Full Transparency

How We Calculate Your Security Score

Security tools ask for trust; we'd rather show our work. This page documents exactly how answers become scores, and how remediation guidance is produced.

Step 1 · Five-Level Maturity Scale

Every control is answered against a five-level scale. Each level maps to a fixed value between 0 and 1 — there is no hidden scoring.

1.00Fully implementedControl is operating consistently across the organization.
0.75Mostly implementedIn place but with gaps in scope, consistency, or ownership.
0.50Partially implementedExists informally or covers only part of the requirement.
0.25PlannedDocumented intent exists; implementation has not started.
0.00Not implementedNo activity related to the control.

Controls marked Not Applicable are excluded from scoring entirely — they neither raise nor lower your result.

Step 2 · Importance Weighting

Controls are not all equally important. Each control carries an importance weight reflecting its typical impact on security posture, and each control's own questions carry sub-weights the same way.

A control's score is the weighted average of its question answers. Your domain score is the weighted average of its controls. Your overall score is the weighted average across all applicable controls, expressed as 0–100.

control_score = Σ(question_weight × answer_value) / Σ(question_weight)

domain_score = Σ(control_weight × control_score) / Σ(control_weight)

overall_score = round( Σ(control_weight × control_score) / Σ(control_weight) × 100 )

Step 3 · Score Bands

Excellent

80 – 100

High ISMS maturity. Maintain and continuously improve.

Good

60 – 79

Solid foundation with room to improve. Focus on lower-scoring domains.

Average

40 – 59

Notable deficiencies. Build a remediation plan and start on key controls.

Needs Improvement

0 – 39

Elevated risk. Prioritize a structured remediation project immediately.

How AI Remediation Guidance Is Produced

AI recommendations are grounded in your actual assessment data — control codes, titles, your maturity answers, and their weighting — plus your company context (industry, regulatory environment). The model is instructed to act as a senior information security consultant and produces a structured summary: risk and priority overview, findings, a 30/90/180-day remediation roadmap, organizational responsibilities, and key metrics.

Per-control remediation guidance is generated once per control, stored in a template library, and reused — so the same control always yields consistent advice, reviewable independently of any single report.

What AI doesn't do: invent findings that aren't in your answers, or replace professional judgment. Treat output as expert-drafted starting points, validated by the people who know your systems.

Scope note: EvaluationCat provides self-assessment and readiness analysis. It is not an audit, and results are not certification. For ISO 27001 certification you need an accredited certification body — see frameworks overview.
    Feedback
    Back to Top