Scanning is easy, deciding is the work
A scan produces hundreds of findings and no priorities. Most organizations do not have capacity to remediate all of them and should not try. The useful questions are which findings are reachable from outside, which affect systems holding sensitive data, and which have exploitation happening in the real world now.
Some findings will stay open deliberately: an application that pins an old component, a device the vendor no longer patches. Those get compensating controls and a documented decision with a review date, which is a defensible position. Silence about them is not.