Vulnerability Health Score Calculator
Roll MTTP, SLA compliance, scan coverage, open criticals and backlog age into one 0–100 health score with a grade.
Inputs
Vulnerability Health Score
65.5/ 100
Grade
C — Fair
MTTP Component
55.0/ 100
SLA Component
78.0/ 100
Backlog Age Component
48.0/ 100
Weakest Component
Backlog age — the oldest critical has been open 95 days
Headline
Struggling — fix the weakest component before adding scope
Step by step
Values used
Critical MTTP = 22 days; SLA compliance = 78 %; Effective scan coverage = 84 %; Open criticals = 18 findings; Age of the oldest open critical = 95 days; Backlog trend over the last quarter = Flat — 0
Vulnerability Health Score
Health = 0.25 × MTTP component + 0.25 × SLA compliance + 0.20 × coverage + 0.15 × open-critical component + 0.15 × backlog-age component, plus a trend adjustment of ±8.
Grade bands
Grades: 90+ A Excellent, 75–89 B Good, 60–74 C Fair, 40–59 D Weak, below 40 F Critical.
Vulnerability Health Score
= 65.5 / 100
Grade
= C — Fair
MTTP Component
= 55.0 / 100
SLA Component
= 78.0 / 100
Backlog Age Component
= 48.0 / 100
Weakest Component
= Backlog age — the oldest critical has been open 95 days
How it works
Speed and discipline carry half the score between them because they are what actually shortens exposure; coverage is next because a finding you never see cannot be counted in either. The two backlog terms are deliberately harsh — one critical open for a year drags the score more than a dozen opened last week — and the trend adjustment stops a snapshot from hiding a programme that is quietly losing ground. One defensible number that decomposes into five drivers is what gets vulnerability management onto a management dashboard without a fortnightly argument about which metric to show.
Formulas
Vulnerability Health Score
Health = 0.25 × MTTP component + 0.25 × SLA compliance + 0.20 × coverage + 0.15 × open-critical component + 0.15 × backlog-age component, plus a trend adjustment of ±8.
- MTTP component
- 100 − 3 × days beyond a 7-day benchmark
- open-critical component
- 100 − 2.5 per open critical
- backlog-age component
- 100 − 0.8 per day the oldest critical exceeds 30
- trend
- ±8 for a shrinking or growing backlog
Grade bands
Grades: 90+ A Excellent, 75–89 B Good, 60–74 C Fair, 40–59 D Weak, below 40 F Critical.
Frequently Asked Questions
How is Vulnerability Health Score calculated?
Health = 0.25 × MTTP component + 0.25 × SLA compliance + 0.20 × coverage + 0.15 × open-critical component + 0.15 × backlog-age component, plus a trend adjustment of ±8. Speed and discipline carry half the score between them because they are what actually shortens exposure; coverage is next because a finding you never see cannot be counted in either. The two backlog terms are deliberately harsh — one critical open for a year drags the score more than a dozen opened last week — and the trend adjustment stops a snapshot from hiding a programme that is quietly losing ground.
Why does Vulnerability Health Score matter?
One defensible number that decomposes into five drivers is what gets vulnerability management onto a management dashboard without a fortnightly argument about which metric to show.
What values do I need to enter?
This calculator takes 6 inputs: Critical MTTP, SLA compliance, Effective scan coverage, Open criticals, Age of the oldest open critical, Backlog trend over the last quarter. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is a single score not an oversimplification?
On its own, yes. It works because every component is published alongside it, so the conversation moves straight to the weakest driver instead of stalling on methodology. Never report the score without its components.
Why is the MTTP benchmark seven days?
Because it matches the critical SLA most regulated organisations commit to, and it is achievable with automated patch orchestration. Change it if your own SLA differs — the component simply penalises three points per day beyond whatever benchmark you set.
You might also need
- Vulnerability Management Maturity CalculatorCommonly used together
- Mean Time to Patch CalculatorCommonly used together
- Patch Compliance CalculatorCommonly used together
- Patch Priority CalculatorAlso in Vulnerability Management
- CVSS v3 Score CalculatorAlso in Vulnerability Management
- Scanner Coverage CalculatorAlso in Vulnerability Management