Time to revoke is a security metric measuring how long an exposed credential remains usable after being confirmed valid. Unlike MTTD or MTTR, it specifically tracks the window between credential validation and confirmed invalidation — closing a ticket or removing a secret from a repo doesn't count. To measure it, teams should capture four timestamps per incident: detection, validation, owner assignment, and invalidation. Key derived metrics include median and P90 time to revoke, percentage revoked within SLA (tiered by risk level), owner coverage rate, percentage still valid after detection, and escalation rate. For CISO reporting, these metrics translate technical exposure into a measurable business risk window, showing whether the organization is actually shrinking the time exposed credentials remain usable.