<h2 style="margin-top: 0px; margin-bottom: 10px;">What is included in Bitdefender GravityZone Patch Management Add-On?</h2>
<p style="margin-top: 0px; margin-bottom: 0px;"><strong>Patch scanning</strong> – Finds missing operating system and application patches on endpoints.<br /> <strong>Automatic patch deployment</strong> – Installs approved patches during scheduled maintenance windows.<br /> <strong>Patch inventory</strong> – Lists every patch with severity, category and CVE references.<br /> <strong>Patch caching server</strong> – Relay endpoints store patches locally and reduce internet traffic.<br /> <strong>Patch status reporting</strong> – Reports installed, missing and failed patches for each endpoint.<br /> <strong>Important</strong> – This add-on requires an existing GravityZone endpoint security product.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">What are the main benefits of Bitdefender GravityZone Patch Management Add-On?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">GravityZone Patch Management is an optional add-on module that adds operating system and third-party application patching to an existing Bitdefender GravityZone endpoint security deployment. It is managed centrally from the same GravityZone console, agent and policy as the other modules, in both cloud and on-premises installations.<br /><br /> <strong>One agent</strong> – Patching uses the same agent, console and policy.<br /> <strong>Controlled rollout</strong> – Install patches on a test group before wider deployment.<br /> <strong>Separate schedules</strong> – Security and non-security patches run on independent schedulers.<br /> <strong>Patch exclusions</strong> – Ignore individual patches that break business-critical applications.<br /> <strong>Lower bandwidth use</strong> – Cached patches stop every endpoint downloading from vendor sites.<br /> <strong>Reboot control</strong> – Restarts can be postponed so users are not interrupted.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which company size is Bitdefender GravityZone Patch Management Add-On suitable for?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The decisive question is not headcount but whether GravityZone is already in use and whether anyone has to prove that patching happens. A company with twenty endpoints and no dedicated IT staff benefits from the automation; a company that answers customer audits benefits from the reporting. Server estates shift the calculation, because file, database and application servers are where deferred reboots and untested patches cause the most damage.</p>
<table style="width: 100%; border-collapse: collapse; background-color: #efefef; margin-top: 15px; margin-bottom: 15px; font-size: 14px; line-height: 1.35;">
<tbody>
<tr><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: left; font-weight: bold; background-color: #dedede;">Requirement</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Small business</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Medium-sized company</th><th style="border: 1px solid #ffffff; padding: 9px 8px; text-align: center; font-weight: bold; background-color: #dedede;">Large company</th></tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Reporting obligation Switzerland</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">NIS 2 in the European Union</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Rarely</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">By sector</td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Security questionnaire from large customers</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Occasional</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">Auditable patch evidence per device</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">Useful</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
<tr>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: left; font-weight: bold; vertical-align: middle;">This product fits</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;">If GravityZone used</td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
<td style="border: 1px solid #ffffff; padding: 8px; text-align: center; vertical-align: middle;"><span style="color: #32a852; font-size: 24px; font-weight: 800; line-height: 1; display: inline-block; transform: translateY(1px);">✓</span></td>
</tr>
</tbody>
</table>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-server-2025-vs-2022-vs-2019"><strong>Windows Server 2025 vs. 2022 vs. 2019: Is the Upgrade Worth It?</strong><br />Compares the server versions and support timelines, which decides how long a server can still receive the patches this module deploys.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Patch Management Add-On meet the requirements of Swiss cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">The reporting obligation under the revised Information Security Act applies to operators of critical infrastructure, not to every Swiss company, so most buyers of this add-on are affected indirectly, through customers and contracts, rather than directly. Organisations that are covered must report a cyberattack to the Federal Office for Cybersecurity (BACS) within 24 hours of discovery. Patch Management supports that duty in a narrow but concrete way: the Network Patch Status report records which endpoints were missing which CVE-referenced patches and when those patches were installed, which is the dated evidence you need when reconstructing how an attacker got in. What it does not do is detect the incident, write the report or notify BACS, and it produces no security telemetry of its own, so detection requires EDR, XDR or a managed service alongside it. It also does nothing for the organisational half of the duty, such as defining who decides that an event is reportable and who sends the report inside the 24-hour window. This information is a general orientation and does not constitute legal advice.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Patch Management Add-On meet the requirements of European cybersecurity legislation?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No product makes an organisation NIS 2 compliant, because the directive addresses management responsibility and documented processes as much as technology. NIS 2 requires risk management measures across categories including risk analysis and security policies, incident handling, business continuity and backup, supply chain security, secure acquisition, development and maintenance including vulnerability handling, cyber hygiene, access control, cryptography and multi-factor authentication. Patch Management maps substantially onto one of those categories, vulnerability handling and basic cyber hygiene, by turning known vulnerable software versions into a scheduled and documented remediation task instead of an occasional manual job. It also contributes to the requirement to assess whether measures are effective, because patch compliance is one of the few security properties that can be reported as a number and tracked over time. It covers none of the remaining categories, so incident handling, backup and recovery, supply chain assessment, access control, encryption and staff training must be answered by other modules and by written procedures.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does Bitdefender GravityZone Patch Management Add-On help with security questionnaires from large customers?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes, for one block of a typical questionnaire, and not for the rest. It answers the vulnerability and patch management items directly: whether patching is centrally managed, how often systems are scanned for missing patches, how quickly security patches are deployed, whether third-party applications are covered alongside the operating system, and whether patch status can be evidenced per device. The Network Patch Status report is usually sufficient to attach as evidence, and the public API returns installed and missing patches if the questionnaire asks for raw data rather than a PDF. It answers nothing about incident detection and response, log retention, backup and recovery, device encryption, access control and multi-factor authentication, or supplier management, because none of those are functions of this module. Where those gaps have to be closed, staying inside the same GravityZone family is normally cheaper than adding a second vendor: full disk encryption, mobile security and EDR or XDR attach to the same console, which keeps one agent, one policy model and one set of reports for the auditor to read.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="data-loss-backups-avoid-outages"><strong>Data Loss Is Expensive: How Backups Help You Avoid Outages</strong><br />Explains the backup and recovery questions that appear in customer questionnaires and that patch management does not answer.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Which limitations should you know before buying?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Rollback is the limitation with the most practical consequences: GravityZone can restore the previous state only on Windows endpoints and only for patches that support rollback, so on macOS and Linux, and for Windows patches without rollback support, a bad update has to be uninstalled or reinstalled by hand. Third-party patching is limited to the vendors and products in Bitdefender's supported catalogue, which means in-house software and niche line-of-business applications still need their own update route. Bitdefender documents disabling Windows automatic updates on managed endpoints so that patch timing is genuinely controlled by your maintenance windows rather than by Microsoft's schedule, and that configuration change is worth planning before rollout rather than after. Patches classed as manually approved, such as Windows feature updates, still require deliberate action and will not install unattended. The module patches software on managed endpoints only, so network appliances, firmware and unmanaged devices stay outside its scope and outside its reports.</p>
<p style="margin-top: 15px; margin-bottom: 15px;"><a href="#" target="_blank" data-ke-doc="windows-10-support-end-2026-option"><strong>End of Support for Windows 10: What Your Options Are</strong><br />Sets out what happens when an operating system stops receiving vendor patches, which no patch management tool can compensate for.</a></p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Frequently asked questions about Bitdefender GravityZone Patch Management Add-On</h3>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does the add-on work with the on-premises GravityZone console?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The module is managed from the same GravityZone console customers already use, for both the cloud and the on-premises deployment. It is added to existing endpoints by creating an installation package in the console rather than by rolling out a separate agent.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">How are patches distributed inside the network?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">An endpoint with the Relay role can additionally take the Patch Caching Server role, which stores patches on the local network and serves them to the other endpoints. If the caching server is unavailable, endpoints fall back to downloading from the vendor websites, so patching continues but uses more internet bandwidth.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Can patch data be exported to other systems?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">Yes. The GravityZone public API returns installed and missing patches, and maintenance windows can be created, updated and assigned through the API as well. That is the usual route when patch status has to feed an existing reporting or ticketing system instead of being read in the console.</p>
<h3 style="margin-top: 30px; margin-bottom: 10px;">Does it also cover risks that have no patch?</h3>
<p style="margin-top: 0px; margin-bottom: 0px;">No. This module identifies and installs available patches for operating systems and applications. Misconfigurations, risky settings and risky user behaviour are handled by GravityZone Risk Management, which is a separate part of the platform and not included in this add-on.</p>
<div class="ke-block mceNonEditable" data-ke-block="blogteaser" data-topics="sec-patch,sec-console" data-audience="b2b" data-count="3"> </div>