Some vulnerabilities cannot be treated immediately. A mature programme makes that constraint explicit without allowing acceptance to become a hidden route around remediation.
Acceptance is a business decision
The remediation team can describe technical exposure and operational constraints, but the accountable business or service owner accepts the residual risk.
Evidence must be reviewable
Record affected assets, exploitation evidence, likely consequence, proposed controls, treatment plan and why delay is proportionate.
Every exception should decay
Use an expiry date and triggers such as KEV addition, rising EPSS, new external exposure or control failure. Automated reminders should reopen review before expiry.
Practical next steps
- Use a standard exception record.
- Require evidence that compensating controls operate.
- Set shorter reviews for exposed or high-EPSS issues.
- Report accepted risk separately from remediated risk.