What does CertIQ actually do?
CertIQ scans a domain from the outside and combines the result with a short Essential Eight self-assessment to give you one cyber health score. The output is a plain-English report you can send to a client — or to an underwriter.
What data sources power the external scan?
Six checks run at once, all from the outside: open doors to your systems (CertIQ:scan), leaked passwords (CertIQ:breach), whether your domain is flagged (CertIQ:reputation), whether someone can fake your email (CertIQ:mail), your website's padlock (CertIQ:layer) and forgotten systems (CertIQ:reach). We never need a password or access to your systems.
What is the Essential Eight self-assessment?
The Essential Eight is the Australian Signals Directorate's baseline control framework. CertIQ maps seven short yes-no questions onto those controls, so a non-technical business owner can answer them in about 90 seconds.
How is the final score calculated?
60% of the score comes from the external scan and 40% from your self-assessment answers. You get an A–F grade, a 0–100 number, and the specific findings that moved the score in either direction.
Can I re-run a scan later?
Yes. Scans are tied to a domain, so re-running one on the same domain later shows what has changed. On the freemium tier you get three scans per month per IP; broker plans are unlimited.