What are the core benefits of AVG Patch Management Business Edition?
Central console – Managed only from the AVG Cloud Management Console.
Third-party patching – Covers Windows and over 150 software vendors.
Scheduled deployment – Scans and patches run daily, weekly or monthly.
Bandwidth control – One Update Agent distributes patches across the network.
Patch evidence – Reports show missing, installed and failed patches.
Important note – Windows only, no macOS or Linux patching.
Download: AVG Patch Management Business Edition
Patch scanning – Scheduled or manual scans for missing OS and application patches.
Automatic patch deployment – Approved patches install on schedule or on demand.
Third-party application coverage – Patches from more than 150 software vendors, Windows included.
Exclusions and severity filters – Block patching per vendor, product or severity level.
Patch reporting – Patch history for evidence, up to twelve months.
Important – No macOS or Linux patching and no rollback.
AVG Patch Management Business Edition is an add-on service for the AVG Cloud Management Console that scans Windows devices for missing operating system and third-party patches and deploys them centrally. It takes over from the older Software Updater component that earlier Cloud Console and CloudCare versions provided, which AVG asks you to remove from devices first.
One patch queue – OS and application patches handled in one place.
Fewer manual updates – No per-device visits or user-driven update prompts.
Bandwidth saving – One Update Agent downloads and distributes patches internally.
Risk prioritisation – Each patch shows severity and a CVSS score.
Controlled restarts – Restart behaviour after patching is set by policy.
Server separation – Servers can run a separate patch policy.
Company size decides how much administrative effort the product saves, but sector decides whether patch evidence is legally required. The deciding technical question is simpler: how much of your device fleet runs Windows, because everything else stays unpatched by this add-on.
| Requirement | Small business | Medium-sized company | Large company |
|---|---|---|---|
| Reporting obligation Switzerland | By sector | By sector | Common |
| NIS 2 in the European Union | Rare | By sector | Usually |
| Security questionnaire from large customers | Sometimes | Often | Standard |
| Windows-only device fleet | Common | Mixed | Rare |
| This product fits | ✓ | ✓ | Limited |
No software product meets those requirements on its own. The reporting obligation introduced by the revised Information Security Act has applied since 1 April 2025 and covers operators of critical infrastructure, among them cantonal and communal administrations, energy and water suppliers, transport and health organisations, who must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovering it. Patch Management supports the preparation side of that duty: its patch report shows per device which operating system and application patches were missing or installed on a given date, so the question of whether a known vulnerability was still open at the time of an incident can be answered from records rather than from memory. It does not detect attacks, does not generate the report to BACS, and produces no attack timeline, all of which require detection and logging that this add-on does not contain. It also covers only Windows devices, so a Linux server or a Mac in scope stays outside the evidence trail. This text is general product information and not legal advice.
No product creates NIS 2 compliance, because the directive addresses the organisation and not the software it buys. NIS 2 requires entities in scope to apply risk management measures across several categories, including the handling of vulnerabilities, security in the acquisition and maintenance of network and information systems, incident handling with reporting duties, business continuity, supply chain security and policies for assessing whether the measures work. AVG Patch Management Business Edition addresses one of these directly by keeping Windows operating systems and third-party applications maintained and by recording which patches were applied and when. It does nothing for incident handling, continuity planning, supply chain assessment, access control, encryption or staff training, and it leaves macOS and Linux systems entirely unaddressed. Entities running mixed operating systems need a second patching mechanism alongside it.
AVG is a brand of Gen Digital, the group formed from Avast and NortonLifeLock. Two authorities have decided cases against Avast Limited and its subsidiaries concerning browsing data collected between 2014 and 2020 through consumer antivirus software and browser extensions and passed to the subsidiary Jumpshot. In the European Union, the Czech data protection authority, acting as lead supervisory authority under the GDPR, imposed a fine of roughly EUR 13.7 million; that decision became final in 2024 after the company's appeal was rejected. In the United States, the Federal Trade Commission finalised an order in June 2024 that bans the sale or licensing of browsing data for advertising purposes, requires a privacy programme with independent assessments for twenty years and a payment of USD 16.5 million; those obligations are still running. Avast has stated that it closed Jumpshot voluntarily in January 2020 and that it disagrees with the FTC's allegations and characterisation of the facts, while choosing to settle the matter. Neither decision restricts the sale or use of AVG business products in Switzerland or the European Union, and neither concerned the Cloud Management Console or the patching service; both concerned the past handling of consumer browsing data. In practice this matters where a public sector tender or a supply chain questionnaire asks whether regulatory decisions exist against a supplier, because the honest answer is yes and you should be able to describe the scope and the dates.
Yes, for the patch and vulnerability-remediation questions, and only for the Windows part of your fleet. It answers items such as whether operating system and application updates are deployed centrally, on what schedule scanning and deployment run, how critical updates are prioritised, and whether current patch status can be shown per device: the patch report supplies dated evidence with severity and CVSS values, and keeps history for up to twelve months. It does not answer items on endpoint detection and response, log retention or SIEM forwarding, disk encryption, mobile device management, multi-factor authentication, backup, or coverage of macOS and Linux endpoints, because none of these are part of the add-on. Two of those gaps cannot be closed inside the AVG business range at all, since it contains no EDR product and no encryption management, so a second vendor is unavoidable if a customer insists on them. Email and Exchange scanning is the exception you can keep in the family, by choosing AVG Internet Security Business Edition as the base product rather than buying a separate mail security tool.
Patch Management is an add-on service and can only be managed from the AVG Cloud Management Console, which AVG provides with its business products, so most buyers pick a base edition first. The decisive difference between the two endpoint editions is Exchange Protection: only Internet Security Business Edition scans Microsoft Exchange mailboxes for suspicious attachments, spam and links. It also adds Password Protection for credentials stored in Chrome and Firefox, while the rest of the protection set is identical in both editions. Patch Management is enabled per device in the console and behaves the same way underneath either edition.
| Component | AVG AntiVirus Business Edition | AVG Internet Security Business Edition |
|---|---|---|
| Cloud Management Console | ✓ | ✓ |
| File, Web and Email Shield | ✓ | ✓ |
| Firewall and Behavior Shield | ✓ | ✓ |
| Exchange Protection | ✕ | ✓ |
| Password Protection | ✕ | ✓ |
| Patch Management | Add-on | Add-on |
This is a Windows-only service: there is no macOS or Linux patching, and AVG describes Mac support as planned rather than available. Windows Server Core installations are outside the supported list, so a Core-based file server or Hyper-V host will not be patched by this add-on, and servers should in any case be placed in their own policy so workstation schedules do not restart them. Microsoft ESU patches are not supported, which matters for anyone keeping Windows 10 devices running on Extended Security Updates, and Windows feature updates cannot be delivered through the service either, although AVG otherwise recommends setting Windows Update to manual on patched devices. There is no patch uninstall or rollback action in the console: a patch can be installed or ignored, and an ignored patch can be returned to pending, but reversing a bad update has to happen by other means, which is why AVG's own guidance points to keeping backups. Finally, this is an add-on and not a standalone tool, so without the AVG Cloud Management Console there is nothing to run it from.
Not completely. AVG recommends setting Windows Update to manual so that quality and security updates arrive through the console instead of arriving at random on each device, but Windows feature updates cannot be installed through Patch Management and still come from Windows Update.
AVG's documentation says yes, provided the other product allows the network communication the service needs. The AVG Business Agent and the AVG Cloud Management Console are still required, because the patching service runs through the agent and is configured only in the console.
Not from the console. Patches can be installed or ignored, and an ignored patch can be set back to pending, but there is no uninstall action, so plan a test group and a working backup before large deployments.