For devices stuck on Windows 10 IoT, RHEL 7, end-of-life kernels, or unsupported chipsets. Score the residual risk, capture the compensating controls, and export a memo a reviewer will accept.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
Risk factors present
Compensating controls in place
What you'll see after you submit
Common misconceptions
Myth: EOS components are an automatic submission blocker.
Reality: They aren't - but only if you document the residual risk and the compensating controls in a way the reviewer can verify. Hand-waving gets a deficiency letter.
Myth: A vendor LTS contract is enough on its own.
Reality: It's a strong control, but reviewers also want to see segmentation, monitoring, and an exit plan with a date.
References & further reading
Tracked signals that change what reviewers expect. Items move on as new ones land.
RHEL 7 Extended Life Support phase ends - devices on RHEL 7 need a compensating-controls memo
CISA adds use-after-free in Linux kernel netfilter to KEV (CVE-2026-0511)
AI-letter analysis - 62% of FDA cyber deficiencies cite a missing or stale CVD URL
SLSA v1.1 published - tightened build-provenance language for regulated industries
Hands-on support to put the controls in place.
Read Legacy device cybersecurity servicesShow the threats the controls mitigate.
Read Threat Model StarterSet the monitoring SLA that backs up the memo.
Read Postmarket Cadence Calculator