Back to 360 Playbooks
Security Ratingsbeginner

Ratings Are Not Certifications

What security ratings can and cannot tell you — and when to escalate beyond the score.

SecurityAudit360 Team
6/25/2026
4 min read
ratingscompliancedue-diligence

Ratings Are Not Certifications

Who this is for: Decision-makers using ratings in contracts, board decks, or vendor committees.

What you'll learn:

  • What ratings represent (and do not)
  • Common misinterpretations
  • When to go deeper than the grade

What a rating is

A point-in-time signal from observable data in our index — attack surface, domain health, weighted findings, and reputation where available.

What a rating is not

  • Not an on-site audit or SOC 2 certification
  • Not a guarantee of future breach or safety
  • Not a substitute for your risk policy, questionnaires, or legal review
  • Not complete if the company was recently indexed or coverage is sparse

Good uses

  • Triage vendors before deeper review
  • Compare peers in the same industry (Competitor Analysis)
  • Track change over time with alerts and re-scans
  • Support conversations with exported evidence (PDF export)

When to escalate

Signal Suggested action
Grade D/F + critical data access Committee review; compensating controls
Score dropped sharply Re-scan; vendor security contact
Strong grade + bad reputation news Reputation analysis
Missing or wrong company data Request correction

Related articles

Still stuck? Contact support

Last updated: 6/25/2026