Learn how to submit a finding for retest or accept it.
:::info During remediation, review findings that pentesters discovered, and take action on them. :::
Once pentesters move a finding to Pending Fix, you can:
Fix the finding and submit it for retest
Mark the finding as Accepted Risk
After you’ve fixed a finding internally, you can submit it for retest to confirm the fix.
The pentester who originally reported the finding is notified and will retest the issue within seven (7) days. When finished, the tester will change the finding state to:
Fixed, if they can’t reproduce the issue.
Pending Fix, if the issue persists. Read the pentester’s comment for details.
:::info
For Agile and Comprehensive Pentests that Cobalt pentesters perform, you can submit findings for retest at any time:
Until the end of the free retesting period; or
10 days before your contract ends.
Cobalt pentesters complete retesting within seven (7) days after submission. :::
For Agile and Comprehensive Pentests, free retesting is available based on your PtaaS tier, provided your contract is active.
Standard tier: 6 months
Premium and Enterprise tiers: 12 months
:::info Notes:
Free retesting is only available within an active contract. Your retest end date is either the duration of your purchased tier or 10 days before your contract end date (until 23:59 UTC).
When you start a pentest right before your contract expires, you may not qualify for retesting. If you add a new contract, we’ll update your retest end date based on the tier your pentest was planned in. :::
The Standard contract duration is from January 1, 2025 to December 31, 2025.
You have a pentest moved to Planned on December 18, 2025 with a start date of December 20, 2025 and an end date of January 3, 2026. The free retesting end date for this pentest is December 21, 2025, until 23:59 UTC (10 days before your current contract end date).
Then on December 30, 2025, you signed a new Enterprise contract for a period from January 1, 2026 to December 31, 2026. To recalculate the free retesting end date for your pentest planned on December 18, we’ll look at the Standard tier. Since you extended your contract, we’ll also update your retesting end date from January 3, 2026 23:59 UTC to June 3, 2026 23:59 UTC (6 months for Standard tier).
:::info
To extend your retest end date, please contact your Customer Success Manager (CSM) or support@cobalt.io. :::
Once you’ve analyzed a finding, you may want to accept it if:
The risk associated with the vulnerability is low; or
You plan to mitigate the finding in a way that doesn’t involve an actual technical fix.
If you determine that the vulnerability does not require a technical fix — either because the risk is low, or you plan to mitigate it through non-technical controls—you can mark it as Accepted Risk.
Users with access to the pentest can see who accepted the risk and view all related details. Findings marked as Accepted Risk will appear in the Post-Test Remediation section of your final report.
If you believe a reported finding is not a valid vulnerability (e.g., it is a false positive, or the associated risk is negligible), you should ask the pentesters to reevaluate it.
Resolution:
If pentesters confirm the finding is not a vulnerability after reevaluation, they will Decline the finding.
If pentesters confirm the finding is a legitimate vulnerability, you can then choose to mark the finding as Accepted Risk if you do not plan to apply a technical fix.