TrustCheck AI Scoring Methodology
This page documents how the Cyber Trust Score is calculated, so the methodology is transparent and reviewable — not a black box.
1. Assessment domains
TrustCheck AI organizes 16 scored questions into six domains aligned to the NIST Cybersecurity Framework (CSF) 2.0 functions:
| Domain | NIST CSF 2.0 function | Weight |
|---|---|---|
| Govern & Identify | GOVERN / IDENTIFY | 20% |
| Protect | PROTECT | 25% |
| Detect | DETECT | 15% |
| Respond | RESPOND | 15% |
| Recover | RECOVER | 15% |
| AI Governance | GOVERN (AI-specific) | 10% |
2. Question scoring
Each scored question is answered on a fixed scale:
| Yes | 100 points |
| Partially | 50 points |
| Not sure | 25 points |
| No | 0 points |
| N/A | Excluded from scoring entirely |
3. Domain and overall score calculation
A domain's score is the simple average of its answered (non-N/A) question scores. The overall Cyber Trust Score is a weighted average of domain scores, using the weights above. If an entire domain is not applicable (for example, AI Governance for an organization that does not use generative AI), that domain is excluded and the remaining domain weights are renormalized proportionally so the score always reflects only the domains that actually apply to you.
4. Score bands
| 0–39 | Critical Attention |
| 40–59 | High Priority |
| 60–74 | Developing |
| 75–89 | Managed |
| 90–100 | Strong |
5. Role of AI
The underlying Cyber Trust Score is calculated entirely by this fixed, deterministic formula — not by a generative AI model. Generative AI, where used elsewhere on this site, is limited to explaining findings, translating technical concepts into plain English, and organizing recommendations. It does not determine the numeric score.
6. Limitations
- This is a self-reported assessment. We do not independently verify your answers.
- The Cyber Trust Score is an educational indicator, not a certification, compliance determination, security guarantee, formal audit, or penetration test.
- It does not replace professional security assessment for organizations with significant regulatory, financial, or safety exposure.
- The weighting reflects a reasonable, documented judgment about relative risk priority for small organizations — it is not derived from a formal empirical study (yet). As the Research Observatory matures, this methodology may be refined and the version number updated.
7. Privacy
All scoring happens in your browser. Your answers are not transmitted to or stored on any CyberAbeer server unless you separately opt in to voluntary research participation. See the Privacy Notice for details.
8. Version history
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026 | Initial published methodology at TrustCheck AI launch. |