SSVC Decision Calculator

Work through the SSVC decision tree to get a defensible act, track, attend or immediate outcome, with the reasoning recorded for the ticket.

Runs locally

Everything happens in your browser. What you paste or drop here is never uploaded, logged or stored.

Use the tool

A decision, not a score

SSVC (Stakeholder-Specific Vulnerability Categorization) replaces "how high is the number?" with a short sequence of questions, each with a small fixed set of answers. The answers lead to one of a few actions. This page implements the CISA Coordinator decision table, version 2.0.3, as published by the CERT Coordination Center. Its four questions are exploitation status, automatability, technical impact, and mission and well-being impact. Its four outcomes are Track, Track*, Attend and Act.

The questions

Exploitation: is there no evidence, a public proof of concept, or active exploitation in the wild? The KEV catalogue answers "active" for many CVEs. Automatable: can an attacker reliably automate reconnaissance, weaponisation, delivery and exploitation? Technical impact: does exploitation give partial or total control of the vulnerable component? Mission and well-being impact: this combines how essential the affected component is to your mission with how badly exploitation could harm people. You can answer it directly, or derive it from its two parts here.

Recorded, so it can be defended

Each answer takes a rationale and a piece of evidence (a KEV entry, an advisory, an asset register). The export records the whole path: model name and version, every decision point with its version, your answer, your reason and your evidence. A reviewer can see not just the outcome but why it was reached, and redo the decision when a fact changes, such as a proof of concept appearing.

Not universally authoritative

The Coordinator tree reflects CISA's role as a national coordinator. Other stakeholders are expected to tailor it. A software supplier deciding patch priority and a hospital deciding deployment order weigh things differently, and SSVC was designed for that. Treat the outcome as your organisation applying a published model, record any changes you make, and review the decision when the inputs change.

One combination is left to you

The official definitions derive mission and well-being impact in every case except one: a component with minimal mission prevalence whose exploitation would cause material harm to public well-being. The definitions do not state an answer for that combination, so the calculator does not invent one. It asks you to choose Medium or High and to record why.

Frequently asked questions

What is the difference between Track and Track*?

Both mean no action beyond normal update timelines. Track* flags characteristics worth closer monitoring, so a change such as new exploitation should prompt a re-decision.

How does this relate to CVSS?

SSVC does not use CVSS. Technical impact and automatability overlap with some CVSS ideas, but the decision comes from the table, not a formula. Use the Prioritization Calculator if you want a weighted score instead.

Is anything sent to a server?

No. The decision table ships with the page and everything is recorded in your browser until you export it.

Sources and licence

What this tool can and cannot tell you. It reports what is present in the input you provide. It cannot see anything you did not give it, and a clean result means nothing was found in that input - not that the wider system is secure.

Security guidance here follows current published sources - OWASP, MDN, the relevant RFCs, NIST, CISA, FIRST and MITRE - which are linked beside the specific claims they support.

Rate this tool

Was this tool useful? Your feedback helps us improve it.

No ratings yet — be the first to rate this tool.
Your rating (required)
0 / 2000

Please do not include passwords, payment details or other sensitive information.

Your feedback is sent privately to the A2Z.Tools team and will not be posted publicly.