🚥Retesting your vulnerabilities
What is included in a retest, and how to request a retest in Portal.
The goal for many clients is to remediate reported vulnerabilities, have the remediation validated, and obtain evidence that they have done so for any stakeholders, auditors, or customers.
Depending on the size of the report and availability, Software Secured can typically support retesting within two weeks of the request being submitted. For maximum flexibility—and if you have a tight timetable—let us know as soon as you have an estimated time for remediation completion, and we can then schedule a retest date.
Retest overview
A retest involves testing the previously reported vulnerabilities to verify that they have been remediated properly. Retests do not identify new vulnerabilities unless new vulnerabilities arise as a direct result of remediation.
Depending on your internal SLAs and timelines, you can either retest all vulnerabilities or only a subset, such as high or critical severity vulnerabilities only. You can choose which vulnerabilities to include when you submit the retesting request.
Confirm whether the retesting is occurring within the same environment and the same accounts as the initial test, or if it is being completed in a new environment or with new accounts.
When the retest is complete, Software Secured will provide a new report with the updated status of the vulnerabilities. If any vulnerabilities were not be effectively fixed, this will be indicated in the updated report with supporting comments or evidence.
Software Secured can support a maximum of 1 round of retesting for Pentest Standard, 3 rounds of retesting for Pentest Standard Plus, and unlimited retesting for PTaaS and Premium clients to validate revised remediation, subject to schedule availability. Further retesting might be possible for an additional fee. For more information, see Software Secured - Pricing and Service Packages.
Requesting a retest
In the projects bar, select the project that you would like to view.
Go to the Vulnerabilities tab.
Using the table multiselect, select the vulnerabilities that you would like to request a retest on, and then click Add to Retest from the bulk actions dropdown.
Alternatively, you can right click any item from the table and use the Add to Retest option from the context menu.

To view your retest request, click Submit Retest.
The Retesting Round modal displays the details of the items in your retest batch.
You can go back to the vulnerabilities table and add more items to the retest round with the Add to Retest button.
If you have any notes about the issues to retest or the retest environment, you can include them in the note field.
Once all issues are in the retesting round, click Submit Request.

Retest results
After a retest, the status of your vulnerabilities can change. You will receive a notification by email, Slack, or both every time new results are available for your project (or projects, if applicable) in Portal.
Any vulnerabilities that were marked with a New status will be changed to the Updated status, and the Last updated date will change to the date of the most recent retest.
If a known vulnerability was remediated successfully, its status will change to Closed and the SLA status will change to Compliant. If the issue remains unresolved, its SLA status does not change because the SLA policy begins on the date that the vulnerability was first found.
Last updated
Was this helpful?

