Findings and risk
CVSS
Also called: Common Vulnerability Scoring System, CVSS score, CVSS 4.0
CVSS is an open standard for scoring the technical severity of a vulnerability from 0.0 to 10.0 based on characteristics such as attack vector, complexity and impact. It measures severity, not business risk.
The distinction matters when reading a report. A CVSS 9.8 on a system with no data and no network path is less urgent than a 6.5 on the authentication path of your main product. A report that ranks only by CVSS has moved the prioritization work onto you.
Sources
See also
Testing, with the report an auditor can actually use
A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.