All solutionsRegion For teams in the UK

Cyber Essentials gives you 14 days to patch. Do you know what day you are on?

Cyber Essentials asks you to fix high and critical vulnerabilities within 14 days of a patch being released, on every device in scope. DeDups lists every laptop and server you own, matches them against a feed refreshed every hour, and shows you what is past day 14 today.

15 minutes to connect. No credit card. No sales call.
14 daysto patch high and critical issues

From the day the update is released, on every device in scope. Re-certification comes round every 12 months.

The problem

The certificate is annual. The requirement is daily.

Cyber Essentials is the gate on most UK public-sector work, and you re-certify every 12 months. Cyber Essentials Plus adds a hands-on technical audit on top. Between certificates nobody is watching, so the 14-day patching rule slips quietly - and then an assessor picks a laptop at random.

  • The device list is a spreadsheet somebody updates when they remember.
  • Nobody knows which laptops run an old browser or an unpatched library.
  • Re-certification week turns into a two-week scramble every year.
How DeDups solves it

A live answer, not an annual one.

One agent per machine, a feed refreshed every hour, and a screen that shows how long each fix has been available. Day 14 becomes a number you can see rather than a date you hope you met.

  1. 01List every device

    The Inspector agent runs on Windows, macOS and Linux and lists everything installed, down to the version. Nothing to click and no user prompts.

  2. 02Match it every hour

    Your inventory is matched against a feed built from MITRE, NVD, CISA’s known-exploited list and EPSS exploit scores, refreshed hourly.

  3. 03Show the countdown

    Each finding shows the fixed version and how long that fix has been available - so past day 14 is a number on a screen, not a guess.

  4. 04Hand the assessor the file

    Device and patch evidence is dated and exportable, alongside ISO 27001 and SOC 2 control evidence collected on your cloud accounts.

What you get

The numbers, and what sits behind them.

14 dayspatch window tracked
Every hourfeed refreshed
3 platformsWindows, macOS and Linux

Full software inventory per device, including packages inside containers

Hourly feed from MITRE, NVD, CISA known-exploited and EPSS scores

Installed version shown next to the version that fixes it

Findings ranked by exploit probability, not just severity score

Cloud posture checks on the same account, if you run one

ISO 27001, SOC 2 and UK GDPR evidence collected as checks run

Machine speed, human judgement

The agent only reads.

It lists installed software, versions and system settings, then stops. It does not change anything on the machine and it does not watch the person using it. Patching stays with your team, on your schedule.

Cyber EssentialsCyber Essentials PlusUK GDPRISO 27001SOC 2
Before you commit

The questions we get asked most.

By default it runs, writes its report and exits. You can run it on a schedule - hourly is typical - and it still only reads. It is a single binary with no runtime to install.

It sees more of the Windows registry as Administrator, and other users’ processes on Linux with sudo. It works without either, with a smaller picture. That trade-off is yours to make.

An MDM tells you the device is enrolled and managed. This tells you which library on it has a known exploit and which version fixes it. Most teams keep both.

Get started

Start with your own numbers.

Connect one account. The first scan finishes in about 15 minutes and the report is yours either way - free, no credit card, no sales call. Read it, then decide.

sales@dedups.ai - we reply within 2 hours