposes it is still supported software: updates exist, and you can apply them inside the 14-day window. ISO 27001 auditors take the same view, provided enrolment is documented and the updates demonstrably flow. Paying for ESU is not a loophole — it is precisely the “vendor-supported” state the schemes require, bought rather than bundled.

What ESU does and does not cover

ESU delivers security fixes only — no feature updates, no non-security bug fixes, and no new certification of the platform by application vendors. Microsoft’s ESU overview also makes the boundary explicit: coverage is for a maximum of three years after end of support, sold annually, per server. Your declaration stays honest exactly as long as the subscription stays current, so the renewal date becomes a compliance date and belongs in the same register as the certificate expiry itself.

What the honest bridge costs

ESU pricing escalates deliberately: roughly 75% of the current licence cost in year one, 100% in year two and 125% in year three — about 300% of a licence across the full bridge, for software you already own. Note also that from 1 April 2026 Microsoft charges the same ESU list price everywhere, so the 2016 wave gets no free-in-Azure discount the way the 2012 wave once did. The chart shows the ladder; the ESU cost comparison works the full sums against upgrading.

ESU annual price as a share of the current licence cost
Year one (to January 2028) 75%
Year two (to January 2029) 100%
Year three (to January 2030) 125%

Evidence to keep if you take the ESU route

Keep the enrolment confirmation, the licence assignment per server, and update logs showing ESU patches actually installing. For Cyber Essentials Plus, expect the assessor to check patch levels on sampled machines directly; an ESU subscription that finance bought but nobody activated shows up immediately as missing updates — unsupported software wearing a receipt.

Segregation: Moving Unsupported Software Out of Scope

unsupported software cyber essentials iso 27001 f chess rook tower

The third accepted route is to keep the machine but remove it from certification scope. Cyber Essentials permits scoping to a subset of the organisation when the subset is separated by a firewall or VLAN with controlled traffic, and its guidance for unsupported software is exactly that: remove it, or segregate it into a network where it cannot reach or be reached by the in-scope environment except through tightly controlled paths.

What segregation means in practice

A flat network with the old server on it fails the test by definition. Genuine segregation means the legacy system sits behind its own firewall rules, reachable only on the specific ports its remaining function needs, with no inbound path from the internet and no ability to browse out. Getting there usually starts with a vulnerability assessment of what the machine exposes today, followed by network changes across your IT infrastructure that are real engineering work — segregation is cheaper than migration, not free.

ISO 27001 sees segregation as a control, not an exit

Under ISO 27001 there is no “out of scope” escape for a system that still processes organisational information — segregation there is a compensating control inside the risk treatment, not a boundary trick. The risk stays on the register; the control reduces it; the auditor reviews both. That framing is useful discipline for Cyber Essentials too, because a segregated machine is still a machine an attacker can find.

Why segregation is a stopgap

Segregation answers the assessor and leaves the business problem intact: the isolated server still runs, still ages, and still fails eventually — now with fewer people watching it. It suits systems with a confirmed retirement date, a vendor dependency that genuinely cannot move yet, or a function too small to justify migration spend this year. As a permanent home for unsupported software it quietly becomes the riskiest asset you own.

Five Routes Compared for Certification

Every Windows Server 2016 machine in your estate resolves to one of five routes. They differ sharply in what they do to each certificate, what they cost, and how long they last.

RouteCyber Essentials outcomeISO 27001 outcomeCost profileHow long it holds
Upgrade in place to 2025Fully compliantRisk closedLicence plus project timeA decade of support
Rebuild or rehost to cloudFully compliantRisk closedMigration effort plus running costsEvergreen while managed
Buy ESUCompliant while the subscription is currentAcceptable with documented plan75% → 100% → 125% of licence, annuallyThree years maximum
Segregate out of scopeCompliant if separation is genuineCompensating control; risk stays registeredNetwork engineering timeUntil the next assessor asks why it is still there
DecommissionFully compliantRisk removedData migration and archival onlyPermanent

The pattern worth noticing: the two cheapest-looking routes are the two that expire. ESU buys at most three years at escalating cost, and segregation buys exactly as much time as your assessors’ patience. Estates above a handful of servers usually blend routes — upgrade the majority, ESU the awkward two, retire the forgotten ones — and the upgrade assessment checklist is the instrument for deciding which machine gets which.

Evidence Your Assessor Will Ask For

All three certification processes converge on the same practical question: show me. What varies is who does the showing and how deep the checking goes.

For the Cyber Essentials self-assessment

You need an accurate software inventory with versions and support status, so the declaration is grounded in something checkable. Where ESU applies, keep the subscription evidence; where segregation applies, keep the firewall rules and a network diagram showing the separation. The certification body — IASME operates the scheme for the NCSC — can and does query declarations that look inconsistent with the organisation’s described estate.

For Cyber Essentials Plus

Plus adds independent verification: an assessor samples devices, checks installed versions and patch levels, and tests that segregation claims hold from the network they are supposed to protect. The most common failure shape is drift between the declaration and the estate — a server that was “being retired” in the paperwork and still answering on port 445 during penetration testing-style verification. Our guide to Cyber Essentials failure reasons covers the recurring patterns; unsupported software found live during the audit is among the least arguable.

For ISO 27001 audits

Bring the risk assessment naming the end-of-life systems, the treatment decision for each, the compensating controls in operation, and the migration plan with dates that have not silently slipped. Auditors at surveillance visits read last year’s plan first — a migration date that moved twelve months without a documented decision is itself a finding about your compliance process, separate from the servers.

A 150-Day Unsupported Software Action Plan

Five months separate August 2026 from the January deadline. Run the phases below and the certification question is answered before the date arrives, whichever routes you pick per server.

Days 1–30: inventory and exposure

Build the definitive list of 2016-era systems — operating systems and the applications on them, including SQL Server 2016, which is already past its own date. Flag which machines sit inside your Cyber Essentials scope and which carry ISO 27001-registered information. This is also the moment to brief the board member who signs the declaration, because the signature is theirs and the cybersecurity risk being signed off is now dated and public.

Days 31–60: decide per server

Score each machine against the five routes using the assessment checklist, and price the ESU candidates honestly — escalating annual costs against a one-off migration. Confirm the domain functional level question early if domain controllers are involved: adding Windows Server 2025 controllers needs the domain and forest at the 2016 functional level or higher, and discovering otherwise mid-project costs weeks.

Days 61–120: execute the majority

Migrate the straightforward machines first — the migration guide’s routes cover in-place upgrades and rebuilds — and implement segregation for the machines staying behind, with firewall rules written and tested rather than promised. Enrol ESU machines before the deadline, not after it: coverage is cleanest when the subscription starts while the software is still supported.

Days 121–150: evidence and recertify

Update the asset register, the network diagrams and the risk register to match reality. If your Cyber Essentials certificate renews in 2027, walk the question set now against the finished estate and fix the gaps while they are cheap. Teams without the internal capacity for this phase typically hand the evidence pack and the renewal to a managed IT services provider — the work is well-bounded once the routes are chosen.

Unsupported Software FAQ

Does Windows Server 2016 fail Cyber Essentials today?

Not yet. Until 12 January 2027 it remains in extended support and receives security updates, so it can be declared honestly. The failure state begins the day updates stop — which is why a renewal falling in early 2027 needs the plan finished in 2026.

Is ESU accepted for Cyber Essentials?

Yes. ESU means the vendor is still providing security updates, which is what the scheme’s definition of supported software turns on. Keep enrolment evidence and apply the updates within the 14-day window, and the declaration holds for as long as the subscription does.

Can I just accept the risk under ISO 27001 and do nothing?

You can accept a risk; you cannot skip assessing it. A documented assessment, considered options, compensating controls and a senior signature will usually survive an audit for a bounded period. Bare risk acceptance with no controls and no end date invites a nonconformity — auditors distinguish sharply between a managed exception and a hope.

Does one old server really jeopardise a whole certificate?

For Cyber Essentials, yes, if it is in scope: the declaration covers the whole boundary, and one machine running unsupported software makes it inaccurate. For ISO 27001 the certificate rarely falls to a single finding, but repeat findings or an ignored corrective action can escalate to suspension.

What about unsupported software besides Windows Server?

The same rules catch everything in scope: old SQL Server versions, out-of-support hypervisors, legacy line-of-business applications, even browser plug-ins. Windows Server 2016 is simply the biggest single wave arriving on one date — treat the January deadline as the trigger to sweep the whole estate for unsupported software, not just one product.

References