Ah answered my own question.
The SSU is a pre-requisite for the monthly CU and does not require a reboot.
In addition, our Software Update Policy is set to install updates at a specific point in time.
So turns out the only update that was "found" by our 2016 agents is the SSU which it faithfully applied and because a reboot was not required (SUP is set to reboot only when needed by an update) that was all that happened.
Now to figure out how to trigger the SSU to install and immediately after install the CU without having to wait for the patch assessment and the SMP to do its filter updates.