
Rex says
Everyday utility math — the kind you'd otherwise pull up four browser tabs for. I keep it to one clean answer.
Try a scenario
Click to load — tweak from there.Inputs
Result
Projected backlog
324
Net weekly change (+growing / -shrinking)
7
Remediation rate needed to hit SLA
147.0
Additional remediations/week needed
119.0
SLA window in weeks
2.1

Psst — share this and help Rex grow
One click, a permanent link with your numbers baked in.
How to use this
- 1Enter current open critical/high vulnerabilities.
- 2Enter new critical/high vulnerabilities per week.
- 3Enter vulnerabilities remediated per week.
- 4Enter sla window (critical/high).
- 5Enter project forward.
- 6Read your projected backlog on the right — it updates as you type.
- 7Hit Share to keep the scenario or send it to someone.
About this calculator
Most vulnerability management programs fail not from lack of tooling but from a simple throughput math problem: new critical and high vulnerabilities arrive faster than the team can remediate them within SLA. This calculator compares your new-vulnerability arrival rate against your remediation rate to determine whether your backlog is shrinking, holding steady, or growing, and projects how many vulnerabilities will still be open and out of SLA in 90 days at current pace. SLA windows commonly used across the industry are 15 days for critical, 30 for high, 90 for medium, per CISA Binding Operational Directive timelines and common enterprise policy, though your own SLA may differ. The output also estimates the additional remediation capacity (patches per week) needed to hit a zero-backlog target, which is the number security leaders actually need when asking for more patching headcount or automation tooling budget.
Worked example
Using the values the calculator loads with:
Inputs
- Current open critical/high vulnerabilities: 240
- New critical/high vulnerabilities per week: 35
- Vulnerabilities remediated per week: 28
- SLA window (critical/high): 15
- Project forward: 12
Results
- Projected backlog: 324
- Net weekly change (+growing / -shrinking): 7
- Remediation rate needed to hit SLA: 147
- Additional remediations/week needed: 119
- SLA window in weeks: 2.1
What each field means
Inputs
- Current open critical/high vulnerabilities
- The current open critical/high vulnerabilities used in the calculation. Starts at 240 so you have a working example on load.
- New critical/high vulnerabilities per week
- The new critical/high vulnerabilities per week used in the calculation. Starts at 35 so you have a working example on load.
- Vulnerabilities remediated per week
- The vulnerabilities remediated per week used in the calculation. Starts at 28 so you have a working example on load.
- SLA window (critical/high)
- The sla window (critical/high) used in the calculation. Starts at 15 so you have a working example on load. Accepted range: 1–180.
- Project forward
- The project forward used in the calculation. Starts at 12 so you have a working example on load. Accepted range: 1–104.
Results
- Projected backlog
- Returned as a whole number and shown as the headline result. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Net weekly change (+growing / -shrinking)
- Returned as a whole number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Remediation rate needed to hit SLA
- Returned as a decimal number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- Additional remediations/week needed
- Returned as a decimal number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
- SLA window in weeks
- Returned as a decimal number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
FAQ
What SLA windows are actually standard?
CISA's Binding Operational Directive 22-01 requires federal agencies to remediate known exploited vulnerabilities within a set window, and most enterprise vulnerability management policies mirror or tighten that with roughly 15 days for critical, 30 for high, 60-90 for medium, and 90-180 for low severity, though regulated industries like finance and healthcare often run tighter timelines.
My backlog is growing even though we're patching every week, what's going on?
This is the most common vulnerability management failure mode: your remediation rate is a fixed capacity (people, change windows, testing cycles) while new vulnerability disclosure volume keeps climbing industry-wide. The fix is either increasing remediation throughput through automation and pre-approved patch windows, or reducing attack surface so fewer systems generate new findings in the first place.
Should every vulnerability actually get patched?
No, mature programs risk-score and often accept or compensate for vulnerabilities that aren't internet-facing, don't have known exploits, or sit behind other controls, rather than treating every scanner finding as equal. Applying that filtering before counting your backlog gives a far more realistic and achievable throughput target than trying to patch everything.
How much does automation actually move the remediation rate?
Organizations moving from manual patch testing and deployment to automated patch management with staged rollout groups commonly see remediation throughput increase 40-70%, mainly by cutting the manual scheduling and verification overhead that dominates patch cycle time more than the actual patching work itself.
Accuracy and limitations
- Estimates assume standard, average conditions — local rules, pricing, and materials vary.
- Results are rounded for readability; add a buffer before ordering, booking, or committing.
- Double-check anything with a real cost attached against a local quote.
Related tools
SOC Staffing Coverage Calculator
Figure out how many analysts you need for 24/7 or business-hours coverage.
MTTD/MTTR Cost Impact Calculator
See how faster detection and response times translate into dollars saved.
Pen Test vs. Bug Bounty Cost Calculator
Compare annual cost and expected coverage of scheduled pen tests vs. an ongoing bounty program.
Cite this calculator
Writing about this topic? Grab a citation — every link helps keep these tools free.
RevenueLab. (2026). Patch SLA Backlog Calculator. Retrieved from https://www.revenuelab.fyi/toolbox/patch-sla-backlog
<p>Source: <a href="https://www.revenuelab.fyi/toolbox/patch-sla-backlog" target="_blank" rel="noopener">Patch SLA Backlog Calculator — RevenueLab</a> (2026).</p>
Source: [Patch SLA Backlog Calculator — RevenueLab](https://www.revenuelab.fyi/toolbox/patch-sla-backlog) (2026).
