Skip to main content

How Vanta Calculates Vulnerability SLAs

S
Written by Shannon DeLange
Updated this week

Vanta helps you stay on top of vulnerability management by automatically calculating SLA (Service Level Agreement) deadlines based on when each vulnerability is detected. This article explains how SLA timing works, how you can customize it, and where to track your performance.

Vanta calculates vulnerability SLAs using the detection date, the moment we first identify a vulnerability in your infrastructure. This approach ensures consistency and accurate tracking across your remediation workflows.

Key Elements of SLA Calculation

  • Detection Date

    • The SLA clock starts ticking as soon as Vanta detects a vulnerability. This date serves as the baseline for calculating the remediation deadline.

  • SLA Settings

    • You can customize your SLA windows in Vanta's Vulnerability Settings. Choose to follow or create your own based on your organization’s policies and risk tolerance.

  • New vs. Existing Vulnerabilities

    • Changes to SLA settings only affect newly detected vulnerabilities. Existing or historical vulnerabilities will retain the SLA deadline that was in place at the time they were detected.

  • Tracking & Accountability

    • All SLA compliance activity is logged in the History tab of the vulnerability, where you’ll find a clear view of on-time remediations and SLA misses.

  • Deadline Field

    • The remediateByDate field in our system displays the exact due date for each vulnerability, based on your active SLA configuration at the time of detection.