Skip to content
Calcrivo

Vulnerability Health Score Calculator

Roll MTTP, SLA compliance, scan coverage, open criticals and backlog age into one 0–100 health score with a grade.

Inputs

days
%
%
findings
days

Vulnerability Health Score

65.5/ 100

Grade

C — Fair

MTTP Component

55.0/ 100

SLA Component

78.0/ 100

Backlog Age Component

48.0/ 100

Weakest Component

Backlog age — the oldest critical has been open 95 days

Headline

Struggling — fix the weakest component before adding scope

Step by step

  1. Values used

    Critical MTTP = 22 days; SLA compliance = 78 %; Effective scan coverage = 84 %; Open criticals = 18 findings; Age of the oldest open critical = 95 days; Backlog trend over the last quarter = Flat — 0

  2. Vulnerability Health Score

    Health = 0.25 × MTTP component + 0.25 × SLA compliance + 0.20 × coverage + 0.15 × open-critical component + 0.15 × backlog-age component, plus a trend adjustment of ±8.

  3. Grade bands

    Grades: 90+ A Excellent, 75–89 B Good, 60–74 C Fair, 40–59 D Weak, below 40 F Critical.

  4. Vulnerability Health Score

    = 65.5 / 100

  5. Grade

    = C — Fair

  6. MTTP Component

    = 55.0 / 100

  7. SLA Component

    = 78.0 / 100

  8. Backlog Age Component

    = 48.0 / 100

  9. Weakest Component

    = Backlog age — the oldest critical has been open 95 days

How it works

Speed and discipline carry half the score between them because they are what actually shortens exposure; coverage is next because a finding you never see cannot be counted in either. The two backlog terms are deliberately harsh — one critical open for a year drags the score more than a dozen opened last week — and the trend adjustment stops a snapshot from hiding a programme that is quietly losing ground. One defensible number that decomposes into five drivers is what gets vulnerability management onto a management dashboard without a fortnightly argument about which metric to show.

Formulas

Vulnerability Health Score

Health = 0.25 × MTTP component + 0.25 × SLA compliance + 0.20 × coverage + 0.15 × open-critical component + 0.15 × backlog-age component, plus a trend adjustment of ±8.

MTTP component
100 − 3 × days beyond a 7-day benchmark
open-critical component
100 − 2.5 per open critical
backlog-age component
100 − 0.8 per day the oldest critical exceeds 30
trend
±8 for a shrinking or growing backlog

Grade bands

Grades: 90+ A Excellent, 75–89 B Good, 60–74 C Fair, 40–59 D Weak, below 40 F Critical.

Frequently Asked Questions

How is Vulnerability Health Score calculated?

Health = 0.25 × MTTP component + 0.25 × SLA compliance + 0.20 × coverage + 0.15 × open-critical component + 0.15 × backlog-age component, plus a trend adjustment of ±8. Speed and discipline carry half the score between them because they are what actually shortens exposure; coverage is next because a finding you never see cannot be counted in either. The two backlog terms are deliberately harsh — one critical open for a year drags the score more than a dozen opened last week — and the trend adjustment stops a snapshot from hiding a programme that is quietly losing ground.

Why does Vulnerability Health Score matter?

One defensible number that decomposes into five drivers is what gets vulnerability management onto a management dashboard without a fortnightly argument about which metric to show.

What values do I need to enter?

This calculator takes 6 inputs: Critical MTTP, SLA compliance, Effective scan coverage, Open criticals, Age of the oldest open critical, Backlog trend over the last quarter. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Is a single score not an oversimplification?

On its own, yes. It works because every component is published alongside it, so the conversation moves straight to the weakest driver instead of stalling on methodology. Never report the score without its components.

Why is the MTTP benchmark seven days?

Because it matches the critical SLA most regulated organisations commit to, and it is achievable with automated patch orchestration. Change it if your own SLA differs — the component simply penalises three points per day beyond whatever benchmark you set.

You might also need