Windows and macOS update themselves, and every RMM in this record can drive that better than the built-in scheduler does. What no operating system updates is the browsers, runtimes, PDF readers, conferencing clients and the hundred small applications that make up most of the exploitable surface on a normal fleet. Third-party patch management is that catalogue, and the catalogue is the entire product.
The only question that matters is the catalogue
Every vendor in this market says it does third-party patching, so the claim carries no information. The questions that do are: which applications are in the catalogue, how quickly a new release appears in it after the vendor ships it, and what the tool does with an application that is not in it. The third answer is the one to press hardest. A product that silently ignores what it cannot patch produces a green compliance report over an unpatched fleet, which is worse than no report at all, because it converts a known gap into a false assurance somebody will act on. Ask for the catalogue list and check your own top twenty applications against it before you compare prices.
Cross platform is a different requirement again
Cross platform patch management means one console patching Windows, macOS and usually Linux, and it matters to two kinds of buyer: an MSP whose clients are mixed, and an internal team with a design or engineering function on Macs. The trap is that support is rarely equal across platforms. A tool with a deep Windows catalogue and a thin macOS one is common and is sold as cross platform without qualification. If a meaningful share of your fleet is not Windows, evaluate the catalogue per platform rather than in aggregate, and weight it by what those machines actually run.
How it is priced, and what this record can evidence
At the vendors here that publish a figure, patching is inside the per-endpoint platform price rather than a separate line: NinjaOne at $1.50 to $3.75 an endpoint a month depending on volume, and Level at a flat $2 a device. Neither prices third-party patching apart, so a standalone comparison of this capability cannot be built from what they publish. Action1, the vendor most associated with a free tier in this category, answers a Cloudflare block to every reader available here, so this record carries no figure for it and will not repeat one from elsewhere. That is a real limit on this page and it is better stated than papered over.
Questions people ask about third party patch management
What is third party patch management?
Patching the applications the operating system does not update: browsers, runtimes, PDF readers, conferencing clients and similar. That catalogue is most of the exploitable surface on a typical fleet.
What should I ask a third-party patching vendor?
Which applications are in the catalogue, how fast a new release lands in it, and what the tool does with an application that is not in it. The last matters most, because silent omission produces a green report over an unpatched fleet.
Is cross platform patching really equal across platforms?
Often not. A deep Windows catalogue with a thin macOS one is common and is still marketed as cross platform. Evaluate the catalogue per platform if a meaningful share of your fleet is not Windows.
How much does third-party patching cost?
At the vendors here that publish, it is inside the per-endpoint platform price rather than a separate line: NinjaOne $1.50 to $3.75 a device, Level a flat $2. Action1's page could not be read from here.