What is a scoring recalibration?
We regularly recalibrate our scoring algorithm to ensure that scores accurately reflect the cybersecurity landscape. During a recalibration, we may add new issue types, retire existing ones, and adjust breach risk and threat levels based on updated risk signals.
We notify customers in advance of each recalibration and of any potential impact on scores.
When does this recalibration take effect?
This recalibration will take effect on November 24, 2026.
Learn more about the upcoming changes and how to prepare for the recalibration in our live webinar happening on Oct 28 2026, 12:00pm EDT.
How will my score be impacted?
You'll see a banner at the top of the Company Overview page for each Scorecard indicating the projected impact of this recalibration.
- If your score is expected to change, the banner shows the projected increase or decrease.
- If your score is not expected to change, the banner will indicate it remains the same.
In addition to the banner, the Issues table includes a Recalibrated impact column that shows each issue's post-recalibration impact.
If you have any questions about how this recalibration affects your Scorecard, please reach out to our Support team or your Customer Success Manager.
What is changing on November 24, 2026?
The table below summarizes changes to threat levels and breach risk for the issue types affected by this recalibration.
For scorecards impacted by this recalibration, the average score change is ▲+0.49 points.
| Issue Type | Threat level change | Breach risk change | Impact | Reason for change |
|
Critical-Severity CVSS v3.0 Service Vulnerability in Last Observation (service_vuln_host_v3_critical) |
Low → Low | High → High | 📈 Increase | Actively running services with known critical-severity CVEs are a leading target for exploitation, and this issue's correlation with breaches has strengthened in current threat data. |
Details and recommendations
The following section provides recommendations for each issue type.
Critical-Severity CVSS v3.0 Service Vulnerability in Last Observation
Update or patch affected software and hardware. Enable automatic updates if available from your software vendor and permitted in your environment. Monitor CVE lists and vulnerability repositories for exploit code that may affect your infrastructure. Maintain a regular update schedule for all software and hardware in use within your organization, ensuring that all the latest patches are applied soon after they are released.
Retired issue types
The following issue types have been removed from the platform. The following issue types have been removed from the platform and are no longer scored.
| Issue type | Status |
| Server error detected (server_error) | 🚫 |
|
Product Potentially Impacted by CVE-2022-41040 & CVE-2022-41082 (microsoft_exchange_0_day_vulnerability) |
🚫 |
Frequently Asked Questions
Q1. Why do scoring recalibrations happen?
- To ensure scores accurately reflect the dynamic elements of the cybersecurity landscape.
- To normalize scoring between organizations of different sizes, with differing digital footprints.
Q2. Where can I see the projected impact of the recalibration?
- A banner appears at the top of both the Company Overview and Issues pages for each Scorecard, showing what your score will be after the recalibration.
- This projected score is a snapshot in time and may change as issues are detected or remediated, just like your current score.
Q3. How can I improve my score ahead of the recalibration?
- Scores can be improved the same way they do today - by remediating detected issues.
- Only issues present on your scorecard at the time of the recalibration will be considered.
Q4. Why is my score projected to drop even though I have the same number of issues?
- During a recalibration, the breach risk or weight of certain issue types may change. Even if the total number of issues stays the same, changes in how those issues are weighted can impact your score.
Q5. Why are these issue types changing now?
- The score impact, threat level, and breach risk for certain issue types have been updated to better reflect their correlation with breach, based on current data. These correlations change over time as the cybersecurity landscape evolves.
- Score impact also varies by organization. Factors such as company size, digital footprint, and affected assets influence how changes to an issue type affect your overall score.
Q6. Are any new issue types being added as a part of this recalibration?
- No. This recalibration does not introduce any new issue types.
Q7. Does this recalibration change how issues and findings are scanned or detected?
- No, recalibration does not impact scanning cadence or issue detection.
Q8. Why does the downloaded report show higher-impact issue types that aren't listed as changed?
The issue types listed in the table above are the only ones whose defined impact level changed as part of this recalibration. For these issue types, each occurrence will decrease the score either more (increasing impact) or less (decreasing impact) than before, regardless of digital footprint, organizational size, or the presence of other issues.
However, SecurityScorecard scoring is not based only on fixed impact levels. Your score is also influenced by how your organization compares with similar organizations (your peer cohort), which are grouped by size and digital footprint.
During a recalibration, we:
- Reevaluate peer cohort groupings
- Reassess how common each issue type is within those cohorts
Because scoring is partly based on relative comparisons, an individual issue's score contribution can change even when the inherent impact of that issue type remains unchanged.
For example:
If your organization has grown or reduced its digital footprint since the previous recalibration, you may now be compared against a different peer group.
If the overall distribution of a specific issue type changes within your cohort, its relative scoring may increase or decrease.
If you have more of a specific issue than your peers, it may contribute more strongly to your score.
If you have fewer than your peers, it may contribute less.
Q9. I have more questions - where can I get answers?
- We value your feedback! If you have questions about this recalibration or how it affects your Scorecard, contact Support or your Customer Success Manager.
For details on how our scoring works, see our Scoring Methodology Whitepaper.