Skip to main content

SLA settings

To keep discovered vulnerabilities from being left unaddressed, your organization needs to decide "by when must this be fixed." Setting per-severity deadlines (SLA) as policy automatically highlights items that have passed their deadline, so you never lose track of priorities.

Configuration

  • Set a remediation deadline (in days) for each severity (critical/high/medium/low).
  • KEV (actively exploited) items can have a shorter deadline separate from the severity deadline. The stricter of the two applies.

SLA settings screen

Permissions

  • Admins/managers edit these settings.
  • Members view them as read-only.

In practice

Items past their SLA are highlighted as overdue, making it clear what to handle first. Mean time to remediate (MTTR) is tracked in Security score.

Next steps