Patch Priority Calculator
Rank a vulnerability for patching from EPSS probability, KEV listing, exploit maturity, asset criticality and exposure.
Inputs
Patch Priority Score
72.5/ 100
Priority Decision
Act — patch out of cycle
Target Remediation Window
3days
Threat Signal Contribution
42.5pts
Asset and Exposure Contribution
30.0pts
Next Step
Raise an emergency change and patch within 72 hours
Step by step
Values used
EPSS probability (30-day) = 22 %; Listed in CISA KEV = Yes; Exploit maturity = Functional exploit available; Asset criticality tier = Tier 2 — business important; Network exposure = Internet-facing; Vendor patch available = Yes; Compensating control already deployed = No
Patch Priority
Priority = EPSS% × 0.25 + 25 if KEV-listed + maturity points (0/6/12/18) + criticality tier × 5 + exposure points (0–15) − 10 if a compensating control is deployed, clamped to 0–100.
Decision bands
Score ≥ 70 Act, ≥ 50 Attend, ≥ 30 Track*, below that Track — the four SSVC stakeholder-specific decision outcomes.
Patch Priority Score
= 72.5 / 100
Priority Decision
= Act — patch out of cycle
Target Remediation Window
= 3 days
Threat Signal Contribution
= 42.5 pts
Asset and Exposure Contribution
= 30.0 pts
Next Step
= Raise an emergency change and patch within 72 hours
How it works
The score deliberately gives the threat side up to 68 points and the asset side up to 35, because whether a vulnerability is being exploited matters more than how bad it would be if it were. KEV listing alone contributes a quarter of the scale: a catalogued CVE has documented in-the-wild use, which no CVSS metric captures. A deployed compensating control buys a 10-point reduction, enough to move a borderline case out of an emergency change but never enough to close it. CVSS ranks the whole world's vulnerabilities identically; this ranks yours, which is the only ordering that makes a finite patching team effective.
Formulas
Patch Priority
Priority = EPSS% × 0.25 + 25 if KEV-listed + maturity points (0/6/12/18) + criticality tier × 5 + exposure points (0–15) − 10 if a compensating control is deployed, clamped to 0–100.
- EPSS%
- Probability of exploitation in the next 30 days
- KEV
- CISA Known Exploited Vulnerabilities catalogue
- maturity
- None, PoC, functional, weaponised
- criticality
- Tier 4 (1) to Tier 1 (4)
Decision bands
Score ≥ 70 Act, ≥ 50 Attend, ≥ 30 Track*, below that Track — the four SSVC stakeholder-specific decision outcomes.
Frequently Asked Questions
How is Patch Priority calculated?
Priority = EPSS% × 0.25 + 25 if KEV-listed + maturity points (0/6/12/18) + criticality tier × 5 + exposure points (0–15) − 10 if a compensating control is deployed, clamped to 0–100. The score deliberately gives the threat side up to 68 points and the asset side up to 35, because whether a vulnerability is being exploited matters more than how bad it would be if it were. KEV listing alone contributes a quarter of the scale: a catalogued CVE has documented in-the-wild use, which no CVSS metric captures. A deployed compensating control buys a 10-point reduction, enough to move a borderline case out of an emergency change but never enough to close it.
Why does Patch Priority matter?
CVSS ranks the whole world's vulnerabilities identically; this ranks yours, which is the only ordering that makes a finite patching team effective.
What values do I need to enter?
This calculator takes 7 inputs: EPSS probability (30-day), Listed in CISA KEV, Exploit maturity, Asset criticality tier, Network exposure, Vendor patch available, Compensating control already deployed. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why not just patch everything with CVSS ≥ 7?
Because that is typically half your findings and a small fraction of your actual risk. Roughly a few per cent of published CVEs are ever exploited in the wild, and EPSS plus KEV identify most of them, so prioritising on exploitation evidence reduces breach probability far more per engineer-hour.
What if the vendor has no patch yet?
The score still tells you the urgency, and the next-step output switches to mitigation. Virtual patching, disabling the feature, tightening the network path or moving the asset behind authentication all buy time; do them at the same SLA the patch would have had.
You might also need
- Exploit Probability CalculatorCommonly used together
- Asset Criticality CalculatorCommonly used together
- CVE Severity CalculatorCommonly used together
- Threat Intelligence Coverage CalculatorCommonly used together
- Asset Exposure CalculatorCommonly used together
- CVSS v4 Score CalculatorCommonly used together