Testing
Remediation SLAs that survive contact with an engineering backlog
Both frameworks expect vulnerabilities to be managed to closure. A policy promising 24-hour critical remediation, routinely missed, documents the miss.
Facts checked — 2026-09-11
How should you set remediation SLAs?
Set timelines the organisation can actually hit, tiered by severity and by exposure — an internet-facing critical and an internal medium are different problems. Then track against them, and record exceptions with a reason and an approver when something slips.
An auditor is not looking for perfection. They are looking for a defined process, evidence it is followed, and a defensible explanation where it was not. A tracked overrun with a decision behind it is fine; a silent one is the finding.
The bottom line
Promise timelines you can meet, then record the exceptions. A missed SLA with an approved exception is manageable; a missed SLA with no record is not.
Related services
Vulnerability Assessment and Penetration Testing (VAPT)
Find what an attacker would find, ranked by what it would actually cost you — and get a report your auditor and your engineers can both use.
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Technical testing
The OWASP Testing Guide, and how to tell a real penetration test from a scan
Two tests can cost the same and cover entirely different ground. The methodology is how you tell, and it is checkable before you pay.
Technical testing
NIST SP 800-115: the four phases, and the one that is not a phase
The four-phase shape behind most credible test methodologies — and the phase that is not fourth at all.
Testing
What a CVSS score does and does not tell you about your risk
A shared scale for technical severity — deliberately context-free, which is exactly why it is not your priority order.