TruRisk™ Scoring: Consolidated Formula Reference
This page is a side-by-side reference for the TruRisk™ formulas. It sets the two asset-level TruRisk™ formulas side by side, and carries the score and severity reference tables that span every level.
Which TruRisk™ Model Applies to You
The model that calculates your TruRisk™ scores depends on your subscription.
| Your subscription | Asset score | Tag and Business Entity score |
|---|---|---|
| VMDR only (also CSAM) | TruRisk™ 1.0 | Platform v1 |
| ETM enabled | TruRisk™ 2.0 (turns on automatically, in all Qualys applications) | Platform v1 |
Enabling ETM changes how asset scores are calculated. It does not change how tag and Business Entity scores are calculated.
Comparing the two platform-level formulas instead? That comparison lives with the topic it belongs to: see TruRisk™ Score for Assets
.htm">TruRisk™ Score for Tags and Business Entities.New to TruRisk™ scoring? Read these in order instead:
- Finding-Level Scores: QVS, QDS, and QVSS — how a single finding is scored.
- TruRisk™ Score for Assets — how the findings on one asset become an asset score, and what changed between TruRisk™ 1.0 and 2.0.
- TruRisk™ Score for Tags and Business Entities — how asset scores roll up, and what changed between Platform v1 and v2.
The Two Asset Formulas at a Glance
| Aspect | TruRisk™ 1.0 Asset level |
TruRisk™ 2.0 Asset level |
|---|---|---|
|
Scored object |
An asset |
An asset |
|
Used by |
VMDR-only subscriptions; also applies to CSAM |
ETM subscriptions (in all Qualys applications, including VMDR, once ETM is enabled) |
|
Unit of risk |
QID — one detection may carry several CVEs |
QID. ETM shows findings by CVE, but QDS is still assigned per QID. |
|
Aggregation method |
Average of scores per severity bin, damped by count |
Maximum score, plus weighted counts per severity bin |
|
Input score |
QDS per QID (managed assets); QVS per CVE (externally exposed unmanaged assets) |
QDS ( |
|
Business context |
ACS multiplier, External × 1.2 |
ACS multiplier, External × 1.2 |
|
g value |
Not used |
g(MaxDetectionScore) — amplifies: 1.3 / 1.2 / 1.0 |
|
Volume caps |
None; count damped by a power function instead |
Medium and Low counts capped at 2000 |
|
How to enable |
Default for VMDR |
Automatic on ETM enablement; no action needed |
|
Customizable |
An alternative max-based variant exists on request |
Using Risk and Compensatory Factors |
|
Full explanation |
Score Availability by Application
|
Score |
Scale |
Granularity |
Where it is used |
|---|---|---|---|
|
QVS |
1–100 |
Per CVE |
Underlying score across VMDR and ETM; the direct input to the TruRisk™ 1.0 unmanaged-asset formula; queryable through a dedicated API endpoint |
|
QDS |
1–100 |
Per QID |
VMDR prioritization; the score driving both asset formulas; retained in ETM for APIs and existing automation; still the displayed score on the ETM Misconfiguration Details page |
|
QVSS |
0.0–10.0 |
Per finding |
ETM only: Findings listing and details; Home page top contributors; TruLens exposure tables, Business Entity views and Risk Workbench, dashboards, widgets and reports |
|
ACS |
1–5, default 2 |
Per asset, via tags |
Multiplier in both asset formulas; set through static or dynamic tags, asset groups, or CMDB import |
|
TruRisk™ Score / ARS |
0–1000 |
Per asset |
VMDR, CSAM, and ETM; the input to both platform-level formulas |
|
Platform TruRisk™ Score |
0–1000 |
Per tag or Business Entity |
Business entity views, home page entity widget, executive reporting |
Severity Bands
|
Band |
QDS |
QVSS |
TruRisk™ |
|---|---|---|---|
|
Critical |
90–100 |
9.0–10.0 |
850-1000 |
|
High |
70–89 |
7.0–8.9 |
700-849 |
|
Medium |
40–69 |
4.0–6.9 |
500-699 |
|
Low |
1–39 |
0.0–3.9 |
0-499 |