Vulnerability Management Metrics Workbook
Produces the four metrics that survive management scrutiny — coverage, mean time to remediate by severity, SLA adherence and overdue exposure — from the tracker data.
Available soon
- Format
- Excel
- Size
- 213 KB
- Length
- 12 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Tracker Data
- Coverage Data
- Metric Definitions
- Metrics
- Trend
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Tracker Data sheet: in the Vulnerability Remediation Tracker, copy the whole tracker table's data rows (sheet Tracker, columns A to AE, from row 4 down). Paste them here as values only (Paste Special → Values) into cell A4. Both sheets have the same columns in the same order, headings on row 3: Example | Finding ID | Asset ID | Asset name | Internet-facing | Asset criticality | Vulnerability reference | Title | Scanner severity | Exploited | Suggested priority | Priority | Priority change reason | Detected date | Deadline | Mitigation due (Priority 1) | Mitigation applied date | Owner | Ticket reference | Status | Exception ID | Exception expiry | Closure evidence | Verified closed date | Days open | Days to deadline | Days past deadline | Deadline status | Escalation | Record check | Notes. |
| 2 | Do not paste over the grey calculated columns to the right of column AE. If the export has more rows than the table, drag the table's bottom-right corner down first so the calculated columns extend. |
| 3 | Dates must be real dates, not text. After pasting, check that the Detected date, Deadline, Exception expiry and Verified closed date columns are right-aligned; left-aligned dates are text and will not be counted. |
| 4 | Coverage Data sheet: add one row per scanning period from the Scan Coverage & Asset Scope Register — the period, the In-scope systems and Scanned within required frequency figures from its Summary sheet — and, from the scanner's login report, the authenticated scan attempts and successes. |
| 5 | Metrics sheet: enter the period start and end dates, and how many months each period covers (1 for monthly reporting, 3 for quarterly). The previous period is worked out for you. |
| 6 | Check the targets on the Metrics sheet. The deadlines per priority come from the Standard; the deadline adherence target is yours to agree with the approver. |
| 7 | Read the results. Every figure has a status in words beside it; the colour only repeats what the word says. 'No closures' or 'No data' means there was nothing to measure, which is not the same as zero. |
| 8 | Write the commentary: what changed, why, and what you need from management. Record whether the latest Vulnerability Scanner Configuration Review Checklist said the figures are ready to report upward. |
| 9 | Trend sheet: shows the same measures for the twelve periods ending with the chosen one. Use it to show direction; one period on its own rarely tells management much. |
| 10 | Printing: the Tracker Data sheet prints only its first 25 rows, so that empty input rows do not print as blank pages. To print all your data, clear or reset the print area on that sheet (Page Layout → Print Area). |
| 11 | Delete the EXAMPLE rows on the Tracker Data and Coverage Data sheets before you paste your own data, then check the Metrics sheet recalculates. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Columns used in calculations: Finding ID, Priority (the number 1 to 4), Detected date, Deadline, Status, Exception ID, Exception expiry and Verified closed date. The tracker's own day counts and Deadline status are carried across but not used, because they are calculated against today's date rather than the period you chose. If you change the tracker's columns, change this sheet's to match.
Priority is read from the digit 1 to 4 in the Priority column, so '2', 'P2' and 'Priority 2 — High' all work.
A finding counts as closed on its Verified closed date — the date a later scan (or other objective evidence) confirmed the fix (VM-13). A finding with Status 'Closed — false positive' is left out of every metric. 'Closed — system retired' counts as remediated on its Verified closed date.
A finding past its deadline is not counted as overdue while it has an Exception ID and an Exception expiry on or after the period end (VM-16, VM-17). An exception with no expiry date does not protect a finding.
Tailoring — small organisation: report quarterly (enter 3 months per period) if you close only a handful of findings a month; averages of two or three findings swing wildly. Keep Priority 1 overdue exposure monthly regardless.
Tailoring — regulated financial entity: report to the management body at least quarterly (VM-20), keep each period's copy of this workbook as a record, and add the scanner review result to every report. Supervisors ask how figures were produced as well as what they are.
Tailoring — IT run by a service provider: ask the provider for the tracker export in the column order above, calculate the figures yourself, and compare them with the provider's own service report. Use the deadlines in your agreement with them if they differ from the Standard.
Tracker Data
Paste the whole Vulnerability Remediation Tracker table here as values (columns A–AE, from row 4). Columns AF–AI are calculated. The five EXAMPLE rows show the format — delete them first.
| Example | Finding ID | Asset ID | Asset name | Internet-facing | Asset criticality | Vulnerability reference | Title | Scanner severity | Exploited | Suggested priority | Priority | Priority change reason | Detected date | Deadline | Mitigation due (Priority 1) | Mitigation applied date | Owner | Ticket reference | Status | Exception ID | Exception expiry | Closure evidence | Verified closed date | Days open | Days to deadline | Days past deadline | Deadline status | Escalation | Record check | Notes | Priority level (calc) | Counted (calc) | Days to verified closure (calc) | Closed within deadline (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | VUL-0001 | SRV-014 | Customer portal web server | Yes | Critical | CVE-2026-10001 | Remote code execution in web server module | Critical | Yes | 1 | 1 | 6 Jul 2026 | 13 Jul 2026 | 9 Jul 2026 | 7 Jul 2026 | IT Operations Manager | CHG-2291 | Closed — verified fixed | Rescan 2026-07-10 clean | 10 Jul 2026 | Closed on time | 1 | Yes | 4 | Yes | |||||||||
| EXAMPLE | VUL-0002 | SRV-031 | File server | No | High | CVE-2026-10002 | Privilege escalation in operating system | High | No | 3 | 3 | 22 Jun 2026 | 22 Jul 2026 | IT Operations Manager | INC-4410 | Closed — verified fixed | Rescan 2026-07-29 clean | 29 Jul 2026 | Closed late | 3 | Yes | 37 | No | |||||||||||
| EXAMPLE | VUL-0003 | FW-002 | Perimeter firewall | Yes | Critical | CVE-2026-10003 | Authentication bypass in management interface | High | No | 2 | 2 | 3 Aug 2026 | 17 Aug 2026 | Network Engineer | CHG-2340 | Closed — verified fixed | Rescan 2026-08-14 clean | 14 Aug 2026 | Closed on time | 2 | Yes | 11 | Yes | |||||||||||
| EXAMPLE | VUL-0004 | SRV-022 | Remote access gateway | Yes | High | CVE-2026-10004 | Information disclosure in remote access service | High | No | 2 | 2 | 4 Aug 2026 | 18 Aug 2026 | IT Operations Manager | INC-4502 | In progress | Overdue | Asset owner's manager | 2 | Yes | ||||||||||||||
| EXAMPLE | VUL-0005 | APP-007 | Finance application server | No | Critical | CVE-2026-10005 | Outdated database driver | High | No | 3 | 3 | 13 Jul 2026 | 12 Aug 2026 | Finance Systems Lead | CHG-2318 | Open | EXC-2026-004 | 31 Oct 2026 | Exception | 3 | Yes |
Coverage Data
One row per scanning period, from the Scan Coverage & Asset Scope Register. A row counts towards a reporting period when its dates fall inside it.
| Row type | Period start | Period end | In-scope systems | Scanned within required frequency | Authenticated scans attempted | Authenticated scans that logged in | Source | Scan coverage (calc) | Coverage status (calc) | Authenticated success (calc) |
|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | 1 Apr 2026 | 30 Apr 2026 | 180 | 162 | 150 | 132 | Coverage register Summary, April export | 90.0% | Below target | 88.0% |
| EXAMPLE | 1 May 2026 | 31 May 2026 | 182 | 168 | 152 | 141 | Coverage register Summary, May export | 92.3% | Below target | 92.8% |
| EXAMPLE | 1 Jun 2026 | 30 Jun 2026 | 185 | 175 | 154 | 146 | Coverage register Summary, June export | 94.6% | Below target | 94.8% |
| EXAMPLE | 1 Jul 2026 | 31 Jul 2026 | 186 | 178 | 155 | 148 | Coverage register Summary, July export | 95.7% | Met | 95.5% |
| EXAMPLE | 1 Aug 2026 | 31 Aug 2026 | 190 | 184 | 158 | 152 | Coverage register Summary, August export | 96.8% | Met | 96.2% |
Metric Definitions
Metric definitions
The four headline measures, defined once so that every report calculates them the same way (Standard requirement VM-21). Change a definition only through a new version of the Vulnerability & Exposure Management Standard.
| Measure | Definition | How this workbook calculates it | Target | How to read it |
|---|---|---|---|---|
| Scan coverage | In-scope systems successfully scanned in the period ÷ in-scope systems. | Sum of 'Scanned within required frequency' ÷ sum of 'In-scope systems' for the Coverage Data rows whose dates fall inside the period. | ≥ 95% (VM-02) | Every other figure is only as good as this one. A drop in open findings with a drop in coverage is not an improvement. |
| Mean time to remediate, by priority | Average calendar days from first detection to verified closure, for findings closed in the period. Shown per priority rather than per scanner severity, because the Standard sets its deadlines per priority. | Average of (Verified closed date − Detected date) for counted findings with a Verified closed date inside the period, for each priority 1 to 4. | Below each priority's deadline: P1 7 days, P2 14 days, P3 30 days, P4 90 days. | An average above the deadline means the typical finding is late, not just a few. A small number of closures makes the average unreliable — look at the count. |
| Deadline adherence | Findings closed in the period within their deadline ÷ findings closed in the period. Deadlines are those set per priority in the Standard (sometimes called the SLA, service level agreement). | Findings with a Verified closed date inside the period and on or before their Deadline ÷ all findings with a Verified closed date inside the period. | [[Target, e.g. ≥ 90%]] | Shows whether the deadlines the business agreed are being kept. It counts only closed findings; overdue exposure shows the ones still open. |
| Overdue exposure | Open findings past their deadline with no approved exception, by priority, with the age of the oldest. | Findings detected by the period end, not closed by it, with a Deadline before the period end and no exception still in force at the period end. Oldest = period end − Deadline, in days. | Zero Priority 1; trend down for the rest | The measure that most often needs a management decision: more people, an accepted risk, or a system retired. Any Priority 1 here needs action now. |
Supporting measures (also required by VM-20)
| Measure | Definition | How this workbook calculates it | Target | How to read it |
|---|---|---|---|---|
| Authenticated scan success | Authenticated scans that logged in successfully ÷ authenticated scans attempted, in the period. | Sum of the two authenticated columns on Coverage Data for rows inside the period. | ≥ 95% (VM-05) | A failed login produces a scan that looks clean. Low success makes coverage and open-finding counts optimistic. |
| Open findings at period end | Counted findings detected by the period end and not closed by it, by priority. | As overdue exposure, without the deadline and exception tests. | No target — context | The workload behind the other figures. |
| Active exceptions at period end | Open findings with an exception still in force at the period end. | Exception ID present and Exception expiry on or after the period end. | No target — context | Rising exceptions can hide falling adherence. Each one has a named risk owner (VM-17). |
Metrics
Metrics for the period
Yellow cells are yours: the period, the targets and the commentary. Everything else is calculated. Each figure has a status in words; the colour only repeats it.
Reporting period
| Setting | Value | |
|---|---|---|
| Period start | 1 Aug 2026 | EXAMPLE period — replace with your own |
| Period end | 31 Aug 2026 | |
| Months in each period (1 = monthly, 3 = quarterly) | 1 | |
| Previous period start | 1 Jul 2026 | |
| Previous period end | 31 Jul 2026 |
Targets
| Target | Value | |
|---|---|---|
| Scan coverage (VM-02) | 95% | |
| Deadline adherence — agree with the approver | 90% | [[Confirm the adherence target — 90% is a suggestion]] |
| Authenticated scan success (VM-05) | 95% | |
| Priority 1 — Emergency — deadline in days | 7 | Deadlines from the Standard, section 5.2. Change them only if the Standard changes. |
| Priority 2 — High — deadline in days | 14 | |
| Priority 3 — Medium — deadline in days | 30 | |
| Priority 4 — Low — deadline in days | 90 |
This period against the previous period
| Measure | Target | This period | Previous period | Change | Status | Commentary — what changed and why |
|---|---|---|---|---|---|---|
| Scan coverage | ≥ 95% | 96.8% | 95.7% | +1.1% | Met | |
| Mean time to remediate — Priority 1 — Emergency (days) | ≤ 7 days | No closures | 4.0 | — | No closures | |
| Mean time to remediate — Priority 2 — High (days) | ≤ 14 days | 11.0 | No closures | — | Within deadline | |
| Mean time to remediate — Priority 3 — Medium (days) | ≤ 30 days | No closures | 37.0 | — | No closures | |
| Mean time to remediate — Priority 4 — Low (days) | ≤ 90 days | No closures | No closures | — | No closures | |
| Deadline adherence | ≥ 90% | 100.0% | 50.0% | +50.0% | Met | |
| Findings closed in the period | — | 1 | 2 | -1 | ||
| of which closed within deadline | — | 1 | 1 | 0 | ||
| Overdue exposure — all priorities | Falling | 1 | 0 | +1 | Rising | |
| Overdue exposure — Priority 1 — Emergency | Zero | 0 | 0 | 0 | Met | |
| Overdue exposure — Priority 2 — High | Falling | 1 | 0 | +1 | Rising | |
| Overdue exposure — Priority 3 — Medium | Falling | 0 | 0 | 0 | No change | |
| Overdue exposure — Priority 4 — Low | Falling | 0 | 0 | 0 | No change | |
| Oldest overdue finding (days past deadline) | — | 13 | 0 | +13 | ||
| Authenticated scan success | ≥ 95% | 96.2% | 95.5% | +0.7% | Met | |
| Open findings at period end — Priority 1 — Emergency | — | 0 | 0 | 0 | ||
| Open findings at period end — Priority 2 — High | — | 1 | 0 | +1 | ||
| Open findings at period end — Priority 3 — Medium | — | 1 | 1 | 0 | ||
| Open findings at period end — Priority 4 — Low | — | 0 | 0 | 0 | ||
| Active exceptions at period end | — | 1 | 1 | 0 |
Change is this period minus the previous one; for percentages it is in percentage points. 'Rising' overdue exposure is the direction to act on even when the number is small.
Commentary for management
| Question | Answer | |||||
|---|---|---|---|---|---|---|
| The headline in one sentence | [[e.g. Coverage is above target for the second month; one Priority 2 finding on the remote access gateway is overdue.]] | |||||
| Decisions or support needed from management | [[e.g. Approve a maintenance window for the remote access gateway, or accept the risk until it is replaced.]] | |||||
| Limits on these figures | [[e.g. Authenticated scanning failed on 18 servers in August, so open findings on those servers are under-counted.]] | |||||
Latest Vulnerability Scanner Configuration Review Checklist — ready to report upward?
Date of that review
| Prepared by (name, role) and date | [[Name, role, YYYY-MM-DD]] | |||||
Trend
Trend — twelve periods to the chosen period end
The same measures for the twelve periods ending with the period chosen on the Metrics sheet. 'No data' and 'No closures' mean there was nothing to measure in that period. Use the last column to note what happened.
| Period start | Period end | Scan coverage | Coverage status | MTTR P1 (days) | MTTR P2 (days) | MTTR P3 (days) | MTTR P4 (days) | MTTR status | Findings closed | Deadline adherence | Adherence status | Overdue — all | Overdue — P1 | Oldest overdue (days) | Overdue status | Commentary |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Target | 95.0% | ≤ 7 | ≤ 14 | ≤ 30 | ≤ 90 | 90.0% | Falling | 0 | ||||||||
| 1 Sep 2025 | 30 Sep 2025 | No data | No data | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | — | |
| 1 Oct 2025 | 31 Oct 2025 | No data | No data | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | No change | |
| 1 Nov 2025 | 30 Nov 2025 | No data | No data | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | No change | |
| 1 Dec 2025 | 31 Dec 2025 | No data | No data | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | No change | |
| 1 Jan 2026 | 31 Jan 2026 | No data | No data | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | No change | |
| 1 Feb 2026 | 28 Feb 2026 | No data | No data | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | No change | |
| 1 Mar 2026 | 31 Mar 2026 | No data | No data | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | No change | |
| 1 Apr 2026 | 30 Apr 2026 | 90.0% | Below target | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | No change | |
| 1 May 2026 | 31 May 2026 | 92.3% | Below target | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | No change | |
| 1 Jun 2026 | 30 Jun 2026 | 94.6% | Below target | — | — | — | — | No closures | 0 | No closures | No closures | 0 | 0 | 0 | No change | |
| 1 Jul 2026 | 31 Jul 2026 | 95.7% | Met | 4.0 | — | 37.0 | — | Above deadline | 2 | 50.0% | Below target | 0 | 0 | 0 | No change | |
| 1 Aug 2026 | 31 Aug 2026 | 96.8% | Met | — | 11.0 | — | — | Within deadline | 1 | 100.0% | Met | 1 | 0 | 13 | Rising |
MTTR = mean time to remediate: average calendar days from first detection to verified closure, for findings closed in the period. Overdue figures are counted at each period's end. No score is combined from these measures; read each one against its own target.
Lists
| PriorityLevel | Status | DeadlineStatus | YesNo | Criticality | Severity | ReviewResult |
|---|---|---|---|---|---|---|
| 1 | Open | On track | Yes | Critical | Critical | Ready |
| 2 | In progress | Due soon | No | High | High | Ready, with limitations |
| 3 | Awaiting verification | Overdue | Standard | Medium | Not ready | |
| 4 | Closed — verified fixed | Exception | Low | Not reviewed in the last 6 months | ||
| Closed — false positive | Closed on time | |||||
| Closed — system retired | Closed late |
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Counted finding | A finding whose Status does not contain 'false positive' or 'duplicate'. Only counted findings enter the metrics. |
| Deadline | The date by which a finding must be fixed: detection date plus the days for its priority in the Vulnerability & Exposure Management Standard (VM-08). |
| Deadline adherence | Of the findings closed in the period, the share closed on or before their deadline. Sometimes called SLA (service level agreement) adherence. |
| Exception | An approved, time-limited decision not to fix a finding by its deadline, with a named risk owner and an expiry date (VM-16, VM-17). |
| In force (exception) | An exception whose expiry date is on or after the period end. |
| Mean time to remediate (MTTR) | Average calendar days from first detection to verified closure, for findings closed in the period, shown per priority. |
| Overdue exposure | Open findings past their deadline with no exception in force, counted at the period end, by priority, with the age of the oldest. |
| Period | The reporting window chosen on the Metrics sheet: its start and end dates, inclusive. |
| Priority | The urgency set for a finding, 1 (Emergency) to 4 (Low), from whether it is exploited, whether the system is internet-facing and its severity — see the Vulnerability Risk Rating & SLA Model. |
| Scan coverage | In-scope systems successfully scanned in the period ÷ in-scope systems (VM-02). |
| Verified closed date | The date a later scan, or other objective evidence, confirmed the fix (VM-13). A ticket marked done is not enough. |
| (calc) | A column or cell calculated by the workbook. Do not type or paste over it. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 9.1 — Monitoring, measurement, analysis and evaluation | Whole workbook |
| ISO/IEC 27001:2022 | Annex A 8.8 — Management of technical vulnerabilities | Metrics, Trend |
| NIST CSF 2.0 | ID.IM-01 — “Improvements are identified from evaluations” | Trend, commentary |
| NIST CSF 2.0 | GV.OV-03 — “Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed” | Metrics, period comparison |
| NIS2 — Directive (EU) 2022/2555 | Article 21(2)(f) — “policies and procedures to assess the effectiveness of cybersecurity risk-management measures” | Whole workbook |
| DORA — Regulation (EU) 2022/2554 | Article 9 — protection and prevention, including documented policies for patches and updates (Article 9(4)(f)) | Metrics, commentary |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 10 — vulnerability and patch management, including automated vulnerability scanning at least weekly for ICT assets supporting critical or important functions | Overdue exposure, remediation measures |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); PCI DSS v4.0.1