Back to glossary

Retest

1 min read

A retest is a bounded second engagement whose only purpose is to verify that the findings of a previous assessment have actually been fixed. In an audit programme it is what converts a report into evidence, because a remediation plan marked complete internally and a finding proven closed by testing are not the same claim.

July 29, 2026
Compartir:

The scope is the finding list, not the system. A retest reproduces each original issue by the original route and records one of three outcomes: closed, open, or partially addressed with the residual condition described. It does not go looking for new issues, and where the fix has changed the application enough that new issues are plausible, that is said in the report as a recommendation for a fresh penetration test rather than quietly absorbed.

Two things determine whether it is worth anything. Timing, because a retest run before the change reaches production tests a staging environment and proves nothing about the estate. And method, because a fix verified by reading a change ticket is not verified. What we hand over is the same evidence format as the original finding, produced again against the fixed system.

The commercially useful part is that certification and regulatory work usually needs this artefact rather than the original report: the auditor wants proof that the identified weaknesses were treated, with dates. Feeding those outcomes back into vulnerability management is what stops the same finding reappearing in the next cycle, and it is included in the certification support work where a closed finding has to be evidenced.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.