Technology Debt Report

Technology debt (also known as tech debt) refers to the accumulated risk and cost associated with outdated, unsupported, or end-of-life technologies in your IT environment. When hardware or software reaches its End-of-Life (EOL) or End-of-Support (EOS) date, the vendor no longer provides security patches, bug fixes, or technical support. This creates a growing security gap, as newly discovered vulnerabilities in these products will remain unpatched, leaving your organization exposed to potential exploits and compliance violations.

The Technology Debt Report in CSAM is an executive-ready PDF report that helps you identify outdated hardware and software across your asset inventory. It highlights End-of-Life (EOL) and End-of-Support (EOS) products, calculates risk scores based on their EOL/EOS status and historical vulnerabilities, and provides insights to help you prioritize remediation.

The report is available from a CSAM (Trial and Full) subscription and helps security teams and leadership understand the scope of outdated technologies, assess the associated risk posture, and make informed decisions about upgrade planning and resource allocation.

To create a Technology Debt Report, navigate to Reports > Create Report > Technology Debt Report.

Features and Benefits

The Technology Debt Report enables you to:

  • Communicate a transparent and actionable assessment of your enterprise's Tech Debt.
  • Highlight risks associated with End-of-Life (EoL) and End-of-Support (EoS) hardware and software with an executive-ready report.
  • Prioritize and proactively plan upgrades for highly vulnerable End-of-Support software that will not have security patches.
  • Foster a proactive risk management culture and informed decision-making to protect your assets and align your security efforts with your overarching business goals.

Who can generate this report?

CSAM users can generate and download the Tech Debt report, and VMDR customers with CSAM can also generate it.

Important to Know!

  • You need a super user role within your Qualys subscription with report generation access to generate the Tech Debt report. Contact your Technical Account Manager (TAM) or Qualys Support for assistance if you don't see the Generate option.
  • The automated 'Technology Debt Report' can be generated only once per user for your subscription. If multiple users on your subscription have access to report generation, each can generate this report once.

How is QDS for Tech Debt EOL/EOS Calculated

The QDS score is calculated every three months as a product moves closer to or further past its End-of-Life (EOL) or End-of-Support (EOS) date. Due to this changes are reflected every three months.

The overall score is calculated using the following formula:

Score = (0.6 x Aggregate QVS Score) + (0.4 x EOL/EOS Timeframe Score)

This means that 40% of the overall score is driven by the product's proximity to or age beyond its EOL/EOS date.

EOL/EOS Timeframe Score

The timeframe score changes every three months based on the product's EOL/EOS status.

EOL/EOS Timeframe Timeframe Score
More than 12 months in the future 0
12 months in the future 10
9 months in the future 20
6 months in the future 30
3 months in the future 40
Within the current month 50
3 months past EOL/EOS 60
6 months past EOL/EOS 70
9 months past EOL/EOS 80
12 months past EOL/EOS 90
More than 12 months past EOL/EOS 100

Example:

If a product reached EOL last week, its Timeframe Score is 50 because it is within the first 3-month EOL/EOS period. The score stays at 50 until the product reaches the next 3-month threshold. At that point, the Timeframe Score increases to 60, which also increases the overall Technology Debt Score.

In other words, you should not expect the score to change every month. It changes only when the product enters the next 3-month EOL/EOS timeframe (assuming the Aggregate QVS Score remains the same).

Qualys Vulnerability Score (QVS)

The Qualys Vulnerability Score (QVS) reflects a product's historical vulnerability profile to help assess its EOL/EOS risk. It does not evaluate vulnerabilities in the same way as TruRisk.

Products that are no longer supported do not all carry the same level of risk. Some have a limited history of vulnerabilities, while others have a long history of severe vulnerabilities that will no longer receive vendor security updates. QVS uses this historical context to better estimate the security risk of unsupported products.

How QVS Differs from TruRisk

Although both QVS and TruRisk use vulnerability information, they serve different purposes.

QVS measures the historical security exposure of a product to help assess the risk associated with EOL/EOS products.
TruRisk evaluates the vulnerabilities currently present in your environment, considering factors such as vulnerability severity, exploitability, and the affected assets.

As a result, QVS and TruRisk complement each other rather than duplicate the same information. QVS provides historical product risk, while TruRisk measures your organization's current exposure.

Generate Tech Debt Report from the Dashboard

You can generate the automated Tech Debt report directly from the Dashboard.

Complete the following steps:

  1. Go to the Dashboard tab and click Generate to generate the Tech Debt Report.

    • After you click Generate to initiate the 'Technology Debt' report request from the Dashboard tab once, the Generate option is no longer available for the 'Technology Debt' report.
    • You can close the banner if you do not want to generate the report immediately. After you close it, the banner is displayed again after 30 days. However, it is displayed again if Qualys introduces a new report within 30 days. If you select the Don't show again checkbox, the banner is displayed only when a new report is introduced.
    • If you close the banner, you can still generate the report from the Notifications menu.
  2. Provide the following details on the Technology Debt Report page:

    Field

    Description

    Assets Last Discovered In

    Select the required time duration, such as Today, Last 24 Hours, and Last 7 days. You can also provide a specific time range.

    It enables you to customize your Technology Debt report according to the time filter you provide.

    Note: These selections are made as per the UTC time zone, and the time zone can't be changed.

    Add recipients to email PDF reports

    After the Tech Debt report is ready, by default, the notification is sent to the requester's email ID and the registered email ID for the subscription.

    However, if you also want the email notification to be sent to other recipients, enter a comma-separated list of the intended recipients' email IDs to whom you want the email notification to be sent.

Create a Technology Debt Report

You can create a Technology Debt Report from the Reports tab.

Navigate to Reports > Create Report > Technology Debt Report. Complete each step and click Next to proceed.

Step 1: Basic Details

Provide a report title and description for the report.

Field

Description

Report Title

Enter a title for the report.

Report Description

Enter a description for the report.

Click Next.

Step 2: Report Source

Specify the assets or asset tags to include in your report.

Field

Description

Include hosts for the tags

Select the tag matching criteria from the dropdown:

  • Any: Any host that has even one of the selected tags associated with it will be included in the report.
  • All: Only hosts that have all of the selected tags associated with them will be included in the report.

Click Create Tag to add tags for filtering the assets to include in the report.

Exclude tags

(Optional) Select this checkbox to exclude specific tags from the report. When enabled, you can select tags whose associated assets are excluded from the report.

Assets Last Discovered In

Select the required time duration to filter assets based on their last discovery time. For example, Last 30 Days.

It enables you to customize your report to include only assets discovered within the specified time range.

Click Next.

Step 3: Report Display

Configure notification settings for the report. Set up notifications to be triggered on execution of this report.

Field

Description

Actions

Select Send Email (Via Qualys) from the Actions dropdown to configure email notifications. When selected, complete the following:

  1. Enter the email addresses in the Recipients field. You can enter multiple email addresses separated by a comma.
  2. Enter the email subject line in the Subject Line field.
  3. Enter the message text in the Message field.
  4. Select the Restrict downloads checkbox and enter a number in the Enter Limit field to limit the number of times the report can be downloaded from the report link sent through the email notification.

The email notification is sent after the report is generated for reports with Completed, Failed, or Incomplete statuses.

Click Next.

Step 4: Report Schedule

Configure the scheduling for your report. You can choose one of the following options:

  • On Demand: The report runs once it is created.
  • Schedule: Schedule the report to run at a specified time. When you select Schedule, provide the following details:

Field

Description

Start Date

Select the date on which the report generation should start.

Start Time

Select the time at which the report generation should start.

Recurring

(Optional) Select this checkbox to create a recurring schedule. When enabled, configure the following:

  • Repeats: Select the frequency: Daily, Weekly, or Monthly.
  • End Date: Select the date on which the recurring schedule should end.
  • End Time: Select the time at which the recurring schedule should end.

You can manage schedules (view info, delete, and pause/resume schedule) from the Reports > Schedules tab.

Click Next.

Step 5: Review and Confirm

Review your selections across all steps. The summary displays the following sections:

  • Basic Details: Shows the report name and description.
  • Report Source: Shows the selected asset tags and time filter.
  • Report Display: Shows the notification settings.
  • Report Schedule: Shows the schedule type (On Demand or Scheduled).

You can edit any section by clicking the edit icon next to the section heading. This takes you back to the respective step to make changes.

Click Finish to create the report.

Download the Technology Debt Report

Users who generate a report can download it multiple times. When the report is ready, you receive an email notification.

You can download the report in the following methods:

  • Clicking the download link in the email.
  • Clicking Download Report from the Notifications menu in the CSAM UI.
  • From the Reports tab.

The Download Report notification is displayed under the Notification menu only for the next 15 days from the day the report generation request is initiated. After that, you can download the report from the Reports tab.

Trending Widget

The Technology Debt report PDF includes a trending widget for assets discovered in the last 30 days. It shows precalculated data for the last 90 days trend for assets discovered over the last 30 days and associated with the selected asset tags.

Important: You cannot see the trending widget on the report immediately after you generate it, as the trending counts are collected according to the weekly pre-set schedule, and the weekly scheduled job might not have been triggered for execution. Also, fewer points between 1 and 13 can be seen on the trending widget.