Bitsight's Ratings Algorithm Update for 2026 Makes Risk Vectors More Impactful

bitsight rau 2026
Abdullah Al Rashid
Written by Abdullah Al Rashid
Senior Data Scientist
Alex Hadjinicolaou
Written by Alex Hadjinicolaou
Senior Data Scientist
Written by Xiaofei Yang
Staff Data Scientist

Making risk vectors more impactful

Bitsight's annual Ratings Algorithm Update (RAU) has been in effect as of July 16, 2026. In preparation, RAU 2026 Preview was made available in April 2026. As in the past, RAU 2026 is an effort to account for the continuous evolution of the threat landscape the Bitsight security ratings seek to quantify. 

This year's update is focused on modernizing the rating by improving how it is composed from various risk vectors (RVs). In particular, this entails the following:

  • Patching Cadence (PC) has been supplanted by Critical Vulnerability Management (CVM), with no change in weight (20% of the Bitsight rating).
  • DMARC begins to impact ratings at a weight of 1%, while the impact of Compromised Systems is reduced to 26% from 27%.
  • SPF and DKIM use a more refined scoring approach in the absence of findings.

DMARC is now a ratings-impacting part of Bitsight's E-Mail Security

fig1 bitsight rau 2026
Infographic Depicting Elements of E-Mail Security: SPF, DKIM, and DMARC

In addition to Sender Policy Framework (SPF) and Domain Keys Identified Mail (DKIM)Domain-based Message Authentication, Reporting, and Conformance (DMARC) constitutes a pillar of modern e-mail security. Specifically, DMARC requires that the domains used for delivering messages (SPF's Mail From or DKIM's d= tag) align with the visible domain in the "From" field of the email, and dictates how receiving servers should handle messages that fail authentication. Details of Bitsight's evaluation of DMARC are available here, with guidance on how to set  up a DMARC policy discussed hereStarting in RAU 2026, DMARC accounts for 1% of the Bitsight rating, bringing its impact in line with those of SPF and DKIM. On a related note, Compromised Systems now accounts for 26% of the ratings, instead of the 27% before RAU 2026.

SPF and DKIM no longer penalize entities without domains

For the evaluation of E-Mail Security, an absence of appropriately configured security elements for a domain constitutes a vulnerability. In light of this, the security ratings algorithm is designed to penalize the absence of detectable SPF and DKIM records — previously awarding an F and a C grade, respectively — for these situations.

However, not all entities have domains registered to them. As a result, they cannot send or receive e-mails, nor can they be expected to have SPF and DKIM records that administer e-mails. 

To account for this nuance and in keeping with the grading of DMARC, entities with no domains will receive 'N/A' grades for these risk vectors (while entities with domains but no SPF and/or DKIM records will be penalized per usual for e-mail misconfiguration).

Critical Vulnerability Management (CVM) supplants Patching Cadence (PC)

With this RAU, we replace the Patching Cadence risk vector with Critical Vulnerability Management (CVM), which is designed to have a better balance between the impact of severity and the impact of the remediation time. Patching Cadence is dominated by the remediation time while CVM limits the rating impact of a vulnerability depending on its severity (using the CVSS score).

Additional details on CVM, such as the maximum achievable percentiles (directly related to RVgrades) by maximum severities and durations, are available on the Bitsight Knowledge Base. For API updates pertaining to the PC-to-CVM transition, see the linked article.

While the focus is still on the time it takes to patch vulnerable software, the formulation of CVM rewards prompt patching of more severe vulnerabilities much more significantly. As a result, the top performers in PC remain high-achievers in CVM, but a focus on the timely patching of high-severity issues becomes the differentiator between the top performers and others in CVM. The PC vs. CVM grade distribution changes, illustrated below, depict this.

fig2 bitsight rau 2026
Risk Vector Grade Distribution Comparisons for Entities with Findings Between Patching Cadence (PC) and Critical Vulnerability Management (CVM)

CVM will retain the same level of rating impact as PC at 20%.

Correlation to breach remains unaffected while capturing new layers of meaning

As illustrated by the overlapping error bars in the Rank Biserial Correlation (RBC) plots for breaches, the Bitsight security ratings maintain the same levels of correlation to breaches as the previous version.

fig3 bitsight rau 2026
Breach Correlation Comparison of the Bitsight Security Ratings Between Current (RAU 2025) and Upcoming (RAU 2026) Versions Based on the Absolute Values of Rank Biserial Correlation Derived from Bitsight's 'CyberPlus' Dataset (for Known Security Incidents Exclusive of Ransomware)

 

fig4 bitsight rau 2026
Breach Correlation Comparison of the Bitsight Security Ratings Between Current (RAU 2025) and Upcoming (RAU 2026) Versions Based on the Absolute Values of Rank Biserial Correlation Derived from Bitsight's 'Ransomware' Dataset (i.e. Recordings of Known Ransomware Incidents)

The ratings become more complete and intuitive

The inclusion of DMARC in the Bitsight security ratings complements the E-Mail Security suite already offered by SPF and DKIM. Meanwhile, the nuanced scoring approach for SPF and DKIM to account for domain-less entities makes the ratings fairer. Lastly, the complete overhaul of PC as CVM places due emphasis on the earliest patching of the severest vulnerabilities that an organization has to defend itself from.

Bitsight cta background color
2026 Bitsight Is Named a Leader in The Forrester Wave CTA cover

Bitsight Named a Leader in The Forrester Wave™ for Cybersecurity Risk Rating Platforms, Q2 2026

Explore why Forrester recognized Bitsight as a Leader in its 2026 evaluation and how Bitsight delivers the intelligence needed to support stronger cyber risk decisions.

 

Get the report

Bitsight cta background color