Overview

Product video
The SecurityScorecard platform uses non-intrusive and proprietary data collection methods, as well as trusted commercial and open-source threat feeds, to quantitatively evaluate the cybersecurity posture of any organization. We continuously monitor 10 risk factor groups and instantly deliver an easy-to-understand A to F rating, empowering organizations to quickly find and fix vulnerabilities and issues.
SecurityScorecard assessments enable enterprises to cut through the "questionnaire noise" by empowering users to send, complete, and auto-validate questionnaires at scale. Our assessments leverage SecurityScorecard ratings to automatically provide insight into the validity of questionnaire responses. This inside-out approach coupled with SecurityScorecard Ratings outside-in perspective provide organizations an objective 360 degree view of the cybersecurity risks of any vendor.
Every company has the universal right to their trusted and transparent cybersecurity rating and can sign up for a free account. Please visit <www.securityscorecard.com/trust > for more information.
For inquiries about a Private Offer (PO) or a Channel Partner Private Offer (CPPO), please contact aws-sales@securityscorecard.io .
Highlights
- Hundreds of thousands of organizations followed and 12+ million companies continuously monitored
- Accelerates the vendor risk assessment process by 75% and cuts the questionnaire cycle in half
- Award-winning customer success team highly rated for "ease-of-setup" and "quality customer service" with over 98% satisfaction rate
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Security credentials achieved
(1)

Buyer guide

Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/12 months |
|---|---|---|
SSC Free | REQUEST QUOTE | $0.00 |
SSC Pro | REQUEST QUOTE | $0.00 |
SSC Business | For vendor management of 5 domains, reporting unlocked | $12,000.00 |
SSC Enterprise | Larger vendor management of 75 domains + onboarding experience | $141,250.00 |
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law or as provided in our MSA.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
Our Customer Success team is a team of advisors, partners and experts that are here to help you maximize your experience with SecurityScorecard. They help you unleash the full potential of SecurityScorecard, provide guidance on use cases, as well as keep you apprised of new product features. From onboarding and adoption through operationalization and scaling, the Customer Success team will be your partner to ensure you meet your goals as an additional layer to our technical support resources. To reach the Customer Success team contact us at csm@securityscorecard.io . For technical support please contact us at support@securityscorecard.io .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Security scoring has guided our vulnerability prioritization and now informs leadership decisions
What is our primary use case?
My main use case for SecurityScorecard is monitoring vulnerabilities that are affecting our domain.
What is most valuable?
The best features SecurityScorecard offers for me are mainly being able to properly position my organization's security posture because of the score that is provided. I am able to know if we are doing well by assigning the quality or assigning the security posture to a score. It helps put things into perspective for me and I am able to know to what extent a vulnerability exists and the level of threat and the level of information breach each vulnerability is associated with.
The score helps me to inform leadership where we truly are at with regards to our security posture as an organization. It is also able to help me prioritize which vulnerabilities to remediate, which is more important, and which one needs immediate attention. It also helps me paint the best picture of our security position to management.
SecurityScorecard helps my organization know how well we are performing with regards to our security posture, and we are able to close security gaps when they are raised in SecurityScorecard.
What needs improvement?
I realized that because my company was acquired by a bigger organization, SecurityScorecard started associating other portfolio company vulnerabilities to our score, which was not helpful because it was giving us wrong data and giving us vulnerabilities we did not have. When you dive deep, you realize that the vulnerabilities are not associated with our domain. If SecurityScorecard could improve anything, it would be making sure the algorithm pulls the right data for the right domain.
For how long have I used the solution?
I have been using SecurityScorecard for two years.
What do I think about the stability of the solution?
SecurityScorecard is stable in my experience.
How are customer service and support?
Customer support is timely. Anytime I have had to dispute anything with regards to our score or the vulnerabilities being highlighted on our domain, they address it within seventy-two hours and change or update the score.
How would you rate customer service and support?
What other advice do I have?
A typical workflow includes logging into SecurityScorecard, seeing which vulnerabilities have been flagged with regards to my domain, and then working with the engineers to have those vulnerabilities mitigated. After that, I upload the evidence into SecurityScorecard so that it can be taken off our score.
One of the benefits I have realized while using SecurityScorecard was that there was a vulnerability with our website and with the insights we got from SecurityScorecard, we were able to take a better decision of building a custom website instead of going with the template we had at the time.
Initially, SecurityScorecard monitoring was being managed by my CISO. However, with the simplicity of the dashboard and the information and the data in SecurityScorecard, he was able to easily hand it over to me, who did not have any prior experience, and I was able to quickly get the hang of things. He did not have to supervise or step in again and he was able to totally hand it over to me.
If you want a simple dashboard that is easy to understand and lets you know the vulnerabilities affecting your domain, SecurityScorecard is a good product for that. I would rate this product eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Continuous monitoring has improved our security rating and simplified vulnerability remediation
What is our primary use case?
My main use case for SecurityScorecard is to keep an eye on our vulnerabilities and also monitor which companies follow us in the platform, and we keep track when our score drops so we can fix it.
For tracking vulnerabilities or monitoring our score with SecurityScorecard , we take action based on our score, and a few people in our group have access there so they check it daily, monitor our IPs, and if there is something they need to discard. We have one specialist who fixes the vulnerabilities, and when he fixes things, he reports back to SecurityScorecard so we keep our score as high as possible, preferably at least A, and we have noticed some customers sharing reports from your platform where they needed us to have this A score.
SecurityScorecard is quite simple and easy to use, and we just need to keep track when we receive those notifications from the tool.
What is most valuable?
The best features SecurityScorecard offers are that it is easy to use and quite easy to understand what the vulnerabilities are and how to fix them. I appreciate the interface where you can see in one screen pretty much everything, and I also appreciate the feature where you can see the number of customers who follow you in the platform.
The interface of SecurityScorecard stands out for me because it is very easy. In one dashboard, you can see pretty much everything. I appreciate the nice colors that are easy to follow, and I also appreciate the graphs in the platform.
SecurityScorecard has impacted my organization positively as it was a surprise to notice that many of our customers follow us there, and the tool scans the web twice per day, so we can see how hackers and what they can see from our publicly available IPs.
Specific outcomes or metrics that show how SecurityScorecard has helped my organization include our score improving quite a lot. We started with a C or maybe D and reached the A, keeping it above 90 points, which has impacted us because it is now a metric our management follows.
What needs improvement?
I suggest that SecurityScorecard could be improved by giving a little more specifics on how the scanning works and how you are able to detect those IPs, including more details on the privacy side about how the scanner operates and how it is sometimes allowed to do those scans. Additionally, it might be good to understand how to quickly fix or report the quite a lot of false positives, perhaps through a self-checkout feature or something similar.
The features of SecurityScorecard are quite adequate and do not need anything added.
For how long have I used the solution?
I have been using SecurityScorecard for about two and a half years.
What do I think about the stability of the solution?
SecurityScorecard is stable.
What do I think about the scalability of the solution?
SecurityScorecard's scalability is easy to scale.
How are customer service and support?
The customer support for SecurityScorecard is amazing.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I did not previously use a different solution, as no solution of this kind was used before.
How was the initial setup?
Before choosing SecurityScorecard, we did not evaluate other options.
What about the implementation team?
My experience with pricing, setup cost, and licensing is that we still have the free version, but we have an offer from your side, which I think is straightforward.
What was our ROI?
I have seen a return on investment with SecurityScorecard as it is easy to use and has saved us some time, so we do not need to do the scans on our own.
What's my experience with pricing, setup cost, and licensing?
I have seen a return on investment with SecurityScorecard as it is easy to use and has saved us some time, so we do not need to do the scans on our own.
Which other solutions did I evaluate?
Before choosing SecurityScorecard, we did not evaluate other options.
What other advice do I have?
I would rate SecurityScorecard a solid nine out of ten.
I chose a nine because I appreciate the features a lot, but there is still room for small improvements, those that I mentioned above.
SecurityScorecard is deployed in my organization in a public cloud.
The cloud provider we use for SecurityScorecard is Microsoft Azure .
My advice for others looking into using SecurityScorecard is to use it as soon as possible and you will know the difference. My overall review rating for SecurityScorecard is nine.
Continuous monitoring has improved vendor risk insights and supports faster security decisions
What is our primary use case?
My main use case for SecurityScorecard is to qualify the surface and the domain of the company, and to detect vulnerabilities or assess the protection made by my client.
What is most valuable?
I provide quick visibility into the vendor's external security posture to my clients. Another situation could be highlighting specific risk areas instead of just a general score. Additionally, I support data-driven conversations with stakeholders and vendors.
SecurityScorecard helps us identify potential vulnerabilities early, reduce third-party risk, and make more informed security decisions without relying only on questionnaires or self-reporting information.
SecurityScorecard positively helps us quickly assess vendor risks and understand an organization's external security posture without spending a lot of time on manual reviews. In particular, it helps us identify security gaps early, prioritize follow-up actions, and have more informed conversations with vendors and internal stakeholders.
In terms of measurable positives regarding risk reduction, we were able to identify high-risk vendors earlier, and we complete assessments thirteen or fourteen percent faster since we rely less on lengthy questionnaires and manual evidence collection.
What needs improvement?
SecurityScorecard could be improved with more detailed remediation guidance, better customization of scoring, and stronger integration with GRC and vendor management tools.
It could also use better reporting and alert customization as well as a more intuitive user interface.
For how long have I used the solution?
I have been using SecurityScorecard for six months.
What do I think about the stability of the solution?
In my experience, SecurityScorecard is stable and operates faster without issues of downtime or reliability.
What do I think about the scalability of the solution?
My experience with SecurityScorecard is that it is highly scalable and can handle more vendors or users as my organization grows.
How are customer service and support?
We have support, and whenever I need it, my colleagues and I find that the support team is quick and responsive, helping to resolve any questions.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously used Azure or another solution called Socradar before switching to SecurityScorecard.
How was the initial setup?
My experience with the pricing has been positive because the platform is robust and user-friendly, and the setup was straightforward. Regarding licensing, my organization has a limitation on the number of domains or vendors we can integrate, but it depends on the type of license that I have.
What was our ROI?
We have seen a clear return on investment, and in terms of the metrics, the time saver is in the reduction of time spent.
Which other solutions did I evaluate?
Before choosing SecurityScorecard, we evaluated other vendors such as Azure and Socradar, but we chose SecurityScorecard for the pricing.
What other advice do I have?
My advice would be to take full advantage of the continuous monitoring and vendor insights, explore the dashboards and alerts early, and understand the license limits, specifically regarding the number of domains or vendors you can track or add in the dashboard for monitoring.
We are a partner with SecurityScorecard.
I think the interview could improve by involving discussions on how to assess other companies with risks in different areas.
I would appreciate a short poem or haiku that summarizes this review. I have provided a review rating of eight out of ten.
Continuous vendor risk insight has improved cloud visibility but still needs fresher data
What is our primary use case?
What is most valuable?
There are both advantages and disadvantages to their approach. The continuous scanning of companies all the time ensures that there is always current information available about the third-party vendors and companies being monitored. However, the downside is that the information may be several days old, so it is not always current. Despite this limitation, using SecurityScorecard enabled us to obtain information about every one of our third parties that our clients are interested in monitoring.
My focus has been primarily on third-party risk. The automated alerts allow us to receive feedback as they update their information and when something comes up, which impacts the risk rating for each vendor or third party.
What needs improvement?
Overall, SecurityScorecard is a good product, and they need to continue developing it. There are challenges around third-party risk management. When providing risk management for your own company, it does everything you want it to do. However, for managing third parties, there are still some challenges, mainly because some aspects are out of their control since you do not have control over another company's risk or infrastructure and cannot dictate whether they are making changes. Overall, SecurityScorecard provides good information, but I am always looking for something that is more automated and would provide a better and more detailed picture of third-party risk profiles.
For how long have I used the solution?
How are customer service and support?
How would you rate customer service and support?
Positive
How was the initial setup?
What's my experience with pricing, setup cost, and licensing?
Which other solutions did I evaluate?
What other advice do I have?
I am not a formal partner with the company yet, but we do conduct evaluations on behalf of our clients. I give SecurityScorecard a seven out of ten overall rating.
Continuous monitoring has strengthened our external posture and improved cyber insurance decisions
What is our primary use case?
My main use case for SecurityScorecard is that most of the time, the customer is looking for a solution which can provide all vulnerabilities and rate, security rate, and it also performs scanning of their domain, subdomain, and IP address. Customers can easily determine what weak passwords and policy configurations exist and can easily find out vulnerabilities.
A specific example of how a customer has used SecurityScorecard to solve a problem is that I have given SecurityScorecard to multiple customers, and they were looking to understand what vulnerabilities they have and what ratings they have.
I must add that SecurityScorecard continuously monitors the cybersecurity posture of the vendor, supplier, partner, SaaS platform, and others. Most of the time, the customer does not know what ports are open and whether they are exposed to vulnerabilities or weak SSL, TLS configuration, or malware signals, or misconfigured DNS. They also do not know whether their credentials are leaked. SecurityScorecard can help with this. For external attack surface monitoring, it is very useful.
What is most valuable?
The best features SecurityScorecard offers are cyber insurance underwriting and risk scoring, which I think are the best use cases, where the customer can easily reduce underwriting time and detect sudden posture changes.
Regarding how the risk scoring and cyber insurance features help my customers, they help detect sudden posture changes and evaluate the cyber hygiene of insured entities and price policies.
I would also add that it provides value for security posture management and executive reporting. It provides simple, visual, letter grade, and easy to explain metrics and score histories. Regarding the value it provides, it converts complex security issues into business-friendly language, which helps executives and the board understand cyber risk. It supports governance and risk metrics. Compliance support and auditing provide continuous monitoring, showcasing external posture over time, detecting misconfiguration that violates standards, and help with frameworks such as NIST 800 and ISO 27001, PCI DSS, HIPAA, DORA, and SOC 2.
SecurityScorecard has positively impacted my organization and my customers by providing numerous benefits. Customers easily obtain the score, which is a use case I value greatly. Customers can easily determine what ports are open and many other things so that they can secure their DNS, applications, and networks effectively.
My customers have seen measurable outcomes and specific improvements, as they have improved compliance and security with the help of SecurityScorecard.
What needs improvement?
SecurityScorecard can be improved. As it currently stands, it does a good job monitoring public-facing devices and the internet and DNS. If SecurityScorecard could also help their customers internally by developing their tool or feature so that customer devices that are not only public-facing can be monitored, it would be more beneficial.
For how long have I used the solution?
I have been using SecurityScorecard for the last five to six years.
What do I think about the stability of the solution?
SecurityScorecard is stable.
What do I think about the scalability of the solution?
The scalability of SecurityScorecard is fine, and there is no challenge with its scalability. As of now, I have not faced any issues with the scalability of SecurityScorecard.
How are customer service and support?
Customers are getting good support 24/7 from SecurityScorecard. I would rate the customer support for SecurityScorecard nine out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, customers were sometimes using FireCompass and sometimes different tools, and some customers were net new, fresh customers using SecurityScorecard for the first time. The payback period of SecurityScorecard is less than six months from an ROI perspective. Sometimes the customer evaluates other options such as FireCompass before choosing SecurityScorecard.
How was the initial setup?
My experience with pricing, setup cost, and licensing is that pricing is acceptable as per the Indian market.
What about the implementation team?
As of now, the customer is happy, and I have not seen any complaints from the customer regarding purchasing SecurityScorecard.
What was our ROI?
When I talk about the return on investment with SecurityScorecard, the customer feedback shows that it is good from an ROI perspective. I have observed that the customer is getting 176% ROI over three years, and they are happy with it.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that pricing is acceptable as per the Indian market.
Which other solutions did I evaluate?
Sometimes the customer evaluates other options such as FireCompass before choosing SecurityScorecard.