Grace Period for Company-Provided Infrastructure Jessica A grace period provides a temporary window during which eligible infrastructure can be reviewed and findings can be addressed before they begin impacting the Risk Vector Grade. Once added, company-provided infrastructure does not impact your rating for a 60-day grace period and there’s no historical impact if the same or new observations come up after the grace period. During this time, you can preview findings for this infrastructure. This allows you to proactively remediate company-provided IPs and domains before they impact your rating.Findings from new company-provided infrastructure are visible to third parties during the grace period. Once the grace period ends, third parties will see any new findings as they are observed.You can opt out of the grace period when adding assets to your infrastructure. The grace period is honored even if our scans would have independently discovered the infrastructure after it was manually added. If we discover infrastructure that overlaps with an existing piece of company-provided infrastructure with a grace period, the start date will be no earlier than the company-provided one. Company-provided infrastructure with a grace period must always have a start date of “today”. If there is any overlapping infrastructure already present in a company’s ratings tree, a request to add company-provided infrastructure with a grace period will be rejected. During an active grace period, findings remain visible in the platform but do not impact the Risk Vector Grade. These findings are identified as No: Grace Period in the Impacts Risk Vector Grade field.Identify Findings Currently in a Grace PeriodNo: Grace Period can appear on: Findings that are currently in an active grace period. Historical findings that were observed while a grace period was active but whose grace period has since ended. To find findings that are currently in an active grace period, filter by: Impacts Risk Vector Grade: No: Grace Period No Impact End Date – Start Date: Today The No Impact End Date indicates when the finding's protection from impacting the Risk Vector Grade ends.If the No Impact End Date has already passed, the finding is a historical record from a grace period that has ended.What Happens After the Grace Period?A finding observed during a grace period does not automatically become an impacting finding when the grace period ends.The original finding remains No: Grace Period.If the issue is observed again after the grace period has ended, a new finding is created. That finding can impact the Risk Vector Grade and is identified as Yes in the Impacts Risk Vector Grade field.This means you may see both a historical No: Grace Period finding and a newer Yes finding for the same issue.The lifetime of this finding begins when it is first observed after the grace period ends. Both findings will appear in their own rows in the Findings Table. The finding observed during the grace period does not impact your risk vector grade. Any eventual findings observed after the grace period will impact risk vector grades from the date they’re first seen after the grace period. Diligence findings observed before and after the grace period will have the same rolled up ID; Compromised Systems and User Behavior findings will have different rolled up IDs. The related findings field can help you track down findings with the same finding identifier and the same risk vector.Use the Grace Period ProactivelyGrace periods provide an opportunity to address risk before it affects the Risk Vector Grade.Rather than waiting for the grace period to expire, use the active grace-period window to: Identify newly introduced infrastructure and associated findings. Review and validate the infrastructure. Investigate findings while they are non-impacting. Remediate applicable issues before the No Impact End Date. Monitor or alert on new findings entering a grace period so they can be addressed early. This allows teams to incorporate grace-period findings into their remediation workflow before those issues can begin affecting the Risk Vector Grade.Grace Period in Cloud Infrastructure SyncWhen a Cloud Infrastructure Sync connection is made, the infrastructure attributed to the self-published company you create as part of that connection receives a 60-day grace period. After the initial grace period ends, newly scanned infrastructure related to that connection is not subject to a grace period due to the dynamic nature of cloud infrastructure. The initial 60 day grace period should be sufficient to identify and remediate any findings that are recurrent. February 20, 2025: Published. Related articles Impacts Risk Vector Grade Attack Surface: Cloud Infrastructure Sync Findings Table: Finding Details Sheet Finding Behavior TLS/SSL Finding Remediation & Remediation Verification Feedback 1 comment Sort by Date Votes Mary Cruz July 25, 2025 16:13 I am missing some understanding. Is this the same as Customer-Provided?Also from this excerpt: Findings from new company-provided infrastructure are visible to third parties during the grace period. Once the grace period ends, third parties will see any new findings as they are observed.Does this mean that the third parties can see the findings during the grace period? What is the difference between the grace before and after? This is a confusing paragraph. 0 Please sign in to leave a comment.