How We Determine What to Fix First
Every priority ranking in your assessment results is produced by the Universal Control Prioritization Algorithm (UCPA) — a deterministic, seven-factor scoring model developed by Viosoph, LLC.
Start an AssessmentFrameworks Tell You What. We Tell You What First.
CIS Controls v8.1 has 153 safeguards. NIST SP 800-53 has 323 base controls — 1,189 including enhancements. CMMC Level 2 requires 110 practices. Organizations subject to multiple frameworks can face a combined control universe exceeding 1,500 requirements.
Frameworks are intentionally silent on implementation order — context matters. But that leaves most organizations without actionable guidance. The UCPA fills that gap with a transparent, reproducible scoring model that turns a compliance checklist into an implementation roadmap.
The Priority Score Formula
Every control receives a composite Priority Score (P) computed from seven weighted factors. Each factor is normalized to a 0–100 scale before weighting, and the weights always sum to 1.0.
The Seven Factors Explained
Each factor draws from empirical, publicly available data sources — not vendor claims or consultant opinion.
Controls that mitigate techniques appearing in active campaigns score higher than those addressing theoretical or rarely observed threats.
- › CISA Known Exploited Vulnerabilities (KEV) Catalog
- › Verizon Data Breach Investigations Report (DBIR)
- › MITRE ATT&CK® technique prevalence data
- › MS-ISAC advisories (K-12 & SLTT focus)
- › CISA #StopRansomware joint advisories
Computed from a Directed Acyclic Graph (DAG) of control relationships. Controls with high out-degree — those that unlock or amplify other controls — are prioritized as foundational infrastructure.
- › Hard prerequisite (B cannot be done without A)
- › Enabler (A makes B functional)
- › Amplifier (A increases B's effectiveness)
- › Policy foundation (A provides governance basis for B)
Particularly important for resource-constrained organizations. Scores are calibrated to three resource profiles: Minimal (volunteer IT), Moderate (small IT team), and Well-resourced (dedicated security staff).
- › Implementation cost (licensing, hardware, staffing)
- › Implementation time to operational status
- › Skill requirement & maintenance burden
- › Breadth and depth of defensive value
Distinct from Threat Relevance: T measures probability, B measures magnitude. Together they approximate classic risk (likelihood × impact), decomposed into independently scored components.
- › Data exposure potential
- › Operational disruption to mission continuity
- › Lateral movement enablement
- › Recovery complexity & regulatory penalty exposure
Scored on a rubric tied to real-world consequence: automatic audit failure scores highest; best-practice recommendations score lowest. The vertical weight profile determines R's influence — it matters most for defense contractors (CMMC) and least for churches.
- › 81–100: Automatic audit failure or loss of certification
- › 61–80: Commonly tested, appears in POA&Ms
- › 41–60: Referenced in regulation, not individually assessed
- › 0–40: Recommended or no direct mandate
Cross-framework consensus is a strong signal of foundational importance. When CIS, NIST CSF, NIST 800-53, CMMC, and HIPAA all require access control enforcement, that convergence speaks for itself.
- › 81–100: Referenced by 6 or more frameworks
- › 61–80: Referenced by 4–5 frameworks
- › 41–60: Referenced by 2–3 frameworks
- › 0–40: Unique to a single framework
The only factor that varies by individual organization rather than by vertical. A control protecting cloud workloads is irrelevant to an organization with no cloud presence. Asset Exposure personalizes the priority sequence to your actual environment.
Each control is pre-tagged with relevant environment factors. Your assessment responses activate or deactivate relevance flags, producing an A score of 0 (irrelevant), 50 (partially relevant), or 100 (directly applicable).
- › Cloud service usage (IaaS, PaaS, SaaS)
- › Remote workforce percentage
- › Bring-your-own-device (BYOD) policies
- › Operational technology (OT/IoT) presence
- › Internet-facing service exposure
- › Third-party integration density
Tuned to Your Industry
The seven factor weights are not one-size-fits-all. Each industry vertical has a default weight profile that reflects its operational reality — threat exposure, resource constraints, and compliance obligations.
Emphasis Profiles — Illustrative Examples
Illustrative — not the actual coefficients| Vertical | T | D | E | B | R | C | A |
|---|---|---|---|---|---|---|---|
| K-12 Education | Leads | Leads | Leads | Standard | Minimal | Standard | Standard |
| Defense Industrial Base | Standard | Standard | Minimal | Standard | Dominant | Standard | Standard |
| Church / House of Worship | Standard | Elevated | Leads | Reduced | Minimal | Elevated | Standard |
All 24 verticals carry a calibrated seven-factor weight profile. The exact coefficients are confidential and proprietary to Viosoph, LLC. Customers receive the applied weights for their vertical inside assessment reports under their engagement's confidentiality terms, and authorized auditors can verify them against the integrity commitment below.
Elevated ransomware exposure, minimal IT staff, limited budgets. Threat Relevance, Dependency, and Effort-to-Value share equal top priority. Regulatory weight is low — most K-12 cybersecurity compliance is voluntary.
CMMC certification is binary — pass or fail. Regulatory Criticality dominates the profile. Effort-to-Value drops to its floor because required controls must be implemented regardless of cost.
Volunteer IT, near-zero budgets, no regulatory mandates. Effort-to-Value leads the profile, ensuring recommended actions are achievable with available resources.
Weight Profile Integrity Commitment
The full weight table is confidential — but it is cryptographically committed. We publish a SHA-256 fingerprint of every versioned weight profile. Customers and auditors who receive the table under confidentiality can hash it and confirm it matches this public commitment, proving the weights were fixed in advance and never retro-tuned to justify a result.
c2d64d830ef3905c17440793c1b3c90d1c951e2ea7e71d886b6e3fdbb2180d0d
406440ae70f89b28c5001c0e372ee924894f45e3fc11def778a55474cad7d2a8
v2.0 commits more than the weights: it fixes the model itself — which factors count as benefits, which one is a cost, how they combine, and where the effort threshold falls. The weights are unchanged from v1.0, which remains published and verifiable for assessments scored before that date.
Fully Deterministic
Given identical inputs, the algorithm always produces an identical priority sequence — essential for audit defensibility. An assessor reviewing results at any point in time can reproduce the exact sequence from documented inputs.
- Higher Dependency Score (foundational controls first)
- Higher Effort-to-Value (quicker wins preferred)
- Higher Threat Relevance (active threats break ties)
- Alphabetical by control identifier (final fallback)
Every Score Is Explainable
Every Priority Score decomposes into its seven constituent factor scores and applied weights. This decomposition is preserved and surfaced as plain-language rationale in your assessment report. The applied weights for your vertical are disclosed in customer reports under your engagement's confidentiality terms:
Cited Data Sources
Every T score traces back to specific KEV entries, DBIR frequency data, and advisory references. Every D score traces back to a documented dependency in the control DAG. Every R score traces back to a specific audit checklist item or enforcement action.
This audit trail is maintained as structured metadata and is available for inspection at any time — supporting grant applications, audit responses, and organizational leadership briefings.
Kept Current
Threat intelligence (Factor T) refreshes on a per-feed cadence: CISA #StopRansomware weekly, CISA KEV and MITRE ATT&CK prevalence quarterly, MS-ISAC advisories quarterly, and the Verizon DBIR annually. Factor weights and blast radius scores are reviewed annually. Coverage Breadth (C) and Asset Exposure (A) update automatically.
The ATT&CK technique intermediary layer keeps maintenance bounded to a technique prevalence catalog rather than thousands of individual control scores. Every refresh is recorded as a versioned snapshot so changes in priority are traceable over time.
Looking for Tool Scoring?
UCPA scores which controls to implement first. The Tool Trust Index (TTI) scores which tools to actually procure. The two algorithms share no scoring state and operate on different objects, but together they answer "what should I do, and what should I buy to do it?"
Primary Data Sources
The UCPA was developed by Viosoph, LLC and is implemented as a scoring engine within the FrameworkMapper platform. © 2026 Viosoph, LLC. All rights reserved.
See the Algorithm in Action
Run an assessment and receive a prioritized implementation roadmap with full factor-level explanations for every control recommendation.