SOP templatesIT

Patch Management SOP Template

A ready-to-use SOP for identifying, testing, deploying and verifying security patches across servers, workstations and network devices.

FreeNo sign-upWord, PDF, Excel & CSV
Ilia PirozhenkoReviewed by Ilia Pirozhenko, Founder, Perfect WikiUpdated September 15, 202612 steps4 roles3 min read
Standard operating procedureSOP-IT-007 ยท Rev 1.0
Owner
IT Security Manager
Effective date
September 15, 2026
Review cycle
Every 6 months

1.Purpose

To keep operating systems, applications and firmware current with security patches on a regular cadence, reducing exposure to known vulnerabilities while minimizing disruption to production systems.

2.Scope

Applies to patching servers, workstations, laptops and network devices, from advisory monitoring through testing, deployment and compliance verification, including expedited handling of critical vulnerabilities. Broader configuration changes follow the change management SOP.

Definitions

Critical vulnerability
A security flaw with a high likelihood of exploitation and severe impact, requiring expedited patching.
Patch window
The scheduled time during which patches are deployed to a group of systems.
Patch ring
A defined batch of systems that receive a patch together, often ordered from lowest to highest risk.
Compliance rate
The percentage of in-scope devices that have received a given patch.

3.Responsibilities

System Administrator
Tests patches, deploys them in batches, and remediates devices that miss the patch window.
IT Security Manager
Classifies patch severity, verifies compliance, and reports results.
Change Manager
Approves the patch deployment window as a standard or normal change.
End User
Restarts or makes their device available for patching when notified.

RACI matrix

ActivitySystem AdministratorIT Security ManagerChange ManagerEnd User
Classify patch severityCR/AI-
Test patches before deploymentR/ACI-
Approve the deployment windowCCR/AI
Deploy and monitor patchesR/AIII
Verify and report patch complianceRR/AI-

R = Responsible, A = Accountable, C = Consulted, I = Informed

4.Materials and PPE

Materials, tools and systems

  • โ†’Patch management console
  • โ†’Vulnerability advisory feeds
  • โ†’Test or staging environment
  • โ†’Patch compliance dashboard
  • โ†’Change request for the patch cycle

5.Procedure

  1. 5.1

    Monitor vulnerability advisories

    System Administrator

    The System Administrator monitors vendor and vulnerability advisory feeds daily for newly released patches affecting in-scope systems.

  2. 5.2

    Classify patch severity

    IT Security Manager

    The IT Security Manager classifies each patch by severity, flagging any critical vulnerability for expedited handling outside the regular cycle.

    Checkpoint: Every new advisory is reviewed and assigned a severity classification within one business day of release.

  3. 5.3

    Test patches on non-production systems

    System Administrator

    The System Administrator deploys the patch to a representative sample of non-production systems and checks for functional issues before wider rollout.

    Warning: Never deploy an untested patch broadly to production, even under time pressure from a critical advisory.

  4. 5.4

    Submit the patch cycle for approval

    Change Manager

    The Change Manager approves the regular patch cycle as a standard change, or fast-tracks a critical patch through the expedited emergency change path.

  5. 5.5

    Schedule and notify

    System Administrator

    The System Administrator schedules the patch deployment window and notifies affected users of any expected restarts or downtime.

  6. 5.6

    Deploy patches in batches

    System Administrator

    The System Administrator deploys patches to production systems in defined rings, starting with lower-risk systems before moving to critical ones.

  7. 5.7

    Monitor for post-patch issues

    System Administrator

    The System Administrator monitors system health and the incident queue after each deployment ring for signs of a patch-related problem.

    Checkpoint: No new critical incidents are linked to the deployment before the cycle is marked complete.

  8. 5.8

    Roll back a problem patch

    System Administrator

    If a patch causes a service-impacting issue, the System Administrator rolls it back on the affected systems immediately and pauses further rollout.

  9. 5.9

    Verify patch compliance

    IT Security Manager

    The IT Security Manager checks the patch management console to confirm which in-scope devices successfully received the patch.

  10. 5.10

    Remediate missed devices

    System Administrator

    The System Administrator follows up on devices that did not receive the patch within the defined grace period, such as offline laptops, and forces the update.

  11. 5.11

    Document the cycle results

    IT Security Manager

    The IT Security Manager documents the patch cycle results, including any exceptions and the final compliance rate.

  12. 5.12

    Report compliance monthly

    IT Security Manager

    The IT Security Manager reports patch compliance trends to the Change Manager and leadership on a monthly basis.

6.Quality checks

  • โ†’Critical vulnerabilities are patched within the defined expedited timeframe.
  • โ†’Patches are tested on non-production systems before broad deployment.
  • โ†’Patch compliance rate is tracked and reported on a monthly basis.
  • โ†’Every patch cycle has a rollback path ready before deployment begins.

7.Records

  • โ†’Patch test results
  • โ†’Change request or approval for the patch cycle
  • โ†’Patch compliance report
  • โ†’Rollback or incident record, if applicable

8.KPIs

  • โ†’Patch compliance rate across in-scope devices
  • โ†’Mean time to patch critical vulnerabilities
  • โ†’Number of rollbacks per patch cycle
  • โ†’Percentage of devices patched within the grace period

9.Common mistakes

  • โ†’Deploying a patch to every production system at once instead of using rings.
  • โ†’Waiting for the next monthly cycle to address a critical vulnerability.
  • โ†’Not tracking which devices missed the patch window.
  • โ†’Having no rollback plan ready before deploying a patch.

10.Revision history

RevisionDateDescriptionReviewed by
1.0September 15, 2026Initial releaseIlia Pirozhenko

This is a template. Adapt it to your organization, equipment and local regulations before use.

Ask this SOP

Nobody opens a PDF in the middle of a task. They ask.

Add this SOP to Perfect Wiki and your team gets answers in the chat app they already use, with a link to the exact step. Ask from ChatGPT, Claude or Copilot too.

Perfect Wiki AIExample answer

A critical zero-day patch just came out, do we wait for the next monthly cycle?

No. Step 5.2 requires classifying it as critical and routing it through the expedited emergency change path rather than the regular monthly cycle, after a quick test on non-production systems.Source: step 5.2 ยท Classify patch severity
Ask your own question about this SOPโ€ฆSign up to keep asking
Word file vs Perfect Wiki

A downloaded SOP starts going out of date the day you save it.

Screen recorders like Scribe and Tango capture clicks. Perfect Wiki holds the whole procedure, including your recorded guides, and answers questions about it.

Word or PDFPerfect Wiki
Finding itDig through folders and email threadsAsk in Teams, Slack, kChat or Mattermost
Keeping it currentEmail a new version and hopeEdit once with AI, everyone sees the update
Everything in one placeText and imagesEmbed Scribe and Tango guides, SharePoint files and videos
Who can change itAnyone with the fileEditors you choose, everyone else reads
Common questions

Frequently asked questions

Didn't find what you're looking for? Contact our support โ†’

Your SOP library

Keep every SOP where your team can ask it.

Perfect Wiki is the knowledge base for Microsoft Teams, Slack, kChat and Mattermost. Store your SOPs, embed your Scribe and Tango guides, and let AI answer questions with a link to the right step.

No credit cardSetup in under 10 minutesCancel anytime