Skip to main content

Methodology 1.0

How ServiceSignal scoring works

Each assessment applies published weights and thresholds to your answers, then keeps the overall score, dimension detail, red flags, and evidence gaps visible together.

Version 1.0Effective 29 September 2026Review owner: ServiceSignal product owner

Design principles

A transparent decision aid

Deterministic

The same answers under the same methodology version always produce the same score. No generative AI or hidden reviewer judgement changes the result.

Evidence-led

A positive answer should be supported by a current document, record, configuration, test, or repeatable operating practice.

Decision-focused

Higher weights sit on controls whose absence changes confidence or the next decision more materially.

Indicative

The result structures a conversation and priorities. It is not certification, legal advice, an audit opinion, or proof that a control operates effectively.

Answer weights

Twenty-five points per dimension

Every dimension contains four questions. A Yes receives the full question weight, Partial receives a reduced score, and No receives zero. The four maximum weights add up to 25.

Question roleYesPartialNo
Primary control1050
Supporting control840
Standard control420
Supporting detail310

The overall percentage is round(raw score / maximum raw score x 100). This prevents assessments with different numbers of dimensions from being compared on raw points alone.

Assessment thresholds

Bands reflect the decision being made

The shared weight model stays constant, but labels and thresholds differ because MSSP assurance, AI adoption, supplier approval, and incident readiness are different decisions.

MSSP Reality Check

6 dimensions, 150 maximum raw points

View assessment overview →
Verified85-100
Credible70-84
Developing50-69
At Risk0-49

A No answer to a primary or supporting control is shown as a red flag.

AI Readiness Check

6 dimensions, 150 maximum raw points

View assessment overview →
Ready85-100
Controlled70-84
Exposed50-69
Uncontrolled0-49

A No or Not sure answer is flagged when the question is marked as a red flag or is a primary or supporting control.

Supplier Security Reality Check

7 dimensions, 175 maximum raw points

View assessment overview →
Low70-100
Medium45-69
High0-44

A No answer to a primary or supporting control is a red flag and can change a Medium result from Conditional Approval to Escalate for Review.

Incident Readiness Reality Check

8 dimensions, 200 maximum raw points

View assessment overview →
Ready80-100
Mostly Ready60-79
Exposed40-59
Critical0-39

Weak answers reduce the dimension score and drive the prioritised gaps, tabletop scenario, and executive action plan.

Evidence expectations

A Yes should be demonstrable

A policy title or verbal assurance is not enough on its own. Look for evidence that is current, owned, repeatable, and connected to the environment or service being assessed.

  • Current scope, asset, supplier, or approved-tool records
  • Detection catalogues, test results, incident exercises, and change logs
  • Contracts, service levels, escalation paths, and review minutes
  • Policies with named owners, approval dates, exceptions, and review dates

Interpretation boundary

Read the detail, not only the number

Reports preserve dimension scores, individual answers, notes, and red flags because one material gap can matter more than an acceptable average. Results depend on the completeness and accuracy of the information supplied and should be checked against evidence before a procurement, risk, security, or governance decision.

ServiceSignal does not use the score to make a legal or similarly significant decision about an individual. See the Terms of Use for the full service limitations.

Common questions

Using the result responsibly

Is a ServiceSignal score a certification or audit opinion?

No. It is an indicative result based on the answers supplied. It helps identify where evidence or challenge is needed, but it does not independently verify a provider, control, or organisation.

Why are some questions worth more points?

Primary and supporting controls have greater operational impact. Their absence can undermine an entire dimension, so the model gives them more influence than supporting detail.

What should I do when I cannot verify an answer?

Use the least favourable answer that is supported by what you know and record the missing evidence in the notes. In the AI check, Not sure scores zero and may be treated as a red flag.

Can a strong overall score hide an important weakness?

It can, which is why reports show every dimension, key-question red flags, evidence gaps, and notes alongside the overall band. The headline score should never be read on its own.

How are methodology changes handled?

Material changes receive a new version and effective date. Sample reports and public explanations are checked against the exported scoring constants before release.