Security Hub Score Calculator
Reproduce the AWS Security Hub score: passed controls over enabled controls per standard, averaged, with a severity-weighted view of the failures.
Inputs
Overall Security Score
75.9%
Grade
B — Good
FSBP Standard Score
76.4%
CIS Standard Score
74.6%
PCI DSS Standard Score
76.7%
Failing Controls
83controls
Severity-Weighted Failure Load
165points
Controls per 5 Score Points
18controls
Disabled Control Share
3.3%
Verdict
Critical control failures outrank the headline score — fix those before optimising the percentage
Step by step
Values used
AWS Foundational Security Best Practices controls enabled = 246 controls; FSBP controls passing = 188 controls; CIS AWS Foundations controls enabled = 59 controls; CIS controls passing = 44 controls; PCI DSS controls enabled = 43 controls; PCI DSS controls passing = 33 controls; Controls disabled across all standards = 12 controls; Failed controls at critical severity = 6 controls; Failed controls at high severity = 21 controls
Security Hub Score
Standard score = passed controls ÷ enabled controls × 100. Overall score = the arithmetic mean of the enabled standard scores, exactly as Security Hub computes it.
Severity weighting
Severity-weighted failure load = 10 × critical failures + 5 × high failures — the view the score itself hides, since every control counts equally in the percentage.
Overall Security Score
= 75.9
Grade
= B — Good
FSBP Standard Score
= 76.4
CIS Standard Score
= 74.6
PCI DSS Standard Score
= 76.7
Failing Controls
= 83 controls
How it works
Security Hub averages standard scores rather than pooling controls, so a small standard moves the number as much as a large one — fifteen failures out of 59 CIS controls costs the same as sixty out of 246 FSBP controls. Because every control counts equally within a standard, the severity-weighted load is reported alongside to show which failures actually matter. The Security Hub percentage is what leadership sees on the dashboard, and it can climb steadily while the six critical failures that would end the company sit untouched.
Formulas
Security Hub Score
Standard score = passed controls ÷ enabled controls × 100. Overall score = the arithmetic mean of the enabled standard scores, exactly as Security Hub computes it.
- fsbpScore
- Passed ÷ enabled FSBP controls × 100
- securityScore
- Mean of the enabled standard scores
- failedControls
- Enabled controls not passing across all standards
Severity weighting
Severity-weighted failure load = 10 × critical failures + 5 × high failures — the view the score itself hides, since every control counts equally in the percentage.
- criticalFailed
- Failed controls whose severity label is CRITICAL
- highFailed
- Failed controls whose severity label is HIGH
Frequently Asked Questions
How is Security Hub Score calculated?
Standard score = passed controls ÷ enabled controls × 100. Overall score = the arithmetic mean of the enabled standard scores, exactly as Security Hub computes it. Security Hub averages standard scores rather than pooling controls, so a small standard moves the number as much as a large one — fifteen failures out of 59 CIS controls costs the same as sixty out of 246 FSBP controls. Because every control counts equally within a standard, the severity-weighted load is reported alongside to show which failures actually matter.
Why does Security Hub Score matter?
The Security Hub percentage is what leadership sees on the dashboard, and it can climb steadily while the six critical failures that would end the company sit untouched.
What values do I need to enter?
This calculator takes 9 inputs: AWS Foundational Security Best Practices controls enabled, FSBP controls passing, CIS AWS Foundations controls enabled, CIS controls passing, PCI DSS controls enabled, PCI DSS controls passing, Controls disabled across all standards, Failed controls at critical severity, Failed controls at high severity. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Why does disabling controls raise my score?
Because the denominator is enabled controls, not applicable controls. Disabling a standard you keep failing is a legitimate scoping decision and also the single easiest way to manufacture improvement, which is why the disabled share is shown here as a first-class number.
Does one control map to one resource?
No. A control is evaluated against every resource in scope and reports pass or fail as an aggregate, so a single failing control can represent one non-compliant bucket or four hundred. Always read the finding count next to the control count before planning the work.
You might also need
- Cloud Compliance CalculatorCommonly used together
- GCP Security Command Center CalculatorCommonly used together
- Azure Secure Score CalculatorCommonly used together
- Cloud Security Health Score CalculatorAlso in Cloud Security
- Cloud IAM Risk CalculatorAlso in Cloud Security
- Cloud Security Group CalculatorAlso in Cloud Security