Assessment Methodology

Methodology principles

Four commitments the scoring keeps: deterministic, fully disclosed, silent about what it cannot evidence, and never scoring absence as zero.

Currentengine 9.0.0Verified 2026-08-30

Deterministic

The same evidence produces the same score. Nothing in the scoring samples, estimates, weights by judgement at run time, or varies between runs.

Disclosed in full

Every threshold, weight, ceiling and rule the engine applies is defined in a configuration file, and reproduced on the methodology page of the board pack. A reader can recompute the result from what the pack prints.

Silent about what it cannot evidence

A domain the evidence cannot support is reported as not assessed, with the population stated. It is never scored as zero and never quietly omitted, because those two mislead in opposite directions and both cost trust.

Absence is not a failure

An account that runs no databases is not penalised for having no database backups. A signal with no in-scope resources is recorded and excluded from scoring rather than counted against you.

The rules these produce

RuleEffect
Control deduplicationRecords are collapsed to distinct controls before scoring
Indeterminate exclusionA record that cannot be classified is excluded from both numerator and denominator, and the excluded count is reported
Evidence admissionOnly files recognised as control evidence are scored. Anything else is listed and ignored
Overall RAG floorThe overall band can never be better than the security band
No silent renormalisationThe overall score is calculated only when every offered domain was scored. A missing domain withholds the rating rather than re-basing across the rest
Confidence gateThe overall rating is withheld entirely when confidence is below High

What none of it does

No part of the scoring models revenue, data value, workload criticality, regulatory position, or the probability of compromise. The assessment observes none of those. See What the scores do not mean.