Under Def Stan 05-138 you are assessed against your own remediation policy. So write one you can meet.
Control 2402 says vulnerabilities should be addressed in accordance with the Supplier's internal remediation timelines. A policy that promises seven days for every critical and then misses it is weak evidence.
How to do it.
Set the timeline by what the finding is, not only by its CVSS score. Four tiers cover most organisations.
- On the KEV list and reachable from the internet.
- On the KEV list, internal only.
- Critical or high, not on the KEV list.
- Everything else.
Then.
- Test the timelines against the last six months of your own data. If you closed 60% of highs inside thirty days, a fourteen day target is a policy you fail on day one.
- Say what happens when you cannot patch. Mitigate, isolate or formally accept, with a named owner and a review date.
- Name when the clock starts. When the finding is first seen, not when a ticket is raised.
- Get it signed by someone who owns the business risk.
Based on my experience running vulnerability management within the MOD, I assess that the policy which holds up to scrutiny is rarely the most aggressive one. It is the one with evidence behind every line.



