Request pentest finding remediation retests
Last updated: July 24, 2026
Context
After completing a penetration test and receiving findings, you'll need to remediate the vulnerabilities and then request retesting to verify that the issues have been properly fixed. This process allows the pentester to confirm your remediation efforts and update the final report accordingly.
Answer
To request retesting of your remediated pentest findings, follow these steps:
Navigate to the Oneleet dashboard and go to your pentest findings
Ensure you are on Version 0.2 (not Version 0.1, which is for downloading the initial report)
Click on the specific finding you have remediated
Click on the Open status - this will reveal a dropdown menu
Select Ready for review from the dropdown
Repeat this process for each finding you have remediated
Once you mark findings as "Ready for review," the assigned pentester will automatically receive a notification and will retest the findings within a few days. The pentester will then update the status to either "Remediated" if the fix was successful, or "Reopened" if the vulnerability still exists.
Important notes:
You can submit findings for retesting individually as they are fixed, or bundle them together
Retesting is unlimited for vulnerabilities found during the pentest for 1 year
Most companies complete remediation within about a month of the pentest completion
Once all findings are remediated or risks are accepted, an updated pentest report will be generated within 1-2 business days
If you need to accept risk for any low-priority findings instead of remediating them, you can mark them as "Accepted risk" and provide a brief description of why the risk is being accepted.