What are the key benefits of Avast Business Patch Management?
Central console – Managed entirely from the Avast Business Hub.
Windows patching – Covers Windows workstations and Windows Server versions.
Third-party apps – Patches over 150 software vendors automatically.
Severity control – Deploy by CVSS score and patch severity.
Bandwidth saving – One master agent distributes patches internally.
Important note – No macOS patching and no antivirus included.
Windows patch automation – Scans and deploys Windows updates on a set schedule.
Third-party application patching – Covers over 150 vendors including Chrome, Java and Adobe.
Business Hub console – Central patch dashboard, policies, alerts and scheduled deployment.
CVSS severity data – Every patch carries a CVSS score and severity rating.
Master agent distribution – One device downloads patches and shares them internally.
Important – No macOS patching and no malware protection included.
Avast Business Patch Management is an add-on service for the cloud-based Avast Business Hub that keeps Windows and third-party software up to date across all managed devices, and it is also included in the Avast Ultimate Business Security bundle. It takes over the job of the older Software Updater component that earlier versions of the Avast Cloud Console and CloudCare provided, which Avast documents should be disabled or removed before Patch Management is deployed.
Faster vulnerability closure – Critical patches reach every device without manual rollouts.
Controlled deployment windows – Schedule scans and installs outside working hours.
Application exclusions – Block patches for fragile line-of-business software.
Rollback and ignore – Remove an unstable patch or skip it entirely.
Patch alerts – Notifies on missing, failed and restart-pending patches.
Antivirus independence – Runs alongside another vendor endpoint protection product.
The deciding factor here is the shape of your device estate, not your headcount. The product fits organisations whose workstations and servers run Windows and that manage everything from a single Business Hub site. Mixed fleets with a meaningful number of Macs, and service providers running many customer tenants, run into its structural limits first.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | Rare | By sector | Common |
| NIS 2 in the European Union | Rare | By sector | Usually |
| Security questionnaire from large customers | Occasional | ✓ | ✓ |
| Central patching across several sites | ✓ | Limited | ✕ |
| This product fits | ✓ | ✓ | Limited |
The obligation applies to operators of critical infrastructure, not to Swiss companies in general: since 1 April 2025 the revised Information Security Act (ISG) requires affected organisations to report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery, with 14 days to complete the report. Patch Management supports that indirectly rather than directly, because the Patch report retains up to twelve months of history and shows which Windows and third-party vulnerabilities were closed, when, and on which devices. That record is exactly what you need when a report has to state whether a known unpatched vulnerability was involved. What the product does not do is detect the attack, open an incident, retain security logs or export anything to a SIEM system, and its alerts cover missing, failed and restart-pending patches only, so the 24-hour clock still depends entirely on your own detection and escalation process. This text is not legal advice; whether your organisation falls under the reporting obligation should be clarified with qualified legal counsel.
No product makes a company compliant with the NIS 2 Directive, because the directive requires organisational measures and software can only support them. NIS 2 sets out categories of measures including risk analysis and security policies, incident handling, business continuity, supply chain security, and security in the acquisition, development and maintenance of network and information systems, which explicitly covers vulnerability handling. Patch Management maps to that last category: it closes known vulnerabilities in Windows and in over 150 third-party vendors on a defined schedule and documents the outcome per device. It contributes nothing to incident handling, business continuity, cryptography, access control or multi-factor authentication, and it delivers no supply chain evidence beyond your own patch state. For every category it does not cover you need separate products and, more importantly, written processes behind them.
In February 2024 the United States Federal Trade Commission filed a complaint against Avast Limited and its subsidiaries concerning the collection and sale of browsing data between 2014 and 2020 through the subsidiary Jumpshot, and finalised the consent order in June 2024. The order requires a payment of 16.5 million US dollars, prohibits the sale or licensing of browsing data from Avast products for advertising purposes, and requires a privacy programme assessed by an independent reviewer for twenty years; it remains in force, and the FTC opened a consumer refund claims process in February 2025. Avast stated that it voluntarily closed Jumpshot in January 2020 and that it disagrees with the allegations and the characterisation of the facts, while settling the matter. The case concerned consumer browser extensions and consumer antivirus software rather than the business patch management service, and Avast continues to list independent test results for its business endpoint products, including an AV-Comparatives Approved Business Security award from July 2024 and an AV-TEST Approved Corporate Endpoint Protection certification from April 2025. In practice this matters most to buyers with public sector contracts or supply chain questionnaires that ask about regulatory actions against a vendor, where the order has to be disclosed and explained; for other buyers it is a documented past data-handling issue to weigh alongside the product itself.
Yes, for the patch and vulnerability-remediation block of a questionnaire, and for very little outside it. It answers whether you have a documented patching process, how often you scan, on what schedule you deploy, whether third-party applications are covered and not just Windows, how you prioritise by risk through the CVSS score and severity rating, how exceptions are handled through documented policy exclusions and ignored patches, and it produces per-device evidence with up to twelve months of history. It answers none of the following: endpoint malware protection, EDR, encryption, multi-factor authentication, backup, log retention or SIEM export, vulnerability scanning beyond software the patch engine recognises, coverage of macOS, Linux or mobile devices, and anything on access control, staff training or incident response. If the open items are mainly endpoint protection, ransomware protection, USB and web control, moving up to Avast Ultimate Business Security inside the same family is usually cheaper and administratively simpler than adding a second vendor, because it contains this same patch service and stays in one console. Encryption, multi-factor authentication and log export are not solved by any edition of this family, so plan those as separate line items rather than hoping an upgrade will absorb them.
The decisive difference is that the add-on contains no malware protection whatsoever. Avast Business Patch Management is a single-purpose service you activate in the Business Hub, which makes it the right choice when another vendor already protects your endpoints and you only want to solve patching. Ultimate Business Security is the full bundle and includes exactly the same patch service alongside next-generation antivirus, ransomware and data protection, web control, USB protection and a VPN. Both are administered in the same console, and both patch Windows only.
| Capability | Patch Management add-on | Ultimate Business Security |
|---|---|---|
| Windows and third-party patching | ✓ | ✓ |
| Next-generation antivirus | ✕ | ✓ |
| Ransomware and data protection | ✕ | ✓ |
| USB protection and Web Control | ✕ | ✓ |
| macOS patching | ✕ | ✕ |
Platform coverage is the limitation that decides most purchases: the service runs on Windows workstations and Windows Server only, so Macs in a mixed fleet stay untouched by it and need a second tool. Two further gaps catch buyers out regularly, because the service deploys neither Windows feature updates nor Microsoft Extended Security Update patches, which is relevant for anyone still running an operating system past its normal support date. It also expects to own the update process, so Windows Update has to be reconfigured on the target devices to stop fetching updates itself, and the service requires the cloud-based Business Hub rather than the on-premises console. For managed service providers there is no centralised patching at partner or multi-tenant level, since patches are viewed and managed per customer site, which turns into real administrative effort across many tenants. We found no indication of country-specific or region-specific feature restrictions for this product; the constraints that matter here are platform-related.
Yes. Avast documents that Patch Management works with other antivirus vendors as long as the other product permits the required communication. That is the usual setup when patching is bought separately from endpoint protection.
You do not disable the Windows Update service itself, but you reconfigure it on the target devices so that it stops checking for and installing updates on its own. Patch Management then drives deployment centrally, and Avast publishes the recommended settings for this in its knowledge base.
You can roll the patch back from the affected devices, or set it to ignored so it no longer appears in the patch results and is not redeployed. Ignored patches can be reverted later, and whole vendors or products can be placed on a policy exclusion list so their patches stop being installed.
Every patch carries a type, a severity rating from None through Low, Moderate and Important to Critical, and a CVSS score out of ten. You can sort and filter on those values, so patch decisions follow measured risk rather than release date.