Free Tool
Pentest Remediation Tracker
Log penetration test findings, classify by severity, track remediation status, and monitor progress over time.
This tool provides general guidance based on the information you provide. It is an initial starting point, not a substitute for professional assessment. Every organization's environment is unique — results should be reviewed with a qualified advisor before making compliance or security decisions.
Who this tool is for
This check is for organizations that commission penetration tests — because a customer, an auditor, or an insurer required one — and are not sure the results ever turned into fixes. It is written for CTOs and engineering leads who receive the report, compliance managers who need pentest evidence for SOC 2, ISO 27001, PCI DSS, or CMMC, executives who signed the invoice and want to know what changed, and security leaders at larger organizations who suspect findings are being closed on paper but not in production. Program size does not matter; the failure pattern is the same at ten engineers and at four hundred.
What it measures — and what “in scope” means
The questions assess the lifecycle around your penetration tests rather than any single report: how recently the last test was conducted, how findings are tracked (not at all, in email, in a spreadsheet, or in a formal system), what percentage of findings have been remediated, whether fixes are verified through retesting, whether findings are correlated with your broader risk assessment, and whether leadership receives reporting on results. The score reflects program maturity: a test that produces findings nobody tracks scores poorly regardless of how good the testers were. "In scope" means external and internal penetration tests and vulnerability assessments performed by a third party or an internal red team.
What your result is not
This tool does not analyze a penetration test report, does not rate the severity of specific findings, and does not tell you whether your testers were competent. It measures whether your organization does anything useful with the results. A strong score means your remediation process works; it says nothing about how many vulnerabilities remain. It is also not a substitute for the retest itself — only a retest confirms a finding is closed.
Frequently asked questions
QHow often should we run a penetration test?
At least annually for most organizations, and after significant changes to internet-facing systems. SOC 2, PCI DSS, and many customer contracts expect annual testing; PCI also requires testing after major changes.
QWhat is the difference between a vulnerability scan and a penetration test?
A scan is automated and finds known weaknesses. A penetration test is performed by a person who chains weaknesses together to demonstrate real impact. Auditors and customers usually want both.
QDo auditors want the report or the remediation evidence?
Both. A report with open critical findings and no remediation plan is a finding in itself. Track fixes, retest, and keep the evidence.
QWhat should we do with findings we cannot fix?
Document the risk acceptance with a business justification, an owner, and a review date. Undocumented open findings are worse than documented accepted risks.
QIs any of this stored?
No. The check runs in your browser and nothing is transmitted.
Related reading
Tool and guide maintained by Ashwameth J Ravilla, CISSP, CISA, CDPSE, CMMC RP (CPN 72949) · Last updated September 2026.
Need a Deeper Analysis?
This tool gives you a starting point. For a comprehensive, professional assessment tailored to your specific environment, schedule a consultation.
Schedule a Scope Call