Vanta helps you stay on top of vulnerability management by automatically calculating SLA (Service Level Agreement) deadlines based on when each vulnerability is detected. This article explains how SLA timing works, how you can customize it, and where to track your performance.
Vanta calculates vulnerability SLAs using the detection date, the moment we first identify a vulnerability in your infrastructure. This approach ensures consistency and accurate tracking across your remediation workflows.
Key Elements of SLA Calculation
Detection Date
The SLA clock starts ticking as soon as Vanta detects a vulnerability. This date serves as the baseline for calculating the remediation deadline.
SLA Settings
You can customize your SLA windows in Vanta's Vulnerability Settings. Choose to follow or create your own based on your organization’s policies and risk tolerance.
New vs. Existing Vulnerabilities
Changes to SLA settings only affect newly detected vulnerabilities. Existing or historical vulnerabilities will retain the SLA deadline that was in place at the time they were detected.
Tracking & Accountability
All SLA compliance activity is logged in the History tab of the vulnerability, where you’ll find a clear view of on-time remediations and SLA misses.
Deadline Field
The
remediateByDate
field in our system displays the exact due date for each vulnerability, based on your active SLA configuration at the time of detection.