Vanta helps you stay on top of vulnerability management by automatically calculating SLA (Service Level Agreement) due dates based on when each vulnerability is detected. This article explains how SLA timing works, how you can customize it, and where to track your performance.
​
Key elements of SLA calculation
💡 Tip: In the API, the vulnerability’s first detection timestamp is returned as firstDetectedDate. The remediation due date is returned as remediateByDate.
Detection date and time
Vanta calculates vulnerability SLAs using the exact date and time Vanta first detects the vulnerability. This timestamp serves as the baseline for calculating the remediation due date—the SLA clock starts as soon as Vanta detects a vulnerability.
To locate the timestamp:
Go to the Vulnerabilities page.
Select Findings by vulnerability.
Scroll to the First seen/Last seen column.
Select a specific vulnerability to open its details.
In the Information tab, look for First seen field to view the exact date and time.
Due date and time
The Due Date field in Vanta reflects the exact remediation due date and time for the vulnerability, based on your active SLA configuration at the time Vanta detected it.
For example, if Vanta detects a vulnerability at 1:07 PM and your SLA is 30 days, the vulnerability is due at 1:07 PM on the due date—not at the end of that calendar day.
This means a vulnerability can become overdue during the due date itself if it is not remediated before the exact due time.
SLA settings
You can customize your vulnerability SLA windows in Vanta’s Vulnerability Settings. Choose Vanta’s recommended SLA windows or create your own based on your organization’s policies and risk tolerance.
To update vulnerability SLAs:
In your account header, click the Settings icon.
In the Settings page menu, scroll to the Features section.
Select Assets.
Go to the Vulnerability remediation SLAs tab.
⚠️ Note: Changes to SLA settings only apply to newly detected vulnerabilities. Existing, currently open, or historical vulnerabilities keep the SLA due date that was in place when Vanta detected them. Updating your SLA settings does not retroactively recalculate due dates for vulnerabilities that were already detected.
Business day SLAs
If your SLA is configured using business days, Vanta still uses the exact detection time when calculating the due date.
For example, if a vulnerability is detected at 1:24 AM, it will be due at 1:24 AM on the applicable future business day. Business hours are not supported.
Tracking and accountability
Vulnerability remediation and SLA activity is tracked in the History tab of the Vulnerabilities page. This includes:
On-time remediations
SLA misses
Historical remediation activity used for audit evidence
