What a Bitsight score means, and what most of the web gets wrong
Read any Bitsight rating against the published scale — the band, how the rated inventory is distributed, what the letter grades underneath mean, and which risk categories actually move the number.
Read a rating
Enter any figure. The reader snaps it to the scale Bitsight actually publishes on, names the band, and says how much of the rated inventory sits above it. It opens on 720, the published average.
720 is Intermediate, and exactly the published average of 720. Roughly 60% of rated entities sit in a stronger band.
A published rating is the floor of a ten-point interval, not a point. A rating shown as 720 means the true rating is somewhere between 720 and 729.
| Category | Range | Share of entities | Relative breach likelihood |
|---|---|---|---|
| Advanced | 740 – 900 | 60% | The lowest breach likelihood of the three bands. |
| IntermediateYour band | 640 – 730 | 35% | Intermediate entities are, on average, 1.5–2× more likely to be breached than Advanced entities. |
| Basic | 250 – 630 | 5% | Basic entities are, on average, 2–3× more likely to suffer a publicly disclosed breach than Intermediate entities. |
Entities rated 400 or below are 5× more likely to suffer a publicly disclosed breach than entities rated 700 or above.
20 points to Advanced. That is 2 rating steps, and every step has to be traceable to a risk vector — the rounding is set so it cannot come from aggregate drift.
What actually moves it
| Risk category | Weight | What sits in it |
|---|---|---|
| Diligence | 71.5% | Externally observable configuration — TLS and certificates, email authentication, open ports, software currency, vulnerability remediation practice. |
| Compromised Systems | 26% | Evidence of machines on your network behaving as though under external control — command-and-control traffic, malware distribution, participation in DDoS, spam. |
| User Behavior | 2.5% | File sharing and exposed credentials attributable to people on your network. |
| Public Disclosures | Conditional | Disclosed breaches. Weighted only if they occur, so it carries no standing share. |
Nearly three-quarters of the rating is Diligence — configuration anyone outside can observe. That is the part you can move without touching your internal estate, and it is why most of a first remediation pass is certificates, TLS and email authentication rather than anything architectural.
Reading the vector grades underneath
| Grade | What it means |
|---|---|
| A | In the top 10% of companies. |
| B | In the top 30% of companies. |
| C | In the top 60% of companies. |
| D | In the bottom 40% of companies. |
| F | In the bottom 20% of companies. |
| N/A | No correlation with performance — an informational vector, a vector with no findings, or one still inside its evaluation period. |
A C is the middle of the field, not seventy per cent right, and a D is the bottom four-tenths. Individual findings underneath a vector carry a separate GOOD / FAIR / WARN / BAD scale — the two vocabularies do not map onto each other.
Indicative. This reads the published scale; it does not look up any organisation’s rating. Figures verified against Bitsight’s own knowledge base.
Take this away as a rating brief
Everything above is yours already. This is the version you can put in front of your team — the same result with your details on it, the owner columns your incident file needs, and the checklist attached. It opens here and lands in your inbox, so it is to hand when you actually need it rather than in a tab you closed.
Why no rating ends in 1 to 9
Bitsight ratings are rounded down in ten-point increments. Every published rating is therefore a multiple of ten, and a true rating of 735 is published as 730. The rounding is set that way deliberately: it means any movement in a rating can be traced back to at least one risk vector, where a finer scale would drift on aggregate noise that no vector could explain.
Two things follow, and both are routinely got wrong. The first is that a published rating is a floor, not a point — a rating shown as 740 means the true figure is somewhere between 740 and 749, so a genuine improvement of a few points may not surface at all. The second is that any source quoting a band as “640 to 739” is describing numbers that cannot occur. The bands are contiguous on a ten-point lattice; they only look as though they have gaps when they are written out as though the scale were continuous.
What each band is actually worth
The nominal scale runs from 250 to 900, but the edges are reserved and unoccupied. Ratings observed in practice fall between 300 and 820, and the average is 720 — which is Intermediate, not Advanced.
| Category | Range | Share of entities | Relative breach likelihood |
|---|---|---|---|
| Advanced | 740 – 900 | 60% | The lowest breach likelihood of the three bands. |
| Intermediate | 640 – 730 | 35% | Intermediate entities are, on average, 1.5–2× more likely to be breached than Advanced entities. |
| Basic | 250 – 630 | 5% | Basic entities are, on average, 2–3× more likely to suffer a publicly disclosed breach than Intermediate entities. |
The distribution is the part worth sitting with. Advanced is not the front of the field; it is 60% of it. A vendor questionnaire that asks for 740 is asking you to be ordinary, and a supplier who clears it has told you they are not in the bottom four-tenths. Entities rated 400 or below are 5× more likely to suffer a publicly disclosed breach than entities rated 700 or above.
A majority of the scale is reserved for the weaker half of the inventory, which is deliberate — there are more ways to be Basic than to be Advanced, and the spacing reflects that rather than any intent to flatter the top.
What moves the number
The rating aggregates risk-vector letter grades across four risk categories, weighted very unevenly. Most published remediation advice does not reflect how uneven.
| Risk category | Weight | What sits in it |
|---|---|---|
| Diligence | 71.5% | Externally observable configuration — TLS and certificates, email authentication, open ports, software currency, vulnerability remediation practice. |
| Compromised Systems | 26% | Evidence of machines on your network behaving as though under external control — command-and-control traffic, malware distribution, participation in DDoS, spam. |
| User Behavior | 2.5% | File sharing and exposed credentials attributable to people on your network. |
| Public Disclosures | Conditional | Disclosed breaches. Weighted only if they occur, so it carries no standing share. |
Diligence is 71.5% of it, and Diligence is made almost entirely of things anyone outside the organisation can observe and you can fix without touching the internal estate — certificates, TLS configuration, email authentication, software currency. That is why a first remediation pass is usually configuration work. You can see two slices of it directly: the SSL estate check reads the certificates across your subdomains, and the email spoofing check reads SPF, DKIM and DMARC.
Underneath the categories, each risk vector carries a letter grade. These are percentile ranks against every rated company, not marks out of a hundred, which is the single most common misreading.
| Grade | What it means |
|---|---|
| A | In the top 10% of companies. |
| B | In the top 30% of companies. |
| C | In the top 60% of companies. |
| D | In the bottom 40% of companies. |
| F | In the bottom 20% of companies. |
| N/A | No correlation with performance — an informational vector, a vector with no findings, or one still inside its evaluation period. |
A C is the middle of the field, not seventy per cent right. Individual findings underneath a vector are graded GOOD, FAIR, WARN or BAD — a separate vocabulary that does not map onto the letters.
What the number cannot tell you
- Whether it is even your estate. A rating is computed against an attributed set of assets. If a subsidiary is missing or someone else’s asset is mapped to you, the rating describes the wrong company and no remediation will move it. Attribution is the first thing to check, not the last.
- What happened today. Ratings are recalculated daily but against a rolling year of evidence, so a finding resolved this morning does not leave the window this morning.
- Anything about internal controls. Everything observed is externally visible. Segmentation, privileged access, backup integrity and recovery testing are invisible to it, which is exactly why a rating complements a questionnaire rather than replacing one.
- Your standing in your own sector. The distribution above is the whole inventory. Sector cohorts sit differently, and a rating that is unremarkable across all industries can be poor among Indian banks.
For the judgement question rather than the lookup — what counts as a good Bitsight score — and for the remediation sequence, see how to improve your Bitsight rating.
This tool reads the published rating scale. It does not look up any organisation’s rating, and nothing entered here leaves your browser. Every figure was read from Bitsight’s own knowledge base rather than from secondary reporting, which is where the incorrect band ranges in circulation come from. Every instrument cited here was verified against the issuing regulator's own notification on .
Worked examples
The same calculator, run for a specific entity — with the thresholds and clocks that apply to it, and the instrument each one comes from.
Questions this page answers
- What does a Bitsight score of 600 mean?
- It is a Basic rating — the lowest of the three categories, covering ratings of 630 and below and around 5% of the rated inventory. Bitsight characterises the band as poor security performance and higher risk, and puts Basic entities on average 2 to 3 times more likely to suffer a publicly disclosed breach than Intermediate ones. It sits 120 points below the published average of 720, and 40 points below the bottom of the Intermediate band.
- Why is there no Bitsight rating of 635?
- Because ratings are rounded down in ten-point increments, so every published rating is a multiple of ten. A true rating of 635 is published as 630. Bitsight sets the rounding this way so that any movement in a rating can be traced back to at least one risk vector rather than to aggregate noise. The practical consequence is that a published rating is the floor of a ten-point interval: a rating shown as 740 means the true figure is somewhere between 740 and 749. Any source quoting a band as “640 to 739” is describing numbers that cannot occur.
- What is the range of Bitsight security ratings?
- The nominal scale runs from 250 to 900, but the upper and lower edges are reserved for future use and are unoccupied. The effective range — where ratings actually fall — is 300 to 820. Quoting 250 to 900 as the working scale overstates the spread at both ends, which matters when a rating is being read as a percentage of some maximum. It is not a percentage of anything.
- What is the average Bitsight score?
- 720, which sits in the Intermediate band. This is worth holding alongside the distribution: 60% of rated entities are Advanced at 740 or above, 35% are Intermediate, and 5% are Basic. Advanced is therefore the majority of the inventory rather than the front of it, and clearing 740 says less about relative standing than the label suggests.
- What do the Bitsight letter grades mean?
- They are percentile ranks against every rated company, not marks out of a hundred. A is the top 10%, B the top 30%, C the top 60%, D the bottom 40% and F the bottom 20%. N/A carries no performance signal at all — it appears on informational vectors, on vectors with no findings, and on vectors still inside an evaluation period. Individual findings underneath a vector are graded on a separate GOOD, FAIR, WARN, BAD scale, and the two vocabularies do not map onto each other.
- What has the biggest effect on a Bitsight rating?
- Diligence, which carries 71.5% of the weight — externally observable configuration such as TLS and certificates, email authentication, open ports, software currency and vulnerability remediation practice. Compromised Systems carries 26%, User Behavior 2.5%, and Public Disclosures is weighted only if a breach occurs, so it has no standing share. Because Diligence dominates and is made of things anyone outside can observe, most of a first remediation pass is configuration work rather than anything architectural.