ClearPenTest

Testing

Retest

Also called: remediation testing, verification testing, re-test

A retest is a follow-up assessment that verifies specific findings from an earlier test have actually been fixed, producing a dated record that closes the loop between a finding and its remediation.

For an audit the retest is often worth more than the original test. A report with an open critical finding raises a question with every buyer who reads it. The same finding with a dated retest showing it closed demonstrates that the vulnerability management control works, which is what the criteria are asking about.

PCI DSS makes this explicit: Requirement 11.4.4 requires exploitable vulnerabilities to be corrected and the testing repeated to verify the correction.

Testing, with the report an auditor can actually use

A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.