TruRisk™ Scoring: Consolidated Formula Reference

This page is a side-by-side reference for the TruRisk™ formulas. It sets the two asset-level TruRisk™ formulas side by side, and carries the score and severity reference tables that span every level.

Which TruRisk™ Model Applies to You

The model that calculates your TruRisk™ scores depends on your subscription.

Your subscription Asset score Tag and Business Entity score
VMDR only (also CSAM) TruRisk™ 1.0 Platform v1
ETM enabled TruRisk™ 2.0 (turns on automatically, in all Qualys applications) Platform v1

Enabling ETM changes how asset scores are calculated. It does not change how tag and Business Entity scores are calculated.

Comparing the two platform-level formulas instead? That comparison lives with the topic it belongs to: see TruRisk™ Score for Assets

.htm">TruRisk™ Score for Tags and Business Entities.

New to TruRisk™ scoring? Read these in order instead:

  1. Finding-Level Scores: QVS, QDS, and QVSS — how a single finding is scored.
  2. TruRisk™ Score for Assets — how the findings on one asset become an asset score, and what changed between TruRisk™ 1.0 and 2.0.
  3. TruRisk™ Score for Tags and Business Entities — how asset scores roll up, and what changed between Platform v1 and v2.

The Two Asset Formulas at a Glance

Aspect TruRisk™ 1.0
Asset level
TruRisk™ 2.0
Asset level

Scored object

An asset

An asset

Used by

VMDR-only subscriptions; also applies to CSAM

ETM subscriptions (in all Qualys applications, including VMDR, once ETM is enabled)

Unit of risk

QID — one detection may carry several CVEs

QID. ETM shows findings by CVE, but QDS is still assigned per QID.

Aggregation method

Average of scores per severity bin, damped by count

Maximum score, plus weighted counts per severity bin

Input score

QDS per QID (managed assets); QVS per CVE (externally exposed unmanaged assets)

QDS (MaxDetectionScore, range 1–100)

Business context

ACS multiplier, External × 1.2

ACS multiplier, External × 1.2

g value

Not used

g(MaxDetectionScore) — amplifies: 1.3 / 1.2 / 1.0

Volume caps

None; count damped by a power function instead

Medium and Low counts capped at 2000

How to enable

Default for VMDR

Automatic on ETM enablement; no action needed

Customizable

An alternative max-based variant exists on request

Using Risk and Compensatory Factors

Full explanation

TruRisk™ Score for Assets

TruRisk™ Score for Assets

Score Availability by Application

Score

Scale

Granularity

Where it is used

QVS
Qualys Vulnerability Score

1–100

Per CVE

Underlying score across VMDR and ETM; the direct input to the TruRisk™ 1.0 unmanaged-asset formula; queryable through a dedicated API endpoint

QDS
Qualys Detection Score

1–100

Per QID

VMDR prioritization; the score driving both asset formulas; retained in ETM for APIs and existing automation; still the displayed score on the ETM Misconfiguration Details page

QVSS
Qualys Vulnerability Scoring System

0.0–10.0

Per finding

ETM only: Findings listing and details; Home page top contributors; TruLens exposure tables, Business Entity views and Risk Workbench, dashboards, widgets and reports

ACS
Asset Criticality Score

1–5, default 2

Per asset, via tags

Multiplier in both asset formulas; set through static or dynamic tags, asset groups, or CMDB import

TruRisk™ Score / ARS

0–1000

Per asset

VMDR, CSAM, and ETM; the input to both platform-level formulas

Platform TruRisk™ Score

0–1000

Per tag or Business Entity

Business entity views, home page entity widget, executive reporting

Severity Bands

Band

QDS
(1–100)

QVSS
(0.0–10.0)

TruRisk™
(0–1000)

Critical

90–100

9.0–10.0

850-1000

High

70–89

7.0–8.9

700-849

Medium

40–69

4.0–6.9

500-699

Low

1–39

0.0–3.9

0-499

Related Topics

TruRisk™ Scoring

Finding-Level Scores: QVS, QDS, and QVSS

TruRisk™ Score for Assets

TruRisk™ Score for Tags and Business Entities