Work out scan coverage percentage instantly with clear inputs, formula shown and shareable results.
Coverage has two dimensions that are frequently conflated. Breadth is the share of the inventory reached at all, and unscanned assets are pure blind spots. Depth is the share scanned with credentials, since unauthenticated scans miss most client-side and configuration issues. Frequency sets the blind window: with weekly scans, a new vulnerability goes unnoticed for an average of three and a half days.
Coverage metrics
coverage = scanned / inventory; authenticated coverage = credentialed scans / inventory; average blind window = scan interval / 2
Unauthenticated scans see only what the network exposes. Missing patches, weak local configuration and installed-software inventory require credentials, and coverage without them overstates assurance.
That is the harder problem. Coverage measured against an incomplete inventory looks excellent while whole environments go unseen, so reconcile against cloud APIs and network discovery.