Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
44 criteria
baselineWhat asset and scan coverage does the platform provide out of the box — network/infrastructure, web application, cloud (CSPM-adjacent), container images, and code/SCA — and which require separate agents or licenses?
baselineDescribe the prioritization methodology beyond raw CVSS (exploit-in-the-wild data, asset criticality/business context, exposure/reachability analysis) and quantify the reduction in 'must-fix' volume versus CVSS-only triage with a customer reference.
baselineHow frequently are external attack-surface and internal scans performed by default, and is continuous/agent-based scanning available versus periodic scheduled scans only?
baselineWhat remediation workflow integration exists (ticketing auto-creation, SLA tracking by severity, verification re-scan on fix), and can remediation be automated (e.g., patch orchestration), or is it detection-only?
baselineDetail how the platform handles vulnerability data for cloud-native and ephemeral assets (containers, serverless, autoscaling groups) where traditional agent-based scanning is impractical.
baselineWhat is the false-positive rate for the default scan configuration, and what mechanism exists for analysts to permanently suppress a confirmed false positive without it reappearing on the next scan?
baselineExplain risk-based reporting for executives/board — can risk be expressed in business terms (e.g., financial exposure, industry benchmarking) rather than raw vulnerability counts, and is this a built-in report or custom BI work?
baselineHow does the product handle zero-day and newly disclosed CVEs before an authenticated scan can confirm exposure — is there an interim exposure estimate based on asset inventory/version data already collected?
baselineHow is authenticated/credentialed scanning handled — does the platform integrate with an existing credential vault (CyberArk, HashiCorp Vault) for scan credentials, or does it require storing credentials directly within the platform, and what is the security model for that storage?
baselineDescribe safety mechanisms for scanning OT/ICS or other fragile legacy environments — is there a passive/non-intrusive scanning mode, and can the vendor cite a real incident where active scanning caused a production outage and what changed afterward?
baselineIs the platform a PCI-approved Scanning Vendor (ASV) for external quarterly compliance scans, and does it generate audit-ready compliance reports for PCI DSS, HIPAA, or other frameworks directly, or does that require manual report assembly?
baselineExplain how findings incorporate EPSS (Exploit Prediction Scoring System) alongside or instead of raw CVSS, and provide a concrete example of how EPSS changed a real prioritization decision for a customer.
baselineWhat is the pricing model — per asset, per IP, per scan, or a flat enterprise tier — and how does cost change when the customer's asset count grows significantly (e.g., cloud auto-scaling doubles the environment) mid-contract?
baselineWhat is the measured performance impact of an active scan on production systems (network bandwidth, target-host CPU/latency), and can scan intensity/throttling be configured per asset criticality?
baselineDetail non-CVE software inventory and end-of-life tracking — does the platform flag unsupported/EOL software versions even when no active CVE exists yet, and how comprehensive is the installed-software catalog versus just known-vulnerable packages?
baselineHow does the platform handle vulnerability data for third-party/vendor-supplied software where the customer has no source-code visibility (SCA-adjacent but for compiled/commercial software), and how is that reconciled with the vendor's own patch release cadence?
baselinePerform server upgrade updates to ensure timely updates and patching.
baselineApply security patches and updates to all relevant hardware and software, ensuring completion in a timely manner following release (Patch Management).
baselineAnalyze current vulnerabilities using scan results, prior audits/test findings, and relevant threat intelligence (Vulnerability Review).
baselineProvide fix validation support and a retest option for high/critical findings (Remediation Guidance & Retest, optional/scoped).
baselineProvide hands-on remediation support to identify, prioritize, and remediate all cybersecurity vulnerabilities discovered during testing, including clear guidance, recommended fixes, and collaborative resolution efforts with internal teams.
baselinePropose an approach for testing mission systems and applications in pre-production/production-like test environments for vulnerabilities, design anti-patterns, resistance to DoS/DDoS, and common coding and configuration errors, with options for tailoring scope, retesting remediated findings, and focused ad hoc tests.
baselineSupport annual FISMA compliance assessments, including third-party assessments for ATO, continuous monitoring, and security penetration testing to identify vulnerabilities, and document/track findings via a Plan of Action and Milestones (POA&M).
baselineProvide a monthly vulnerability report and risk mitigation plan; report Critical/High vulnerabilities to the organization's CIO/CISO and remediate as soon as possible with a POA&M.
baselineProvide weekly vulnerability scanning and reporting.
baselineDescribe your vulnerability scanning and reporting process including tools utilized.
baseline(Optional) Provide mitigation recommendations for in-scope infrastructure based on vulnerability reports shared by the financial institution, and correlate vulnerability information with the threat management system to get a 360-degree view of assets in scope.
baselineContractor shall support management, tracking, analysis, and reporting of Plans of Action and Milestones (POA&Ms), risk acceptances, and related remediation activities, including status reporting on open, overdue, closed, and risk-accepted items, and identify trends/recurring issues.
baselineContractor shall provide vulnerability management support as a sustained enterprise function, including tracking, analysis, reporting, remediation coordination and trend analysis across systems, applications, devices, and other in-scope assets, and assist stakeholders in evaluating remediation actions, timelines, and residual risk.
baselineContractor shall develop and maintain a Plans of Action and Milestones (POA&M) Management Program Plan and Procedure, manage POA&M creation from findings arising from A&A assessments, audits, incidents, and penetration test findings, and use the organization-designated software (currently JIRA) for tracking all POA&Ms.
baselineContractor shall provide bi-weekly trending and metrics reports on POA&Ms including POA&M trending graphs by severity/system/BPO, delayed POA&Ms, open POA&Ms, closed POA&Ms, and risk-accepted POA&Ms.
baselineContractor shall develop and maintain a Vulnerability Management Program Plan and Procedure covering patch remediation timelines, remediation verification before weakness closure, and manage/coordinate tracking and closure of system vulnerabilities (including code-based vulnerabilities); currently the organization uses Tenable as its vulnerability scanning tool, and Contractor is expected to provide a recommendation for the best tool to track vulnerabilities.
baselineContractor shall perform analysis on weekly security scans to facilitate discussions with system teams and ISSOs, and provide weekly/bi-weekly trending and metrics reports on vulnerabilities including trending graphs, age tracking, and severity tracking overall and by system.
baselineContractor shall provide support for Cyber Hygiene by developing and executing procedures for capturing and tracking through to remediation all vulnerabilities reported by federal sources (e.g. DHS Binding Operational Directive 22-01), generating specific reports at least bi-weekly.
baselineSolution will be productionised only after closure of all security findings by the financial institution's Information Security Department; if vulnerabilities remain unresolved beyond 30 days, the financial institution reserves the right to cancel the purchase order and require reimbursement of payments made for licenses/installation.
baselineWhat combination of Pen testing, scanning, and vulnerability assessment tools will be used for this project? Identify possible impact of Pen testing on the organization's system Infrastructure.
baselineConduct external and internal vulnerability testing and threat assessment.
baselineHow often do you scan for vulnerabilities on your network? How often do you scan for vulnerabilities within your web applications?
baselineVendor will, at its expense, perform scans for unauthorized applications, services, code and system vulnerabilities on the networks/systems used to perform services, prior to the Agreement and at least annually thereafter and whenever a change is made that may impact confidentiality/integrity/availability, providing reports within five business days of generation or receipt.
baselineVendor will carry out updates and patch management for all systems and devices in a timely manner, applying security patches within five (5) business days or less based on reported criticality, using an auditable process reviewable by the University.
baselineVendor is responsible for continuous vulnerability management of hardware and software for Cloud Software, including scanning and issue remediation, and is responsible for all disruptions and damage caused to University Data while hosted in Cloud Software.
baselineDoes the vendor conduct any recurring vulnerability or penetration testing?
baselineVendor shall conduct vulnerability assessments against all Vendor internet-facing information systems on a regular basis, and shall perform penetration tests on all Vendor web applications and services used to provide services to the agency, in accordance with standard methodologies, no less often than annually.
baselineFor applicable CVEs, DHS CISA emergency directives, or product vendor 'Patch Now' recommendations, Vendor shall provide a statement of resolution or an executable mitigation plan within thirty (30) calendar days of the CVE or CISA release.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat asset and scan coverage does the platform provide out of the box — network/infrastructure, web application, cloud (CSPM-adjacent), container images, and code/SCA — and which require separate agents or licenses?Answer key — what a strong answer shows
Strong answers give a coverage matrix and are upfront about which surfaces require an additional agent, connector, or SKU rather than implying one license covers everything.
RFPDescribe the prioritization methodology beyond raw CVSS (exploit-in-the-wild data, asset criticality/business context, exposure/reachability analysis) and quantify the reduction in 'must-fix' volume versus CVSS-only triage with a customer reference.Answer key — what a strong answer shows
Look for a concrete reduction figure (e.g., 'X% fewer critical tickets') backed by a named customer, and a methodology that goes beyond relabeling CVSS scores.
RFIHow frequently are external attack-surface and internal scans performed by default, and is continuous/agent-based scanning available versus periodic scheduled scans only?Answer key — what a strong answer shows
Continuous or agent-based scanning materially reduces exposure windows compared to weekly/monthly scheduled scans; the answer should state the default, not just the maximum available.
RFIWhat remediation workflow integration exists (ticketing auto-creation, SLA tracking by severity, verification re-scan on fix), and can remediation be automated (e.g., patch orchestration), or is it detection-only?Answer key — what a strong answer shows
Strong answers describe closed-loop remediation (auto-verification the fix worked), not just detection plus a manual ticket handoff.
RFPDetail how the platform handles vulnerability data for cloud-native and ephemeral assets (containers, serverless, autoscaling groups) where traditional agent-based scanning is impractical.Answer key — what a strong answer shows
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Look for image/registry scanning and IaC-time or runtime detection suited to ephemeral infrastructure, not just an agent that assumes long-lived hosts.
RFIWhat is the false-positive rate for the default scan configuration, and what mechanism exists for analysts to permanently suppress a confirmed false positive without it reappearing on the next scan?Answer key — what a strong answer shows
A vendor unable to state even an approximate false-positive rate likely hasn't measured it; suppression should persist across scans, not require re-triage every cycle.
RFPExplain risk-based reporting for executives/board — can risk be expressed in business terms (e.g., financial exposure, industry benchmarking) rather than raw vulnerability counts, and is this a built-in report or custom BI work?Answer key — what a strong answer shows
A native executive report is stronger than requiring the customer to build their own BI dashboard on top of raw exported data.
RFIHow does the product handle zero-day and newly disclosed CVEs before an authenticated scan can confirm exposure — is there an interim exposure estimate based on asset inventory/version data already collected?Answer key — what a strong answer shows
Look for an interim, inventory-based exposure estimate delivered within hours of disclosure, rather than waiting for the next full scan cycle to say anything.
RFIHow is authenticated/credentialed scanning handled — does the platform integrate with an existing credential vault (CyberArk, HashiCorp Vault) for scan credentials, or does it require storing credentials directly within the platform, and what is the security model for that storage?Answer key — what a strong answer shows
Vault integration is materially safer than platform-stored credentials; if credentials must be stored directly, ask specifically how they're encrypted and who can access them.
RFPDescribe safety mechanisms for scanning OT/ICS or other fragile legacy environments — is there a passive/non-intrusive scanning mode, and can the vendor cite a real incident where active scanning caused a production outage and what changed afterward?Answer key — what a strong answer shows
Look for an explicit passive-scanning capability for fragile environments and an honest answer about past incidents — a vendor claiming zero incidents ever across a large customer base should be scrutinized.
RFIIs the platform a PCI-approved Scanning Vendor (ASV) for external quarterly compliance scans, and does it generate audit-ready compliance reports for PCI DSS, HIPAA, or other frameworks directly, or does that require manual report assembly?Answer key — what a strong answer shows
ASV certification and native compliance-report generation are concrete, verifiable claims — ask for the ASV certificate number rather than accepting an unqualified 'yes.'
RFPExplain how findings incorporate EPSS (Exploit Prediction Scoring System) alongside or instead of raw CVSS, and provide a concrete example of how EPSS changed a real prioritization decision for a customer.Answer key — what a strong answer shows
A vendor actively using EPSS (a probabilistic, frequently-updated exploitation-likelihood score) shows more current prioritization thinking than one relying solely on static CVSS severity.
RFIWhat is the pricing model — per asset, per IP, per scan, or a flat enterprise tier — and how does cost change when the customer's asset count grows significantly (e.g., cloud auto-scaling doubles the environment) mid-contract?Answer key — what a strong answer shows
Look for a clear, predictable per-asset cost structure; a vendor whose pricing breaks down or requires renegotiation when asset counts fluctuate (common with cloud/ephemeral infrastructure) creates budget risk.
RFIWhat is the measured performance impact of an active scan on production systems (network bandwidth, target-host CPU/latency), and can scan intensity/throttling be configured per asset criticality?Answer key — what a strong answer shows
Strong answers give real measured impact figures and configurable throttling; a vendor unable to quantify scan impact likely hasn't tested against sensitive production workloads.
RFPDetail non-CVE software inventory and end-of-life tracking — does the platform flag unsupported/EOL software versions even when no active CVE exists yet, and how comprehensive is the installed-software catalog versus just known-vulnerable packages?Answer key — what a strong answer shows
EOL/unsupported-software tracking independent of active CVEs is a meaningfully broader risk view than pure vulnerability-only scanning.
RFIHow does the platform handle vulnerability data for third-party/vendor-supplied software where the customer has no source-code visibility (SCA-adjacent but for compiled/commercial software), and how is that reconciled with the vendor's own patch release cadence?Answer key — what a strong answer shows
Look for a real mechanism tracking commercial software patch releases against the customer's deployed versions, not just open-source SCA coverage.
RFPPerform server upgrade updates to ensure timely updates and patching.
RFPApply security patches and updates to all relevant hardware and software, ensuring completion in a timely manner following release (Patch Management).
RFPAnalyze current vulnerabilities using scan results, prior audits/test findings, and relevant threat intelligence (Vulnerability Review).
RFPProvide fix validation support and a retest option for high/critical findings (Remediation Guidance & Retest, optional/scoped).
RFPProvide hands-on remediation support to identify, prioritize, and remediate all cybersecurity vulnerabilities discovered during testing, including clear guidance, recommended fixes, and collaborative resolution efforts with internal teams.
RFPPropose an approach for testing mission systems and applications in pre-production/production-like test environments for vulnerabilities, design anti-patterns, resistance to DoS/DDoS, and common coding and configuration errors, with options for tailoring scope, retesting remediated findings, and focused ad hoc tests.
RFPSupport annual FISMA compliance assessments, including third-party assessments for ATO, continuous monitoring, and security penetration testing to identify vulnerabilities, and document/track findings via a Plan of Action and Milestones (POA&M).
RFPProvide a monthly vulnerability report and risk mitigation plan; report Critical/High vulnerabilities to the organization's CIO/CISO and remediate as soon as possible with a POA&M.
RFPProvide weekly vulnerability scanning and reporting.
RFPDescribe your vulnerability scanning and reporting process including tools utilized.
RFP(Optional) Provide mitigation recommendations for in-scope infrastructure based on vulnerability reports shared by the financial institution, and correlate vulnerability information with the threat management system to get a 360-degree view of assets in scope.
RFPContractor shall support management, tracking, analysis, and reporting of Plans of Action and Milestones (POA&Ms), risk acceptances, and related remediation activities, including status reporting on open, overdue, closed, and risk-accepted items, and identify trends/recurring issues.
RFPContractor shall provide vulnerability management support as a sustained enterprise function, including tracking, analysis, reporting, remediation coordination and trend analysis across systems, applications, devices, and other in-scope assets, and assist stakeholders in evaluating remediation actions, timelines, and residual risk.
RFPContractor shall develop and maintain a Plans of Action and Milestones (POA&M) Management Program Plan and Procedure, manage POA&M creation from findings arising from A&A assessments, audits, incidents, and penetration test findings, and use the organization-designated software (currently JIRA) for tracking all POA&Ms.
RFPContractor shall provide bi-weekly trending and metrics reports on POA&Ms including POA&M trending graphs by severity/system/BPO, delayed POA&Ms, open POA&Ms, closed POA&Ms, and risk-accepted POA&Ms.
RFPContractor shall develop and maintain a Vulnerability Management Program Plan and Procedure covering patch remediation timelines, remediation verification before weakness closure, and manage/coordinate tracking and closure of system vulnerabilities (including code-based vulnerabilities); currently the organization uses Tenable as its vulnerability scanning tool, and Contractor is expected to provide a recommendation for the best tool to track vulnerabilities.
RFPContractor shall perform analysis on weekly security scans to facilitate discussions with system teams and ISSOs, and provide weekly/bi-weekly trending and metrics reports on vulnerabilities including trending graphs, age tracking, and severity tracking overall and by system.
RFPContractor shall provide support for Cyber Hygiene by developing and executing procedures for capturing and tracking through to remediation all vulnerabilities reported by federal sources (e.g. DHS Binding Operational Directive 22-01), generating specific reports at least bi-weekly.
RFPSolution will be productionised only after closure of all security findings by the financial institution's Information Security Department; if vulnerabilities remain unresolved beyond 30 days, the financial institution reserves the right to cancel the purchase order and require reimbursement of payments made for licenses/installation.
RFPWhat combination of Pen testing, scanning, and vulnerability assessment tools will be used for this project? Identify possible impact of Pen testing on the organization's system Infrastructure.
RFPConduct external and internal vulnerability testing and threat assessment.
RFPHow often do you scan for vulnerabilities on your network? How often do you scan for vulnerabilities within your web applications?
RFPVendor will, at its expense, perform scans for unauthorized applications, services, code and system vulnerabilities on the networks/systems used to perform services, prior to the Agreement and at least annually thereafter and whenever a change is made that may impact confidentiality/integrity/availability, providing reports within five business days of generation or receipt.
RFPVendor will carry out updates and patch management for all systems and devices in a timely manner, applying security patches within five (5) business days or less based on reported criticality, using an auditable process reviewable by the University.
RFPVendor is responsible for continuous vulnerability management of hardware and software for Cloud Software, including scanning and issue remediation, and is responsible for all disruptions and damage caused to University Data while hosted in Cloud Software.
RFIDoes the vendor conduct any recurring vulnerability or penetration testing?
RFIVendor shall conduct vulnerability assessments against all Vendor internet-facing information systems on a regular basis, and shall perform penetration tests on all Vendor web applications and services used to provide services to the agency, in accordance with standard methodologies, no less often than annually.
RFIFor applicable CVEs, DHS CISA emergency directives, or product vendor 'Patch Now' recommendations, Vendor shall provide a statement of resolution or an executable mitigation plan within thirty (30) calendar days of the CVE or CISA release.