Patch Gap Glossary
Patch Gap
The patch gap is the lag between the availability of a security fix and its effective deployment across the systems that need it.
A patch can exist while exposure continues. Organizations may not know which systems are affected. Testing may be slow. Legacy software may be incompatible. Devices may be offline, unmanaged, or too important to interrupt. Some operators simply postpone the work.
The patch gap matters because automated vulnerability discovery does not automatically produce automated safety. AI may shorten the time required to find and repair a flaw while leaving distribution, testing, asset inventory, and institutional delay untouched. Attackers operate inside that remaining gap.
NIST describes enterprise patching as a process of identifying, prioritising, acquiring, installing, and verifying updates. The sequence matters: the release of a patch begins the operational work; it does not complete it.
Source
- NIST, Guide to Enterprise Patch Management Planning, SP 800-40 Rev. 4 (2022).