ClearPenTest

Findings and risk

CVSS

Also called: Common Vulnerability Scoring System, CVSS score, CVSS 4.0

CVSS is an open standard for scoring the technical severity of a vulnerability from 0.0 to 10.0 based on characteristics such as attack vector, complexity and impact. It measures severity, not business risk.

The distinction matters when reading a report. A CVSS 9.8 on a system with no data and no network path is less urgent than a 6.5 on the authentication path of your main product. A report that ranks only by CVSS has moved the prioritization work onto you.

Testing, with the report an auditor can actually use

A fixed price, a date, and a report that states scope, method and closure. No discovery call required to get a number.