Learn about the latest product improvements in the SecurityScorecard platform.
Some features mentioned in this article may only be available with a paid SecurityScorecard plan. See our plans page for more information about feature levels and access.
Want to try what’s next?
Visit the Early Access center from the Help icon in the upper-right corner of the platform to explore features that are available to try now.
October
Faster, More Accurate Domain Attribution with RDAP
Vendor Intake and Automated Inherent Risk Tiering
We're moving from the legacy WHOIS protocol to RDAP (Registration Data Access Protocol). New registrations in using the RDAP protocol now reach scorecards within a day of being observed. Domains that are unregistered age out of a footprint after 45 days. The criteria used to attribute a domain to an organization hasn't changed — a domain still needs to match on a DNS nameserver, a registrant email's apex domain, or a registrant name.
September
Vendor Intake and Automated Inherent Risk Tiering
A new Vendor Intake form lets the business stakeholders who bring on a vendor submit it for review directly — no platform account required. They get an email link, verify with a one-time code, and fill out the form. Their answers automatically calculate an inherent risk tier and populate the vendor record in All Companies, so your team gets a standardized, self-service way to onboard new vendors.
Set up a Vendor Intake form and share it with your team directly from All Companies.
Learn more about Vendor Intake and Automated Inherent Risk Tiering
Unified Risk View
Scorecards now include a unified risk view that brings your Security Score, Breach Susceptibility Indicator, and Ransomware Score together in one place. Instead of checking separate reports, you get a single, clearer view of an organization's overall risk posture.
Security Score, Breach Susceptibility Indicator, and Ransomware Score, together in one unified view.
Learn more about Unified Risk View
Updated Ransomware Report
The Ransomware Report now explains each factor behind a company's Ransomware Score against a population baseline, so you can see exactly why a score is what it is, not just what the score is.
The updated Ransomware Report now shows how each factor contributes to the overall likelihood of a ransomware event.
Learn more about the Updated Ransomware Report
New BSI Report
A new Breach Susceptibility Indicator (BSI) report is now available in the reporting center, giving you a consistent, transparent, factor-level breakdown of what drives a company's BSI score.
The new BSI Report gives a transparent, factor-level view of breach susceptibility.
New Comparison Report
The Comparison Report has a new look and now includes BSI and Ransomware score data. Opening it automatically populates up to 7 comparable companies — no more adding them one at a time — and you can still add, remove, or adjust the list from there.
Select companies and use Compare to generate a report populated automatically with comparable peers.
Learn more about the New Comparison Report
Bulk Vendor Upload — Custom Field Support
Bulk vendor upload now supports your custom fields alongside system fields, and the upload template automatically includes a column for every custom field you've configured. Onboard large vendor lists in a single upload, tracking the data that actually matters to your program.
Custom fields are now included automatically in the bulk vendor upload template.
Learn more about Bulk Vendor Upload with Custom Field Support
Recalibrated Score Columns in All Companies & Portfolios
A new Recalibrated Score column shows the projected post-recalibration score for every company in your All Companies and Portfolio views — and it's included in CSV exports. Values update daily and reflect current findings, so you can self-serve the projected impact of the upcoming quarterly Scoring Recalibration ahead of time, instead of waiting on a report.
The Recalibrated Score column shows each company's projected score ahead of the next quarterly recalibration - the next one on November 24th, 2026 (as of September 2026).
Other enhancements and fixes
Multi-CPE CVE detection fix
Fixed a scoring bug where CVEs requiring both a software version and an OS match were being applied on version alone, which could return zero results in large result sets. CVE-driven findings are now more accurate, with fewer false positives.
Breach Analysis v1.1.2
Improved the accuracy of threat-actor extraction in Breach Analysis, reducing incorrect labels and consolidating aliases into a single entry for more accurate, de-duplicated attribution.
Custom scorecards in automation rules
Automation rules can now target custom scorecards, not just standard scorecards, so you can build rule-based workflows scoped to any custom scorecard grouping you've created.
Public trust center data on scorecard
Scorecards now show a link and overview of a company's public trust center, giving you more context on its security posture directly from the scorecard.
August
Alleged Breaches
Two new breach measurement types, alleged first-party and alleged third-party breaches, now appear as INFO-severity findings. See early breach signals on your own organization or your vendors before they're confirmed, with zero impact to your score.
Learn more about Alleged Breaches
SecurityScorecard for Vulnerability Response is Live on the ServiceNow Store
Install SecurityScorecard for Vulnerability Response directly from the ServiceNow Store. Findings tied to known CVEs flow automatically into the ServiceNow queue your remediation team already works from, on a refresh schedule you choose, with no manual export or re-typing required.
Learn more about the new ServiceNow Listing
New Jira App Ownership Assignments
The Jira App integration now supports assignees in the rule builder, so you can assign clear ownership for remediation tasks.
Learn more about ownership assignment in the Jira App integration
August 20, 2026 scoring recalibration
On August 20, 2026, we performed our quarterly scoring recalibration. In this recalibration, we decreased the impact of 2 issue types and increased the impact of 2 issue types.
Learn more about this scoring recalibration
Questionnaire Decision — Vendor Visibility & Save Restrictions
You can set questionnaires decisions to “No Decision”, “Passed”, “Passed with Conditions” and “Failed”. They are also explicitly shown in the Platform UI.
Learn more about reviewing vendor responses to questionnaires
Question-Level Internal Messaging
You can now toggle any question-level message to "Internal Only," keeping it in the same thread but hidden from vendor users in the UI and API.
Learn more about reviewing vendor responses to questionnaires
AI Document Analysis
leverage AI to analyze a vendor's questionnaire documents (such as a SOC 2 report). The AI asks and answers a default set of questions against the documents, and you can log any answer straight to a finding.
Learn more about reviewing vendor responses to questionnaires
New Weak Cipher Suite Flagged: TLS_DHE_RSA_WITH_AES_256_CCM_8
We have added a new cipher suite to those that will flag the TLS Weak Cipher Suite. This is related to the issue type “TLS Service Supports Weak Cipher Suite.” You can now get visibility into this previously unflagged weak cipher suite on your footprint, letting you identify and remediate exposure before it becomes a compliance or audit gap.
July
Updated 48-Hour Scorecard Refresh SLA
You can now expect Scorecard changes to reflect within 48 hours, with most updates landing in under 24 — down from the previous 72-hour SLA.
ServiceNow for VRM v2.5.4
You can now use v2.5.4 of the SecurityScorecard for Vendor Risk Management app on the ServiceNow Store to sync 10K+ vendor portfolios without a single bad record halting the whole batch, and access factor-level Risk Intelligence Scores and Subfactor data directly in ServiceNow's TPRM tables.
Learn more about SecurityScorecard for Vendor Risk Management
June
Custom Scoring in UI
You can now add and modify question-level scoring directly within the platform, with no CSV export or re-upload required.
Learn more about building a customized questionnaire template
Questionnaire Instruction PDF Attachments
You can now attach a PDF to any questionnaire you send, giving vendors instructions, process documentation, or compliance context before they begin responding.
Questionnaire Bulk Send via CSV
You can now send questionnaires in bulk to multiple recipients across multiple vendor organizations by uploading a CSV, instead of sending each one individually.
Learn more about sending a questionnaire to a vendor
Custom Fields in All Companies
You can now add up to 20 custom fields to your vendor list in All Companies, set admin visibility controls to show or hide fields, and filter and sort across them.
Learn more about managing your vendors using All Companies
Questionnaire Internal Comments
You can now add a questionnaire-level comment that's visible only to internal reviewers, to capture overall notes, context, or flags for an assessment without affecting the vendor-facing experience.
May
May 20, 2026 scoring recalibration
On May 20, 2026, we performed our quarterly scoring recalibration. In this recalibration, we decreased the impact of 2 issue types, increased the impact of 2 issue types, and retired 7 issue types.
Learn more about this scoring recalibration
MAX Questionnaires dashboard
A new Questionnaires dashboard is now available on the MAX Customer Portal. This is a read-only dashboard that pulls data from the Questionnaire module within the SecurityScorecard platform.
Learn more about Questionnaires in MAX
Ransomware Analytics Report Fix
The Ransomware Analytics widget now connects to the new, data-driven Ransomware Score, enabling more accurate and predictive insights for measuring supply chain business disruption risk.
April
Enhanced Breach Details
Our “Incidents” page now includes multiple source articles, evidence types, and score impacts all in one view and leverages an LLM to reduce duplicates and extract more comprehensive breach data.
Learn more about how to view breach incidents
Breach scoring impact change
We’ve introduced a breach scoring change where we differentiate between 1st and 3rd party breaches: 1st party impact unchanged starts at 10 points, 3rd party now starts at 5 points. This distinguishes between internal security gaps and indirect vendor risks, giving customers a more precise and actionable view of their true risk profile.
Learn more about how breaches affect scores
Korean language support
We have significantly expanded Korean language support across key areas of the SecurityScorecard platform. Full Korean language support is now available for critical platform sections, including Risk Quantification, Communication, Automation, and Threat Intelligence.
Rules for Custom Scorecards
You can now leverage automated actions and workflows for Custom Scorecards which are the same as those available for standard Scorecards,
Historic findings in MAX Incident Likelihood Assessment
Historical findings that continue to impact risk ratings are now listed in the MAX incident likelihood assessments.
Custom Scoring in UI
You can now add and modify question level scoring from within the UI.
Questionnaire Instruction PDF Attachments
You can now include a PDF file with your questionnaire that contains instructions and guidance for your organization’s assessment process.
Questionnaire Bulk Send via CSV
You now send questionnaires in bulk to multiple recipients at multiple vendor organizations.
March
AI Agents
10 specialized AI Agents are available within ChatSSC to analyze entire portfolios at scale, and perform deep-tier investigations like downstream breach mapping and remediation planning.
Learn how to get started with AI Agents
Filtering for Subresource Integrity Findings
We have introduced filtering for Subresource Integrity Findings so that large dynamic script providers Google Tag Manager, Adobe Tag Manager, and Google Fonts will not trigger Unsafe Implementation of Subresource Integrity findings.
Detection Capability for Websites with a 4xx Response
We have added detection capability for websites where a 4xx response is received but http headers still contain data relevant to the security posture of a domain.
Enhanced Detection for Cookie Missing http
We have enhanced our detection for Cookie Missing http Only so that it will not be applied for csrf or xsrf cookies.
Enhanced Trust Center functionality
SecurityScorecard is replacing legacy Trust Center capabilities with a more robust Trust Page powered by HyperComply. You can now tailor profiles, automate watermarking, and gain access to enterprise integrations. Evidence requests are automated and granular access audiences are integrated with enterprise tools. Direct Evidence Locker integration can be used to manage documents influencing security scores.
Questionnaire performance improvement
Latencies when working with large or complex questionnaires have been reduced from up to ~1 minute to less than 5 seconds on average.
External vendor ID in exports
External Vendor IDs have been added as a custom field to key areas of the platform, specifically within All Companies and various data exports. This update allows you to include their internal unique identifiers for joining SecurityScorecard data with other internal systems.
February
Recommend rules
You can now build automation rules without your natural workflow in the SecurityScorecard platform. Rule builder drawers are embedded directly in workflows with context-aware pre-population of triggers and rule snippets.
Learn how to create rules using the Rule Builder
Improved vendor detection
We have improved Automatic Vendor Detection (AVD) by introducing a dynamic discovery engine that automatically identifies a vast and growing landscape of digital technologies. This upgrade provides deeper insights into the products used by vendors across numerous categories, enabling customers to better understand their potential exposure and monitor crucial 4th parties.
Learn how to manage supply chain risk with Automatic Vendor Detection
February 18, 2026 scoring recalibration
On February 18, 2026, we performed our quarterly scoring recalibration. In this recalibration, we also decreased the impact of 3 issue types and increased the impact of 3 issue types.
Learn more about this scoring recalibration
Reporting Center automation
You can now automate recurring reports based on custom logic, perform bulk actions (generate, download, delete), and customize CSV exports to include only specific, relevant fields.
Learn how to automatically send recurring reports
Reports on historical data
You can now generate both canned and custom reports based on a specific date in the past.
Learn more about managing reports in Reporting Center
API endpoints for Breach Susceptibility Indicator
You can now ingest Breach Susceptibility Indicator data into your own stacks using an API endpoint.
Learn more about the Breach Susceptibility Indicator API endpoint