Remediation Progress Calculator
Track backlog burn-down: closure and intake rates, net change, current backlog and how long until you reach your target.
Inputs
Backlog Now
435findings
Net Change This Period
45findings
Closure Rate
7.00per day
Net Burn Rate
1.50per day
Closure Ratio
127.3%
Days to Reach Target
157days
Trajectory
Shrinking — target reached in about 157 days at the current rate
Step by step
Values used
Backlog at the start of the period = 480 findings; Findings closed in the period = 210 findings; New findings in the period = 165 findings; Length of the period = 30 days; Target backlog = 200 findings
Remediation Progress
Backlog now = starting backlog + new findings − closures. Net burn rate = (closures − new findings) ÷ period days, and days to target = (backlog − target) ÷ net burn rate.
Closure ratio
Closure ratio = closures ÷ intake. Below 100% the backlog grows no matter how many findings your team closes.
Backlog Now
= 435 findings
Net Change This Period
= 45 findings
Closure Rate
= 7.00 per day
Net Burn Rate
= 1.50 per day
Closure Ratio
= 127.3
Days to Reach Target
= 157 days
How it works
The number that matters is the net rate, not the closure count. A team closing 210 findings a month looks productive until you notice 165 arrived in the same month, leaving a net of 45 and a ten-month path to target. When the net rate is zero or negative, no amount of extra effort in the same mode will clear the backlog — the intake side has to change, usually through golden images, base-image patching or dependency upgrades. Backlog burn-down is the metric that shows whether your programme is actually improving or just running hard, and the days-to-target figure is what justifies automation spend.
Formulas
Remediation Progress
Backlog now = starting backlog + new findings − closures. Net burn rate = (closures − new findings) ÷ period days, and days to target = (backlog − target) ÷ net burn rate.
- net burn rate
- Findings removed from the backlog per day, net of intake
- closure ratio
- Closures ÷ new findings; above 100% means the backlog shrinks
- target
- Backlog size you are aiming for
Closure ratio
Closure ratio = closures ÷ intake. Below 100% the backlog grows no matter how many findings your team closes.
Frequently Asked Questions
How is Remediation Progress calculated?
Backlog now = starting backlog + new findings − closures. Net burn rate = (closures − new findings) ÷ period days, and days to target = (backlog − target) ÷ net burn rate. The number that matters is the net rate, not the closure count. A team closing 210 findings a month looks productive until you notice 165 arrived in the same month, leaving a net of 45 and a ten-month path to target. When the net rate is zero or negative, no amount of extra effort in the same mode will clear the backlog — the intake side has to change, usually through golden images, base-image patching or dependency upgrades.
Why does Remediation Progress matter?
Backlog burn-down is the metric that shows whether your programme is actually improving or just running hard, and the days-to-target figure is what justifies automation spend.
What values do I need to enter?
This calculator takes 5 inputs: Backlog at the start of the period, Findings closed in the period, New findings in the period, Length of the period, Target backlog. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why is my backlog growing when the team is closing more than ever?
Because intake grew too, usually from new scan coverage, new assets or a noisy new plugin. Split intake into genuinely new exposure and newly visible existing exposure — the second kind is a one-off bulge and should be tracked separately.
Should the target backlog be zero?
No. A healthy programme runs a small steady-state backlog of low-severity findings; zero is achievable only by suppressing aggressively. Set the target from the volume you can hold within SLA, and keep criticals at zero instead.
You might also need
- Security Debt CalculatorCommonly used together
- Mean Time to Patch CalculatorCommonly used together
- Patch Compliance CalculatorCommonly used together
- Patch Priority CalculatorAlso in Vulnerability Management
- Vulnerability Health Score CalculatorAlso in Vulnerability Management
- CVSS v3 Score CalculatorAlso in Vulnerability Management