Work out patch sla compliance instantly with clear inputs, formula shown and shareable results.
Patch SLA compliance is the share of in-scope findings remediated inside the agreed window, and it is the metric auditors and regulators most often ask for. The useful companion figure is how many additional on-time remediations would close the gap to target, because that converts a percentage into a work item count the team can plan against.
SLA compliance
compliance = patched within SLA / total in scope; extra needed = ceil(total x target) - patched on time
Only if the acceptance was not formally approved. Documented, time-bound exceptions are normally excluded from the denominator, but undocumented ones are breaches.
Because remediation effort is finite. Typical tiers are 7 days for critical, 30 for high and 90 for medium, which concentrates urgency where exploitation is most likely.