FrameworkMapper
 
Vendor Trust, Transparently Scored

How We Decide Which Tools to Recommend

Every tool recommendation in your assessment carries a Tool Trust Index (TTI) — a vertical-aware score derived from independent, authoritative trust signals. No vendor self-attestation. No analyst opinion polls. Every score is fully explainable.

 

Vendors Say "Secure." We Show the Receipts.

Every security tool on the market claims to be trustworthy. Most of those claims are unverifiable. Buyers — especially in K-12, SLTT, and small business markets — are routinely asked to choose between dozens of products with no objective basis for comparison.

TTI answers the question buyers actually need to ask: which of these products has been independently vetted, and by whom? It draws from public registries — CISA, FedRAMP®, GovRAMP, NIST CMVP, CSA STAR, Gartner, Forrester, IDC — and combines them into a single score, calibrated to your industry vertical.

5
Independent trust signals
24
Vertical default profiles
100%
Explainable
No
Vendor self-attestation
 
Layer 1
UCPA

Prioritizes controls. Tells you what to fix first.

Methodology overview →
Layer 2 — You Are Here
Tool Trust Index (TTI)

Scores tools. Tells you which products to actually procure.

Layer 3 — Future
Tiebreaking Signals

Soft organizational attestation for breaking ties between similarly-scored tools.

UCPA and TTI share no scoring state. They operate on different objects (controls vs. tools) and are complementary, not overlapping.

 

The Trust Index Formula

TTI is the sum of all applicable, enabled signal scores, normalized to a 0–100 scale, then multiplied by a KEV exposure factor. The denominator adjusts to your vertical and configuration — so tools are never penalized for signals that don't apply to their market.

TTIraw = MA + (RAMP × Wvertical) + FIPS + CSA
TTInormalized = (TTIraw / TTImax applicable) × 100
TTIfinal = TTInormalized × KEVmultiplier
KEV — Known Exploited Vulnerabilities
MA — Market Analysis
RAMP — FedRAMP / GovRAMP
FIPS — FIPS 140-2/3 Validation
CSA — Cloud Security Alliance STAR
The Disqualifier Signal

KEV is a Multiplier, Not an Addend

The CISA Known Exploited Vulnerabilities catalog is special. A tool with an active, unpatched KEV entry cannot be made trustworthy by stacking other credentials. KEV is applied as a final multiplier — capable of zeroing the score regardless of what comes before it.

Not Present in KEV
× 1.0

No impact. The full additive score carries through.

In KEV — Patch Exists
Reduced

The vendor has responded. Patch application is unverifiable, so a significant trust penalty applies.

In KEV — No Patch
× 0.0

The tool is suppressed from recommendations regardless of any other signal performance.

Why KEV Doesn't Age Off

TTI does not track software versions. Without version data, we cannot assert that a KEV entry doesn't apply to your specific environment — so once a product appears in KEV, that flag stays. Partial credit is awarded only for vendor patch publication, never for assumed customer remediation.

KEV is the one signal that cannot be disabled. Not by you, not by a partner, not by configuration. This is intentional liability protection.

The Four Additive Signals

Each signal contributes points to the additive score. Maximum contributions vary by signal and by vertical. Signals not applicable to your vertical are excluded from both the numerator and denominator — no penalty for missing what was never relevant.

MA
Market Analysis
Gartner, Forrester, IDC — commercial credibility

Each analyst firm scores independently — no single firm can dominate. Per-firm contribution is capped, with a multi-year time decay applied to reduce the weight of stale evaluations. Stacking multiple years from the same firm is not permitted.

Tier Scores
  • Higher placement tiers earn proportionally more credit
  • Evaluations decay year over year; stale evaluations age out entirely
  • Exact tier points and decay rates are confidential

Combined contribution across all three firms is capped.

RAMP
FedRAMP / GovRAMP
Third-party government authorization

A procurement gate signal — "has this product been vetted for government use?" — not a threat signal. RAMP scores are multiplied by a vertical weight: full weight for Federal, State/Local Gov, DIB, K-12 and Higher Ed; reduced for less-relevant verticals.

Authorization Levels (Base Score)
  • Credit scales with authorization rigor
  • FedRAMP High > FedRAMP Moderate > GovRAMP Authorized > FedRAMP Low > GovRAMP Progressing
  • Exact base scores are confidential
FIPS
FIPS 140 Validation
NIST CMVP cryptographic module validation

Independently tested cryptographic implementations. Technically rigorous across most verticals — any environment handling sensitive data benefits from confirmed cryptographic validation.

Validation Levels
  • FIPS 140-3 validation earns the most credit
  • FIPS 140-2 Level 2 earns more than Level 1
  • Exact point values are confidential
CSA
CSA STAR Registry
Cloud Security Alliance assurance levels

Cloud-specific security assurance from the Cloud Security Alliance. Level 2 (independent third-party assessment) carries significantly more weight than Level 1 (self-assessment), reflecting the rigor difference between attested and verified claims.

Assurance Levels
  • Level 2 (third-party assessment) carries substantially more credit than Level 1 (self-assessment)
  • Exact point values are confidential
 

Tuned to Your Industry

Each vertical has a default signal profile reflecting which credentials matter in that market. You can enable additional signals within your vertical's bounds — but you cannot disable KEV, and you cannot enable signals that aren't applicable. Both rules are platform-defined for score consistency.

Signal Defaults by Vertical

Enabled by default Available, disabled Not applicable
Vertical KEV MA FedRAMP GovRAMP FIPS CSA
Federal Gov
State Gov
Local Gov
Defense Industrial Base
K-12 Education
Higher Education
Healthcare
Pharmaceuticals
Research Institutions
Banking
Insurance
Utilities
E-Commerce
SMB
Church / Faith
Nonprofit
Showing 16 of 24 verticals. See all verticals →
Federal & SLTT

RAMP authorization is the dominant procurement gate. FedRAMP and GovRAMP carry full vertical weight (1.0). Tools without authorization face a measurable score ceiling.

K-12 Education

GovRAMP is increasingly required; FedRAMP available but off by default. Cloud assurance (CSA) reflects the SaaS-heavy edtech market.

Regulated Non-Gov

Banking, Insurance, Utilities, E-Commerce. Sector-specific regimes (FFIEC, NAIC, NERC CIP, PCI DSS) dominate procurement — so RAMP is excluded and CSA is optional rather than default.

Worked Example

A hypothetical cloud security platform serving K-12 Education (V12), evaluated against all enabled signals for that vertical. Contributions are shown qualitatively — the exact point values are confidential.

Signal Value Contribution Notes
Gartner (2026) Leader Full Current evaluation — no decay applied
Forrester (2024) Strong Performer Partial Reduced by two years of time decay
IDC (2021) Mention None Past the staleness cutoff — excluded
FedRAMP Moderate Authorized Major Full vertical weight for K-12
FIPS 140-2 Level 2 Validated Moderate Tamper-evidence requirements met
CSA STAR Level 2 Third-Party Assessed Moderate Independent verification
TTIraw Sum of signal contributions All enabled, applicable signals
TTInormalized Scaled to 0–100 Against the V12 maximum applicable score
KEVmultiplier Not in KEV × 1.0 No exposure penalty
TTIfinal Normalized score, no KEV penalty ~79 → Trusted band
Same tool with an active, unpatched KEV entry:
TTIfinal = anything × 0.0 = 0 → Do Not Recommend

Signal Schedule Integrity Commitment

The exact point values, decay schedule, and KEV multipliers are confidential — but they are cryptographically committed. We publish a SHA-256 fingerprint of every versioned signal schedule. Customers and auditors who receive the schedule under confidentiality can hash it and confirm it matches this public commitment, proving the scoring was fixed in advance and never retro-tuned to favor a vendor.

TTI signal point schedule v1.0 (committed 2026-06-10) — SHA-256
e49e7b742279c958a357ba23f5d2e25aaf38a9144d2186f150916b020cea54af

Score Bands

The final 0–100 score maps to one of six bands. Each band determines how the tool is surfaced — or whether it's surfaced at all.

Range Band Recommendation Behavior
85 – 100 Highly Trusted Recommend with confidence. Surface prominently.
65 – 84 Trusted Recommend. Minor caveats may apply.
40 – 64 Provisionally Trusted Recommend with conditions. Surface applicable caveats.
20 – 39 Low Trust Surface but flag prominently. Advise additional due diligence.
1 – 19 Insufficient Vetting Do not recommend without disclosure.
0 Do Not Recommend KEV hit with no patch available. Suppress from recommendations.

When KEV Applies, We Say So

Tools with a KEV multiplier below 1.0 carry plain-language disclosure attached to the recommendation. The language is verbatim and consistent — no buried warnings, no marketing softening.

When no patch is available

"This tool has a known exploited vulnerability with no vendor patch currently available. FrameworkMapper does not recommend this tool at this time."

When a vendor patch exists

"This tool has a known exploited vulnerability. A vendor patch exists, but FrameworkMapper cannot verify whether the patch has been applied in your environment. This tool is scored with a significant trust penalty."

Two Ways to Read a TTI Score

The same underlying data drives two views. Switch between them with a single toggle on any tool comparison surface.

Default

Normalized View

TTI score computed from enabled, applicable signals only. Apples-to-apples comparison within your configuration.

  • Disabled signals excluded from both numerator and denominator
  • Tools competing in the same vertical scored identically
  • The fair ranking surface for standard procurement decisions
Advanced

Above and Beyond View

Same score, plus badges surfacing credentials that exceed the baseline expectation for the vertical.

  • No score change — badges are metadata only
  • Identifies tools that went further than required for their market
  • Badges only display when TTIfinal ≥ 40 (to prevent badge-padding on low-trust tools)

Every Score Is Explainable

Every TTI score decomposes into its constituent signal scores, decay multipliers, vertical weights, and KEV state. The full breakdown is preserved and surfaced as plain-language rationale on the tool detail page:

"This tool scores 79 in K-12. Gartner (2026 Leader) and Forrester (2024 Strong Performer, reduced by time decay) contribute commercial credibility; FedRAMP Moderate carries full K-12 weight; FIPS 140-2 Level 2 and CSA STAR Level 2 complete the additive score, normalized against the K-12 maximum. No KEV exposure detected. Exact per-signal point contributions are disclosed in customer reports under your engagement's confidentiality terms."

Honest About Scope

TTI reflects vendor-level trust signals available from authoritative public registries at the time of catalog enrichment. It is not a vulnerability scanner, patch verification engine, or real-time threat feed.

Where we cannot verify something — such as whether a published vendor patch has actually been applied in your environment — we say so explicitly rather than imply confidence we don't have.

Cited Data Sources

Every signal traces back to a specific public registry: a KEV entry, a FedRAMP Marketplace listing, a CMVP certificate ID, a CSA STAR registry record, an analyst report citation.

Each score snapshot is preserved per assessment for audit and historical comparison — supporting procurement justifications, board reporting, and grant applications.

Kept Current

Signal data refreshes on cadences calibrated to each source: KEV weekly (with manual force-refresh for active incidents), RAMP / FIPS / CSA monthly. Analyst rankings refresh quarterly via the catalog enrichment pipeline.

Every refresh is recorded as a versioned snapshot, so changes in a tool's TTI score are traceable over time.

Complementary Algorithm

Looking for Control Scoring?

TTI scores which tools to buy. UCPA — the Universal Control Prioritization Algorithm — scores which controls to implement first. The two algorithms share no scoring state and operate on different objects, but together they answer "what should I do, and what should I buy to do it?"

Primary Data Sources

CISA Known Exploited Vulnerabilities (KEV)
Authoritative catalog of vulnerabilities confirmed as actively exploited
FedRAMP Marketplace
Federal cloud product authorization registry
StateRAMP / GovRAMP Authorized Product List
State and local government cloud authorization registry
NIST CMVP (Cryptographic Module Validation Program)
FIPS 140-2 / 140-3 cryptographic module certificates
CSA STAR Registry
Cloud Security Alliance Security, Trust, Assurance and Risk Registry
Gartner, Forrester, IDC
Tier-1 analyst placement — commercial credibility signal with 5-year time decay
DISA APL & NIAP Common Criteria (v1.1)
Additional Federal / DIB signals architecturally reserved for the next release

The Tool Trust Index was developed by Midwest Cyber, LLC and Viosoph, LLC and is implemented within the FrameworkMapper platform. © 2026 Midwest Cyber, LLC and Viosoph, LLC. All rights reserved.

 

See Tool Trust Scores in Action

Browse the FrameworkMapper tool catalog with TTI scores and per-signal breakdowns. Run an assessment to receive vertical-tuned tool recommendations alongside your prioritized control roadmap.