Every tool recommendation in your assessment carries a Tool Trust Index (TTI) — a vertical-aware score derived from independent, authoritative trust signals. No vendor self-attestation. No analyst opinion polls. Every score is fully explainable.
Every security tool on the market claims to be trustworthy. Most of those claims are unverifiable. Buyers — especially in K-12, SLTT, and small business markets — are routinely asked to choose between dozens of products with no objective basis for comparison.
TTI answers the question buyers actually need to ask: which of these products has been independently vetted, and by whom? It draws from public registries — CISA, FedRAMP®, GovRAMP, NIST CMVP, CSA STAR, Gartner, Forrester, IDC — and combines them into a single score, calibrated to your industry vertical.
Scores tools. Tells you which products to actually procure.
Soft organizational attestation for breaking ties between similarly-scored tools.
UCPA and TTI share no scoring state. They operate on different objects (controls vs. tools) and are complementary, not overlapping.
TTI is the sum of all applicable, enabled signal scores, normalized to a 0–100 scale, then multiplied by a KEV exposure factor. The denominator adjusts to your vertical and configuration — so tools are never penalized for signals that don't apply to their market.
The CISA Known Exploited Vulnerabilities catalog is special. A tool with an active, unpatched KEV entry cannot be made trustworthy by stacking other credentials. KEV is applied as a final multiplier — capable of zeroing the score regardless of what comes before it.
No impact. The full additive score carries through.
The vendor has responded. Patch application is unverifiable, so a significant trust penalty applies.
The tool is suppressed from recommendations regardless of any other signal performance.
TTI does not track software versions. Without version data, we cannot assert that a KEV entry doesn't apply to your specific environment — so once a product appears in KEV, that flag stays. Partial credit is awarded only for vendor patch publication, never for assumed customer remediation.
KEV is the one signal that cannot be disabled. Not by you, not by a partner, not by configuration. This is intentional liability protection.
Each signal contributes points to the additive score. Maximum contributions vary by signal and by vertical. Signals not applicable to your vertical are excluded from both the numerator and denominator — no penalty for missing what was never relevant.
Each analyst firm scores independently — no single firm can dominate. Per-firm contribution is capped, with a multi-year time decay applied to reduce the weight of stale evaluations. Stacking multiple years from the same firm is not permitted.
Combined contribution across all three firms is capped.
A procurement gate signal — "has this product been vetted for government use?" — not a threat signal. RAMP scores are multiplied by a vertical weight: full weight for Federal, State/Local Gov, DIB, K-12 and Higher Ed; reduced for less-relevant verticals.
Independently tested cryptographic implementations. Technically rigorous across most verticals — any environment handling sensitive data benefits from confirmed cryptographic validation.
Cloud-specific security assurance from the Cloud Security Alliance. Level 2 (independent third-party assessment) carries significantly more weight than Level 1 (self-assessment), reflecting the rigor difference between attested and verified claims.
Each vertical has a default signal profile reflecting which credentials matter in that market. You can enable additional signals within your vertical's bounds — but you cannot disable KEV, and you cannot enable signals that aren't applicable. Both rules are platform-defined for score consistency.
Signal Defaults by Vertical
| Vertical | KEV | MA | FedRAMP | GovRAMP | FIPS | CSA |
|---|---|---|---|---|---|---|
| Federal Gov | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| State Gov | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Local Gov | ✓ | ✓ | ○ | ✓ | ✓ | ✓ |
| Defense Industrial Base | ✓ | ✓ | ✓ | ○ | ✓ | ✓ |
| K-12 Education | ✓ | ✓ | ○ | ✓ | ✓ | ✓ |
| Higher Education | ✓ | ✓ | ✓ | ○ | ✓ | ✓ |
| Healthcare | ✓ | ✓ | ○ | — | ✓ | ✓ |
| Pharmaceuticals | ✓ | ✓ | ○ | — | ✓ | ✓ |
| Research Institutions | ✓ | ✓ | ○ | ○ | ✓ | ✓ |
| Banking | ✓ | ✓ | — | — | ✓ | ○ |
| Insurance | ✓ | ✓ | — | — | ✓ | ○ |
| Utilities | ✓ | ✓ | — | — | ✓ | ○ |
| E-Commerce | ✓ | ✓ | — | — | ✓ | ○ |
| SMB | ✓ | ✓ | — | — | ○ | ○ |
| Church / Faith | ✓ | ✓ | — | — | ○ | ○ |
| Nonprofit | ✓ | ✓ | — | — | ○ | ○ |
RAMP authorization is the dominant procurement gate. FedRAMP and GovRAMP carry full vertical weight (1.0). Tools without authorization face a measurable score ceiling.
GovRAMP is increasingly required; FedRAMP available but off by default. Cloud assurance (CSA) reflects the SaaS-heavy edtech market.
Banking, Insurance, Utilities, E-Commerce. Sector-specific regimes (FFIEC, NAIC, NERC CIP, PCI DSS) dominate procurement — so RAMP is excluded and CSA is optional rather than default.
A hypothetical cloud security platform serving K-12 Education (V12), evaluated against all enabled signals for that vertical. Contributions are shown qualitatively — the exact point values are confidential.
| Signal | Value | Contribution | Notes |
|---|---|---|---|
| Gartner (2026) | Leader | Full | Current evaluation — no decay applied |
| Forrester (2024) | Strong Performer | Partial | Reduced by two years of time decay |
| IDC (2021) | Mention | None | Past the staleness cutoff — excluded |
| FedRAMP Moderate | Authorized | Major | Full vertical weight for K-12 |
| FIPS 140-2 Level 2 | Validated | Moderate | Tamper-evidence requirements met |
| CSA STAR Level 2 | Third-Party Assessed | Moderate | Independent verification |
| TTIraw | Sum of signal contributions | — | All enabled, applicable signals |
| TTInormalized | Scaled to 0–100 | — | Against the V12 maximum applicable score |
| KEVmultiplier | Not in KEV | × 1.0 | No exposure penalty |
| TTIfinal | Normalized score, no KEV penalty | ~79 | → Trusted band |
The exact point values, decay schedule, and KEV multipliers are confidential — but they are cryptographically committed. We publish a SHA-256 fingerprint of every versioned signal schedule. Customers and auditors who receive the schedule under confidentiality can hash it and confirm it matches this public commitment, proving the scoring was fixed in advance and never retro-tuned to favor a vendor.
The final 0–100 score maps to one of six bands. Each band determines how the tool is surfaced — or whether it's surfaced at all.
| Range | Band | Recommendation Behavior |
|---|---|---|
| 85 – 100 | Highly Trusted | Recommend with confidence. Surface prominently. |
| 65 – 84 | Trusted | Recommend. Minor caveats may apply. |
| 40 – 64 | Provisionally Trusted | Recommend with conditions. Surface applicable caveats. |
| 20 – 39 | Low Trust | Surface but flag prominently. Advise additional due diligence. |
| 1 – 19 | Insufficient Vetting | Do not recommend without disclosure. |
| 0 | Do Not Recommend | KEV hit with no patch available. Suppress from recommendations. |
Tools with a KEV multiplier below 1.0 carry plain-language disclosure attached to the recommendation. The language is verbatim and consistent — no buried warnings, no marketing softening.
"This tool has a known exploited vulnerability with no vendor patch currently available. FrameworkMapper does not recommend this tool at this time."
"This tool has a known exploited vulnerability. A vendor patch exists, but FrameworkMapper cannot verify whether the patch has been applied in your environment. This tool is scored with a significant trust penalty."
The same underlying data drives two views. Switch between them with a single toggle on any tool comparison surface.
TTI score computed from enabled, applicable signals only. Apples-to-apples comparison within your configuration.
Same score, plus badges surfacing credentials that exceed the baseline expectation for the vertical.
Every TTI score decomposes into its constituent signal scores, decay multipliers, vertical weights, and KEV state. The full breakdown is preserved and surfaced as plain-language rationale on the tool detail page:
TTI reflects vendor-level trust signals available from authoritative public registries at the time of catalog enrichment. It is not a vulnerability scanner, patch verification engine, or real-time threat feed.
Where we cannot verify something — such as whether a published vendor patch has actually been applied in your environment — we say so explicitly rather than imply confidence we don't have.
Every signal traces back to a specific public registry: a KEV entry, a FedRAMP Marketplace listing, a CMVP certificate ID, a CSA STAR registry record, an analyst report citation.
Each score snapshot is preserved per assessment for audit and historical comparison — supporting procurement justifications, board reporting, and grant applications.
Signal data refreshes on cadences calibrated to each source: KEV weekly (with manual force-refresh for active incidents), RAMP / FIPS / CSA monthly. Analyst rankings refresh quarterly via the catalog enrichment pipeline.
Every refresh is recorded as a versioned snapshot, so changes in a tool's TTI score are traceable over time.
TTI scores which tools to buy. UCPA — the Universal Control Prioritization Algorithm — scores which controls to implement first. The two algorithms share no scoring state and operate on different objects, but together they answer "what should I do, and what should I buy to do it?"
The Tool Trust Index was developed by Midwest Cyber, LLC and Viosoph, LLC and is implemented within the FrameworkMapper platform. © 2026 Midwest Cyber, LLC and Viosoph, LLC. All rights reserved.
Browse the FrameworkMapper tool catalog with TTI scores and per-signal breakdowns. Run an assessment to receive vertical-tuned tool recommendations alongside your prioritized control roadmap.