We run a small-scale fleet tracking SaaS for logistics companies out of Austin. An enterprise client made signing contingent on us passing a third-party penetration test. We paid 4,500 dollars for the assessment, and yesterday we received a detailed 40-page report.
The executive summary states: 'It is recommended that critical, high, and medium-severity findings be remediated within 30 days.' We have 3 full-time developers, but since we've never been through an enterprise audit before, we're not entirely sure what this remediation process requires operationally.
Do our devs fix these, or do we offload them to our cloud hosting provider? Is clearing everything in 30 days realistic, and most importantly, how do we officially prove to the client that the vulnerabilities have been resolved?