Skip to main content

Compliance & Exceptions

Patch Management combines CMDB context, vulnerability data, and patch status to calculate compliance against your baselines and SLAs. Where patches cannot be applied, exceptions capture the rationale, scope, and review dates, so you can demonstrate risk is understood and actively managed.

This section explains how to track patch policy compliance across your estate and document justified deviations, such as temporary exceptions or risk acceptances.

Compliance Reporting

Evaluate patch SLA adherence, coverage, outstanding patch age, exception impact, and compliance evidence across teams, applications, environments, and accounts.

Exceptions & Risk Acceptance

Manage patching exceptions and exclusions when systems cannot be patched within standard SLAs.