Unsupported software is the quickest way to fail a Cyber Essentials assessment, and from 12 January 2027 every machine still running Windows Server 2016 becomes exactly that. The certification consequences arrive on a calendar date, not after a breach: the day free security updates stop, an operating system that passed last year’s assessment becomes a declaration you can no longer make honestly. ISO 27001 reaches the same destination by a different route — not an automatic fail, but a finding your auditor will write up if the risk is unmanaged.
This guide is the compliance companion to four earlier articles in this series. The Windows Server 2016 end of support risk guide covers the security exposure, the migration guide covers the technical routes, the ESU cost comparison prices the pay-to-stay option, and the upgrade assessment checklist scores each server. None of them answers the question this one does: what does unsupported software actually do to your certificates, and which fixes do assessors accept?
The short version: Cyber Essentials treats unsupported software as a binary — remove it, keep it supported through paid updates, or segregate it out of scope. ISO 27001 treats it as a risk to be managed with evidence. Both give you workable routes through January 2027, and every route works better started now than started in December 2026.
Table of contents
- Why Unsupported Software Fails Cyber Essentials
- Unsupported Software Under ISO 27001
- The Deadline Arithmetic: Dates and Runway
- ESU and Unsupported Software: Does Paying Count?
- Segregation: Moving Unsupported Software Out of Scope
- Five Routes Compared for Certification
- Evidence Your Assessor Will Ask For
- A 150-Day Unsupported Software Action Plan
- Unsupported Software FAQ
- References
Why Unsupported Software Fails Cyber Essentials
Cyber Essentials is built on five technical controls — firewalls, secure configuration, access control, malware protection and security update management — and the last of those is where unsupported software breaks the scheme’s logic. The security update management control requires that software on in-scope devices is licensed and supported, and that updates fixing vulnerabilities the vendor rates as high or critical are applied within 14 days of release. An operating system whose vendor has stopped publishing updates cannot meet either half of that sentence.
What the question set actually asks
The self-assessment asks you to confirm, in writing, that all software in scope is supported and receiving security updates. That declaration is signed by a board member or equivalent, which turns a technical oversight into a governance problem: certifying with known unsupported software in scope is not a grey area, it is an inaccurate declaration. The NCSC’s Cyber Essentials scheme is explicit that unsupported software must be removed from in-scope devices or moved out of scope by segregation. There is no third option where it simply stays and nobody asks.
The 14-day rule needs a living vendor
The patching clock only works when a vendor is still publishing patches. After 12 January 2027, Microsoft will keep finding flaws that affect Windows Server 2016 — its newer server products share ancestry with it, so researchers effectively keep auditing the old code — but fixes ship only to supported versions and to Extended Security Update subscribers. Everyone else accumulates known, published, unpatchable flaws. The NCSC’s obsolete products guidance describes exactly this position as the one to engineer your way out of, fast.
How the three schemes treat the same server
The table below compares how the UK’s most common certifications respond to the same unsupported software finding. The differences drive every decision later in this article.
| Scheme | Rule applied | Consequence of unsupported software in scope | How it is checked |
|---|---|---|---|
| Cyber Essentials | All in-scope software licensed and supported | Assessment fails, or the declaration is inaccurate | Signed self-assessment, verified by an assessor |
| Cyber Essentials Plus | Same rule, independently tested | Audit evidence contradicts the declaration; certification refused | Hands-on technical verification of sampled devices |
| ISO 27001 | Risk-based; vulnerabilities managed under control 8.8 | Nonconformity if unmanaged; acceptable if treated with evidence | Stage audits plus annual surveillance |
Unsupported Software Under ISO 27001
ISO 27001 never names products or deadlines, which is why some teams assume an ageing estate is safe territory there. It is not. The standard requires an information security management system that identifies risks and treats them, and unsupported software is one of the easiest risks in existence for an auditor to spot: the vendor has published the end date, the vulnerability feeds keep flowing, and the patch column in your report stays empty.
Control 8.8: management of technical vulnerabilities
Annex A control 8.8 requires organisations to obtain information about technical vulnerabilities, evaluate exposure, and take appropriate measures. A server that can no longer receive fixes makes that control unsatisfiable in its normal form — you can still know about the vulnerabilities, but “appropriate measures” narrows to compensating controls or removal. Our ISO 27001 readiness assessment checklist covers how assessors probe this control; an end-of-life operating system is among the first things they grep an asset register for.
Risk acceptance is not a free pass
ISO 27001 does allow risk acceptance, and this is the honest difference from Cyber Essentials: you may run unsupported software under ISO 27001 if the risk is formally assessed, treatment options were considered, compensating controls exist, and someone with authority signed the residual risk. What you may not do is stay silent. An unassessed end-of-life estate found during surveillance is a classic nonconformity; a documented, time-boxed migration plan with interim controls is usually a pass with an observation. The paperwork is the difference.
What a nonconformity costs you
A minor nonconformity means a corrective action plan with deadlines your certification body will chase. A major one — or minors left unresolved — can suspend the certificate itself, and contracts increasingly reference certification status directly. If your organisation holds both certificates, the comparison in our Cyber Essentials Plus vs ISO 27001 guide explains which clients care about which; losing either over a known, dated, fixable issue is a difficult conversation with a board that signed the declaration.
The Deadline Arithmetic: Dates and Runway
Certification planning against end-of-life dates is arithmetic, not judgement. Every date below is published by Microsoft, and each one changes what you can honestly declare.
Dates locked into the calendar
| Date | Event | Certification impact |
|---|---|---|
| 11 January 2022 | Windows Server 2016 mainstream support ended | None yet — security updates continued |
| 14 July 2026 | SQL Server 2016 extended support ended | Databases on that version are already unsupported software |
| 12 January 2027 | Windows Server 2016 extended support ends | The OS becomes unsupported unless ESU is purchased |
| January 2028 | ESU year one expires | Renew at a higher price or lose supported status |
| January 2029 | ESU year two expires | Final paid year begins |
| January 2030 | ESU year three expires | No further route — the software is unsupported everywhere |
How much runway is left
Counting from mid-August 2026, the gaps between today and each expiry date above work out as follows — and the first bar is the one your next recertification probably lands inside.
Five months is shorter than most annual certification cycles. If your Cyber Essentials renewal falls between January and August 2027 and a migration is not finished, you will be declaring against an estate containing unsupported software — which is why the decision belongs in this quarter, not next year.
ESU and Unsupported Software: Does Paying Count?
Extended Security Updates change the compliance answer, and this is the point most often misunderstood. A server enrolled in ESU continues to receive the vendor’s critical and important security fixes, so for Cyber Essentials purposes it is still supported software: updates exist, and you can apply them inside the 14-day window. ISO 27001 auditors take the same view, provided enrolment is documented and the updates demonstrably flow. Paying for ESU is not a loophole — it is precisely the “vendor-supported” state the schemes require, bought rather than bundled.
What ESU does and does not cover
ESU delivers security fixes only — no feature updates, no non-security bug fixes, and no new certification of the platform by application vendors. Microsoft’s ESU overview also makes the boundary explicit: coverage is for a maximum of three years after end of support, sold annually, per server. Your declaration stays honest exactly as long as the subscription stays current, so the renewal date becomes a compliance date and belongs in the same register as the certificate expiry itself.
What the honest bridge costs
ESU pricing escalates deliberately: roughly 75% of the current licence cost in year one, 100% in year two and 125% in year three — about 300% of a licence across the full bridge, for software you already own. Note also that from 1 April 2026 Microsoft charges the same ESU list price everywhere, so the 2016 wave gets no free-in-Azure discount the way the 2012 wave once did. The chart shows the ladder; the ESU cost comparison works the full sums against upgrading.
Evidence to keep if you take the ESU route
Keep the enrolment confirmation, the licence assignment per server, and update logs showing ESU patches actually installing. For Cyber Essentials Plus, expect the assessor to check patch levels on sampled machines directly; an ESU subscription that finance bought but nobody activated shows up immediately as missing updates — unsupported software wearing a receipt.
Segregation: Moving Unsupported Software Out of Scope
The third accepted route is to keep the machine but remove it from certification scope. Cyber Essentials permits scoping to a subset of the organisation when the subset is separated by a firewall or VLAN with controlled traffic, and its guidance for unsupported software is exactly that: remove it, or segregate it into a network where it cannot reach or be reached by the in-scope environment except through tightly controlled paths.
What segregation means in practice
A flat network with the old server on it fails the test by definition. Genuine segregation means the legacy system sits behind its own firewall rules, reachable only on the specific ports its remaining function needs, with no inbound path from the internet and no ability to browse out. Getting there usually starts with a vulnerability assessment of what the machine exposes today, followed by network changes across your IT infrastructure that are real engineering work — segregation is cheaper than migration, not free.
ISO 27001 sees segregation as a control, not an exit
Under ISO 27001 there is no “out of scope” escape for a system that still processes organisational information — segregation there is a compensating control inside the risk treatment, not a boundary trick. The risk stays on the register; the control reduces it; the auditor reviews both. That framing is useful discipline for Cyber Essentials too, because a segregated machine is still a machine an attacker can find.
Why segregation is a stopgap
Segregation answers the assessor and leaves the business problem intact: the isolated server still runs, still ages, and still fails eventually — now with fewer people watching it. It suits systems with a confirmed retirement date, a vendor dependency that genuinely cannot move yet, or a function too small to justify migration spend this year. As a permanent home for unsupported software it quietly becomes the riskiest asset you own.
Five Routes Compared for Certification
Every Windows Server 2016 machine in your estate resolves to one of five routes. They differ sharply in what they do to each certificate, what they cost, and how long they last.
| Route | Cyber Essentials outcome | ISO 27001 outcome | Cost profile | How long it holds |
|---|---|---|---|---|
| Upgrade in place to 2025 | Fully compliant | Risk closed | Licence plus project time | A decade of support |
| Rebuild or rehost to cloud | Fully compliant | Risk closed | Migration effort plus running costs | Evergreen while managed |
| Buy ESU | Compliant while the subscription is current | Acceptable with documented plan | 75% → 100% → 125% of licence, annually | Three years maximum |
| Segregate out of scope | Compliant if separation is genuine | Compensating control; risk stays registered | Network engineering time | Until the next assessor asks why it is still there |
| Decommission | Fully compliant | Risk removed | Data migration and archival only | Permanent |
The pattern worth noticing: the two cheapest-looking routes are the two that expire. ESU buys at most three years at escalating cost, and segregation buys exactly as much time as your assessors’ patience. Estates above a handful of servers usually blend routes — upgrade the majority, ESU the awkward two, retire the forgotten ones — and the upgrade assessment checklist is the instrument for deciding which machine gets which.
Evidence Your Assessor Will Ask For
All three certification processes converge on the same practical question: show me. What varies is who does the showing and how deep the checking goes.
For the Cyber Essentials self-assessment
You need an accurate software inventory with versions and support status, so the declaration is grounded in something checkable. Where ESU applies, keep the subscription evidence; where segregation applies, keep the firewall rules and a network diagram showing the separation. The certification body — IASME operates the scheme for the NCSC — can and does query declarations that look inconsistent with the organisation’s described estate.
For Cyber Essentials Plus
Plus adds independent verification: an assessor samples devices, checks installed versions and patch levels, and tests that segregation claims hold from the network they are supposed to protect. The most common failure shape is drift between the declaration and the estate — a server that was “being retired” in the paperwork and still answering on port 445 during penetration testing-style verification. Our guide to Cyber Essentials failure reasons covers the recurring patterns; unsupported software found live during the audit is among the least arguable.
For ISO 27001 audits
Bring the risk assessment naming the end-of-life systems, the treatment decision for each, the compensating controls in operation, and the migration plan with dates that have not silently slipped. Auditors at surveillance visits read last year’s plan first — a migration date that moved twelve months without a documented decision is itself a finding about your compliance process, separate from the servers.
A 150-Day Unsupported Software Action Plan
Five months separate August 2026 from the January deadline. Run the phases below and the certification question is answered before the date arrives, whichever routes you pick per server.
Days 1–30: inventory and exposure
Build the definitive list of 2016-era systems — operating systems and the applications on them, including SQL Server 2016, which is already past its own date. Flag which machines sit inside your Cyber Essentials scope and which carry ISO 27001-registered information. This is also the moment to brief the board member who signs the declaration, because the signature is theirs and the cybersecurity risk being signed off is now dated and public.
Days 31–60: decide per server
Score each machine against the five routes using the assessment checklist, and price the ESU candidates honestly — escalating annual costs against a one-off migration. Confirm the domain functional level question early if domain controllers are involved: adding Windows Server 2025 controllers needs the domain and forest at the 2016 functional level or higher, and discovering otherwise mid-project costs weeks.
Days 61–120: execute the majority
Migrate the straightforward machines first — the migration guide’s routes cover in-place upgrades and rebuilds — and implement segregation for the machines staying behind, with firewall rules written and tested rather than promised. Enrol ESU machines before the deadline, not after it: coverage is cleanest when the subscription starts while the software is still supported.
Days 121–150: evidence and recertify
Update the asset register, the network diagrams and the risk register to match reality. If your Cyber Essentials certificate renews in 2027, walk the question set now against the finished estate and fix the gaps while they are cheap. Teams without the internal capacity for this phase typically hand the evidence pack and the renewal to a managed IT services provider — the work is well-bounded once the routes are chosen.
Unsupported Software FAQ
Does Windows Server 2016 fail Cyber Essentials today?
Not yet. Until 12 January 2027 it remains in extended support and receives security updates, so it can be declared honestly. The failure state begins the day updates stop — which is why a renewal falling in early 2027 needs the plan finished in 2026.
Is ESU accepted for Cyber Essentials?
Yes. ESU means the vendor is still providing security updates, which is what the scheme’s definition of supported software turns on. Keep enrolment evidence and apply the updates within the 14-day window, and the declaration holds for as long as the subscription does.
Can I just accept the risk under ISO 27001 and do nothing?
You can accept a risk; you cannot skip assessing it. A documented assessment, considered options, compensating controls and a senior signature will usually survive an audit for a bounded period. Bare risk acceptance with no controls and no end date invites a nonconformity — auditors distinguish sharply between a managed exception and a hope.
Does one old server really jeopardise a whole certificate?
For Cyber Essentials, yes, if it is in scope: the declaration covers the whole boundary, and one machine running unsupported software makes it inaccurate. For ISO 27001 the certificate rarely falls to a single finding, but repeat findings or an ignored corrective action can escalate to suspension.
What about unsupported software besides Windows Server?
The same rules catch everything in scope: old SQL Server versions, out-of-support hypervisors, legacy line-of-business applications, even browser plug-ins. Windows Server 2016 is simply the biggest single wave arriving on one date — treat the January deadline as the trigger to sweep the whole estate for unsupported software, not just one product.