Patch cadence calendar: what patches when, on one page

Patching fails at small teams not because anyone disagrees with it, but because it has no when. "We patch when we get to it" means the scary updates happen during incidents and the boring ones never happen at all. The patch management checklist covers what to patch; this page covers the cadence — the four lanes that sort every patch by urgency, the calendar anchors that survive busy weeks, the deferral card that keeps skipping honest, and the one-page report that proves the machine is running. The whole system fits on one calendar page and costs nothing but a recurring block of an afternoon.

1. The four lanes: every patch lands in exactly one

2. Calendar anchors that survive busy weeks

3. The deferral card: skipping is legal, silent skipping is not

4. The vendor EOL watch: the calendar item nobody schedules

5. The one-page evidence report

Small-team honesty note: a five-person company does not need a patch management platform; it needs a recurring calendar event and a log file. This page's entire system is four lanes, three anchors, a four-line deferral card, and one evidence page. The trap this page exists to prevent is cadence theater — a beautiful policy document with no calendar entry behind it. If the PATCH WAVE event is not in your calendar as you read this, the cadence does not exist yet. Put the event in, run the first wave ugly, and let the system make itself real.

Related: patch management checklist · change freeze window policy · asset inventory checklist · backup restore test · severity matrix · weekly status report · vendor outage runbook · vendor escalation ladder · SLA/SLO definition · postmortem template · status page template · first 30 minutes · new admin's first week