Skip to content
Calcrivo

Patch Priority Calculator

Rank a vulnerability for patching from EPSS probability, KEV listing, exploit maturity, asset criticality and exposure.

Inputs

%

Patch Priority Score

72.5/ 100

Priority Decision

Act — patch out of cycle

Target Remediation Window

3days

Threat Signal Contribution

42.5pts

Asset and Exposure Contribution

30.0pts

Next Step

Raise an emergency change and patch within 72 hours

Step by step

  1. Values used

    EPSS probability (30-day) = 22 %; Listed in CISA KEV = Yes; Exploit maturity = Functional exploit available; Asset criticality tier = Tier 2 — business important; Network exposure = Internet-facing; Vendor patch available = Yes; Compensating control already deployed = No

  2. Patch Priority

    Priority = EPSS% × 0.25 + 25 if KEV-listed + maturity points (0/6/12/18) + criticality tier × 5 + exposure points (0–15) − 10 if a compensating control is deployed, clamped to 0–100.

  3. Decision bands

    Score ≥ 70 Act, ≥ 50 Attend, ≥ 30 Track*, below that Track — the four SSVC stakeholder-specific decision outcomes.

  4. Patch Priority Score

    = 72.5 / 100

  5. Priority Decision

    = Act — patch out of cycle

  6. Target Remediation Window

    = 3 days

  7. Threat Signal Contribution

    = 42.5 pts

  8. Asset and Exposure Contribution

    = 30.0 pts

  9. Next Step

    = Raise an emergency change and patch within 72 hours

How it works

The score deliberately gives the threat side up to 68 points and the asset side up to 35, because whether a vulnerability is being exploited matters more than how bad it would be if it were. KEV listing alone contributes a quarter of the scale: a catalogued CVE has documented in-the-wild use, which no CVSS metric captures. A deployed compensating control buys a 10-point reduction, enough to move a borderline case out of an emergency change but never enough to close it. CVSS ranks the whole world's vulnerabilities identically; this ranks yours, which is the only ordering that makes a finite patching team effective.

Formulas

Patch Priority

Priority = EPSS% × 0.25 + 25 if KEV-listed + maturity points (0/6/12/18) + criticality tier × 5 + exposure points (0–15) − 10 if a compensating control is deployed, clamped to 0–100.

EPSS%
Probability of exploitation in the next 30 days
KEV
CISA Known Exploited Vulnerabilities catalogue
maturity
None, PoC, functional, weaponised
criticality
Tier 4 (1) to Tier 1 (4)

Decision bands

Score ≥ 70 Act, ≥ 50 Attend, ≥ 30 Track*, below that Track — the four SSVC stakeholder-specific decision outcomes.

Frequently Asked Questions

How is Patch Priority calculated?

Priority = EPSS% × 0.25 + 25 if KEV-listed + maturity points (0/6/12/18) + criticality tier × 5 + exposure points (0–15) − 10 if a compensating control is deployed, clamped to 0–100. The score deliberately gives the threat side up to 68 points and the asset side up to 35, because whether a vulnerability is being exploited matters more than how bad it would be if it were. KEV listing alone contributes a quarter of the scale: a catalogued CVE has documented in-the-wild use, which no CVSS metric captures. A deployed compensating control buys a 10-point reduction, enough to move a borderline case out of an emergency change but never enough to close it.

Why does Patch Priority matter?

CVSS ranks the whole world's vulnerabilities identically; this ranks yours, which is the only ordering that makes a finite patching team effective.

What values do I need to enter?

This calculator takes 7 inputs: EPSS probability (30-day), Listed in CISA KEV, Exploit maturity, Asset criticality tier, Network exposure, Vendor patch available, Compensating control already deployed. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Why not just patch everything with CVSS ≥ 7?

Because that is typically half your findings and a small fraction of your actual risk. Roughly a few per cent of published CVEs are ever exploited in the wild, and EPSS plus KEV identify most of them, so prioritising on exploitation evidence reduces breach probability far more per engineer-hour.

What if the vendor has no patch yet?

The score still tells you the urgency, and the next-step output switches to mitigation. Virtual patching, disabling the feature, tightening the network path or moving the asset behind authentication all buy time; do them at the same SLA the patch would have had.

You might also need