Revenue Rex logo mark
🧰 Other · Rex's Toolbox

Patch Management SLA Backlog Calculator

See if your patching throughput can clear the vulnerability backlog before it grows.

Revenue Rex peeking

Rex says

Everyday utility math — the kind you'd otherwise pull up four browser tabs for. I keep it to one clean answer.

Try a scenario

Click to load — tweak from there.

Inputs

Result

Projected backlog

324

Net weekly change (+growing / -shrinking)

7

Remediation rate needed to hit SLA

147.0

Additional remediations/week needed

119.0

SLA window in weeks

2.1

Revenue Rex peeking

Psst — share this and help Rex grow

One click, a permanent link with your numbers baked in.

More other

How to use this

  1. 1Enter current open critical/high vulnerabilities.
  2. 2Enter new critical/high vulnerabilities per week.
  3. 3Enter vulnerabilities remediated per week.
  4. 4Enter sla window (critical/high).
  5. 5Enter project forward.
  6. 6Read your projected backlog on the right — it updates as you type.
  7. 7Hit Share to keep the scenario or send it to someone.

About this calculator

Most vulnerability management programs fail not from lack of tooling but from a simple throughput math problem: new critical and high vulnerabilities arrive faster than the team can remediate them within SLA. This calculator compares your new-vulnerability arrival rate against your remediation rate to determine whether your backlog is shrinking, holding steady, or growing, and projects how many vulnerabilities will still be open and out of SLA in 90 days at current pace. SLA windows commonly used across the industry are 15 days for critical, 30 for high, 90 for medium, per CISA Binding Operational Directive timelines and common enterprise policy, though your own SLA may differ. The output also estimates the additional remediation capacity (patches per week) needed to hit a zero-backlog target, which is the number security leaders actually need when asking for more patching headcount or automation tooling budget.

FormulaNet weekly change = new vulnerabilities/week − remediated/week. Backlog in N weeks = current backlog + (net weekly change × N). Required rate to clear SLA = (current backlog + inflow over SLA window) ÷ SLA window in weeks.

Worked example

Using the values the calculator loads with:

Inputs

  • Current open critical/high vulnerabilities: 240
  • New critical/high vulnerabilities per week: 35
  • Vulnerabilities remediated per week: 28
  • SLA window (critical/high): 15
  • Project forward: 12

Results

  • Projected backlog: 324
  • Net weekly change (+growing / -shrinking): 7
  • Remediation rate needed to hit SLA: 147
  • Additional remediations/week needed: 119
  • SLA window in weeks: 2.1

What each field means

Inputs

Current open critical/high vulnerabilities
The current open critical/high vulnerabilities used in the calculation. Starts at 240 so you have a working example on load.
New critical/high vulnerabilities per week
The new critical/high vulnerabilities per week used in the calculation. Starts at 35 so you have a working example on load.
Vulnerabilities remediated per week
The vulnerabilities remediated per week used in the calculation. Starts at 28 so you have a working example on load.
SLA window (critical/high)
The sla window (critical/high) used in the calculation. Starts at 15 so you have a working example on load. Accepted range: 1–180.
Project forward
The project forward used in the calculation. Starts at 12 so you have a working example on load. Accepted range: 1–104.

Results

Projected backlog
Returned as a whole number and shown as the headline result. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
Net weekly change (+growing / -shrinking)
Returned as a whole number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
Remediation rate needed to hit SLA
Returned as a decimal number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
Additional remediations/week needed
Returned as a decimal number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.
SLA window in weeks
Returned as a decimal number. It recalculates instantly whenever you change an input, so you can compare scenarios without reloading.

FAQ

What SLA windows are actually standard?

CISA's Binding Operational Directive 22-01 requires federal agencies to remediate known exploited vulnerabilities within a set window, and most enterprise vulnerability management policies mirror or tighten that with roughly 15 days for critical, 30 for high, 60-90 for medium, and 90-180 for low severity, though regulated industries like finance and healthcare often run tighter timelines.

My backlog is growing even though we're patching every week, what's going on?

This is the most common vulnerability management failure mode: your remediation rate is a fixed capacity (people, change windows, testing cycles) while new vulnerability disclosure volume keeps climbing industry-wide. The fix is either increasing remediation throughput through automation and pre-approved patch windows, or reducing attack surface so fewer systems generate new findings in the first place.

Should every vulnerability actually get patched?

No, mature programs risk-score and often accept or compensate for vulnerabilities that aren't internet-facing, don't have known exploits, or sit behind other controls, rather than treating every scanner finding as equal. Applying that filtering before counting your backlog gives a far more realistic and achievable throughput target than trying to patch everything.

How much does automation actually move the remediation rate?

Organizations moving from manual patch testing and deployment to automated patch management with staged rollout groups commonly see remediation throughput increase 40-70%, mainly by cutting the manual scheduling and verification overhead that dominates patch cycle time more than the actual patching work itself.

Accuracy and limitations

  • Estimates assume standard, average conditions — local rules, pricing, and materials vary.
  • Results are rounded for readability; add a buffer before ordering, booking, or committing.
  • Double-check anything with a real cost attached against a local quote.

Related tools

Cite this calculator

Writing about this topic? Grab a citation — every link helps keep these tools free.

APA
RevenueLab. (2026). Patch SLA Backlog Calculator. Retrieved from https://www.revenuelab.fyi/toolbox/patch-sla-backlog
HTML
<p>Source: <a href="https://www.revenuelab.fyi/toolbox/patch-sla-backlog" target="_blank" rel="noopener">Patch SLA Backlog Calculator — RevenueLab</a> (2026).</p>
Markdown
Source: [Patch SLA Backlog Calculator — RevenueLab](https://www.revenuelab.fyi/toolbox/patch-sla-backlog) (2026).
Advertisement