Request pentest finding remediation retests

Last updated: July 24, 2026

Context

After completing a penetration test and receiving findings, you'll need to remediate the vulnerabilities and then request retesting to verify that the issues have been properly fixed. This process allows the pentester to confirm your remediation efforts and update the final report accordingly.

Answer

To request retesting of your remediated pentest findings, follow these steps:

  1. Navigate to the Oneleet dashboard and go to your pentest findings

  2. Ensure you are on Version 0.2 (not Version 0.1, which is for downloading the initial report)

  3. Click on the specific finding you have remediated

  4. Click on the Open status - this will reveal a dropdown menu

  5. Select Ready for review from the dropdown

  6. Repeat this process for each finding you have remediated

Once you mark findings as "Ready for review," the assigned pentester will automatically receive a notification and will retest the findings within a few days. The pentester will then update the status to either "Remediated" if the fix was successful, or "Reopened" if the vulnerability still exists.

Important notes:

  • You can submit findings for retesting individually as they are fixed, or bundle them together

  • Retesting is unlimited for vulnerabilities found during the pentest for 1 year

  • Most companies complete remediation within about a month of the pentest completion

  • Once all findings are remediated or risks are accepted, an updated pentest report will be generated within 1-2 business days

If you need to accept risk for any low-priority findings instead of remediating them, you can mark them as "Accepted risk" and provide a brief description of why the risk is being accepted.