Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
26 criteria
baselineWhat is the specific scope of scanning this platform performs (network/infrastructure, web application, container/image, cloud configuration, code/SCA) — is this a broad general-purpose scanner or focused deeply on one surface, and how does that compare to the customer's actual highest-priority exposure?
baselineDescribe scan frequency and triggering model — continuous/always-on versus scheduled periodic scans versus on-demand only — and what the practical exposure window is between a new vulnerability appearing and the platform detecting it.
baselineWhat is the false-positive rate at default scan sensitivity, and what tuning/suppression workflow exists so a confirmed false positive doesn't resurface on every subsequent scan requiring repeated manual re-triage?
baselineHow does the platform prioritize findings beyond raw severity score — exploitability, asset criticality/business context, exposure to the internet — and quantify the reduction in 'must-fix-now' volume versus a raw severity-only approach with a customer reference.
baselineDetail remediation workflow integration — automated ticket creation with SLA tracking by severity, verification re-scan confirming a fix actually worked — versus a static report the security team must manually convert into tracked remediation work.
baselineWhat is the scan's performance/availability impact on the systems being scanned, particularly for production environments — has the platform ever caused a production incident during scanning, and what safeguards (rate limiting, safe-mode scanning) exist to prevent that?
baselineWhat is the pricing model — per asset scanned, per scan, or a flat enterprise tier — and how does cost scale as the organization's asset count and scan frequency both grow?
baselineWhen a scan finding indicates active exploitation risk during a genuine incident window (not routine periodic scanning), is there a fast-track escalation path distinct from the standard findings queue, and what is a customer-referenced example?
baselineWhat compliance-evidence generation exists showing scanning coverage was active and comprehensive (for a PCI DSS or similar audit requirement), and is this a built-in exportable report or something the security team must assemble manually?
baselineDetail historical trend reporting on scan findings and remediation-velocity trends over time, suitable for demonstrating program maturity to leadership.
baselineWho within the organization gets access to scan findings, and is there role-based access control given that a comprehensive vulnerability report is itself a roadmap of exploitable weaknesses if it fell into the wrong hands?
baselineHow consistent is scanning depth across multi-cloud/hybrid environments — is coverage equally deep across on-prem, AWS, Azure, and GCP, or meaningfully shallower for one environment?
baselineWhat API/automation depth exists beyond the built-in console — can scans be triggered and results consumed programmatically as part of the customer's own CI/CD or infrastructure-as-code workflows?
baselineWhat migration support exists for moving from an incumbent scanner — can historical findings, suppression rules, and asset context be imported rather than starting from a blank slate, and what is a customer-referenced migration timeline?
baselineConduct a comprehensive analysis of existing applications, application development and testing practices, and tools (e.g. HP Fortify, F5 Web Application Firewall) from a security standpoint and provide detailed findings and recommendations.
baselineAdditional methods, especially automated ones, should be suggested to the organization's IT team and will be potentially considered value-add.
baselineDevelop an Application Security Policy; develop source control policy and procedures; develop database access security and procedures; review current application implementation (release management) procedures and provide recommendations.
baselineScan existing code repository, identify the vulnerabilities, group them by severity (Critical, High, Medium, Low), recommend the best remediation approach, and provide a report.
baselineDescribe what the vendor could offer to help remediate any of the problems identified during the assessment.
baselineProvide sample deliverables. This includes reports, project plans, mitigation plans, and other services.
baselineProvide a knowledge transfer plan that includes what the vendor accomplished and an overview of how it was accomplished.
baselinePerform analysis (automated or otherwise) of the organization's application portfolio to identify and remediate vulnerabilities and flaws in software that may lead to security breaches.
baselineExamine (code review) source code to identify, detect, and report weaknesses that can lead to security vulnerabilities.
baselineDescribe your web application security standards. Do you meet OWASP standards?
baselineVendor's web applications must meet OWASP Application Security Verification Standards (ASVS); Vendor will perform adequate testing prior to releasing updates, modifications, or new functionality to software.
baselineVendor shall ensure that all Vendor applications are developed with secure coding best practices, such as the OWASP Top 10 Most Critical Web Application Security Risks.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat is the specific scope of scanning this platform performs (network/infrastructure, web application, container/image, cloud configuration, code/SCA) — is this a broad general-purpose scanner or focused deeply on one surface, and how does that compare to the customer's actual highest-priority exposure?Answer key — what a strong answer shows
"Security scanning" spans many different surfaces; ask the vendor to be specific about scope rather than accepting a broad, undifferentiated claim, and match it against the buyer's actual priority gap.
RFPDescribe scan frequency and triggering model — continuous/always-on versus scheduled periodic scans versus on-demand only — and what the practical exposure window is between a new vulnerability appearing and the platform detecting it.Answer key — what a strong answer shows
Continuous or event-triggered (e.g., on every deploy) scanning materially shrinks the exposure window versus weekly/monthly scheduled scans; ask for the platform's actual default cadence, not just the fastest option available.
RFIWhat is the false-positive rate at default scan sensitivity, and what tuning/suppression workflow exists so a confirmed false positive doesn't resurface on every subsequent scan requiring repeated manual re-triage?Answer key — what a strong answer shows
A vendor unable to state an approximate false-positive rate likely hasn't measured production accuracy; persistent suppression (not requiring re-triage every scan) is a meaningful practical usability requirement.
RFIHow does the platform prioritize findings beyond raw severity score — exploitability, asset criticality/business context, exposure to the internet — and quantify the reduction in 'must-fix-now' volume versus a raw severity-only approach with a customer reference.Answer key — what a strong answer shows
Context-aware prioritization (not just CVSS relabeling) is the real differentiator between a basic scanner and a mature risk-prioritization platform; ask for a concrete reduction figure from a named customer.
Detail remediation workflow integration — automated ticket creation with SLA tracking by severity, verification re-scan confirming a fix actually worked — versus a static report the security team must manually convert into tracked remediation work.
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
RFP
Answer key — what a strong answer shows
Closed-loop remediation (automatic verification a fix worked) is materially stronger than a one-time scan report requiring the customer to build their own tracking and verification process around it.
RFIWhat is the scan's performance/availability impact on the systems being scanned, particularly for production environments — has the platform ever caused a production incident during scanning, and what safeguards (rate limiting, safe-mode scanning) exist to prevent that?Answer key — what a strong answer shows
Aggressive scanning can itself cause outages in fragile production systems; a credible vendor discusses real safeguards (throttling, non-intrusive scan modes) rather than dismissing the risk.
RFIWhat is the pricing model — per asset scanned, per scan, or a flat enterprise tier — and how does cost scale as the organization's asset count and scan frequency both grow?Answer key — what a strong answer shows
Look for transparent, predictable scaling economics; a vendor unable to project cost at meaningfully higher asset count creates real budget risk for a growing environment.
RFPWhen a scan finding indicates active exploitation risk during a genuine incident window (not routine periodic scanning), is there a fast-track escalation path distinct from the standard findings queue, and what is a customer-referenced example?Answer key — what a strong answer shows
A finding indicating imminent or active exploitation deserves faster handling than routine scan-report triage — ask for a specific fast-track mechanism and a real customer example.
RFIWhat compliance-evidence generation exists showing scanning coverage was active and comprehensive (for a PCI DSS or similar audit requirement), and is this a built-in exportable report or something the security team must assemble manually?Answer key — what a strong answer shows
Native compliance-evidence generation is materially more valuable than raw scan output requiring manual compilation for every audit cycle.
RFPDetail historical trend reporting on scan findings and remediation-velocity trends over time, suitable for demonstrating program maturity to leadership.Answer key — what a strong answer shows
Trend-over-time reporting is a distinct capability from a per-scan report — confirm this exists as a maintained, exportable report.
RFIWho within the organization gets access to scan findings, and is there role-based access control given that a comprehensive vulnerability report is itself a roadmap of exploitable weaknesses if it fell into the wrong hands?Answer key — what a strong answer shows
A complete scan-findings report is a meaningful target in its own right — role-based access control over this specific asset is an often-overlooked consideration.
RFIHow consistent is scanning depth across multi-cloud/hybrid environments — is coverage equally deep across on-prem, AWS, Azure, and GCP, or meaningfully shallower for one environment?Answer key — what a strong answer shows
Ask for an honest per-environment coverage breakdown; uneven scanning coverage across environments is a common real gap a vendor should disclose rather than obscure.
RFPWhat API/automation depth exists beyond the built-in console — can scans be triggered and results consumed programmatically as part of the customer's own CI/CD or infrastructure-as-code workflows?Answer key — what a strong answer shows
A real, documented API/IaC-integration capability is materially more useful for a mature DevOps organization than console-only scan management.
RFIWhat migration support exists for moving from an incumbent scanner — can historical findings, suppression rules, and asset context be imported rather than starting from a blank slate, and what is a customer-referenced migration timeline?Answer key — what a strong answer shows
Strong answers describe real migration tooling and a concrete, customer-validated timeline; a vendor with no migration story is asking the customer to manually rebuild potentially years of accumulated tuning and context from scratch.
RFPConduct a comprehensive analysis of existing applications, application development and testing practices, and tools (e.g. HP Fortify, F5 Web Application Firewall) from a security standpoint and provide detailed findings and recommendations.
RFPAdditional methods, especially automated ones, should be suggested to the organization's IT team and will be potentially considered value-add.
RFPDevelop an Application Security Policy; develop source control policy and procedures; develop database access security and procedures; review current application implementation (release management) procedures and provide recommendations.
RFPScan existing code repository, identify the vulnerabilities, group them by severity (Critical, High, Medium, Low), recommend the best remediation approach, and provide a report.
RFPDescribe what the vendor could offer to help remediate any of the problems identified during the assessment.
RFPProvide sample deliverables. This includes reports, project plans, mitigation plans, and other services.
RFPProvide a knowledge transfer plan that includes what the vendor accomplished and an overview of how it was accomplished.
RFPPerform analysis (automated or otherwise) of the organization's application portfolio to identify and remediate vulnerabilities and flaws in software that may lead to security breaches.
RFPExamine (code review) source code to identify, detect, and report weaknesses that can lead to security vulnerabilities.
RFPDescribe your web application security standards. Do you meet OWASP standards?
RFPVendor's web applications must meet OWASP Application Security Verification Standards (ASVS); Vendor will perform adequate testing prior to releasing updates, modifications, or new functionality to software.
RFIVendor shall ensure that all Vendor applications are developed with secure coding best practices, such as the OWASP Top 10 Most Critical Web Application Security Risks.