CertIQ
How CertIQ works

Three layers. One score. One quote.

CertIQ combines automated domain scanning with an Essential Eight self-assessment to produce a hybrid risk score. When that score crosses the ready threshold, a cyber insurance quote is generated automatically.

Layer 1
Score
Layer 2
Ready
Layer 3
Insure
The scoring model

Every signal, weighted and to scale.

Not every check counts the same. Bar length below is the points a signal is worth — so you can see at a glance what moves your score most.

Layer 1 — External scan
60% of score

Run automatically on your domain. Nothing to install, nothing to fill in.

Exposed ports & services
20
Leaked credentials
20
Domain reputation
20
Email spoofing (SPF/DKIM/DMARC)
20
TLS certificate health
10
Forgotten subdomains
10
100 points in total, scaled to 60% of your combined score
Layer 2 — Essential Eight
40% of score

Seven plain-English questions, about 90 seconds.

MFA
10
Restrict admin privileges
8
Patch applications & OS
8
Regular backups
8
Application control
6
Restrict Office macros
5
Incident response
5
50 points in total, scaled to 40% of your combined score
Combined score
0–100
Graded A to F
External scan 60%
Self-assessment 40%

The two layers are blended, not added — the external scan is independently verified, so it carries more of the result.

The gate

CertIQ Ready takes three things, not one.

A score on its own is not enough. All three have to be true at the same time — and the 65 applies to the external scan, not your combined score.

01
External scan reaches 65
065100
02
All 7 questions answered
Self-assessment complete
03
No critical findings open
0 Critical required
Anything critical must be resolved first
→ Pre-filled cyber insurance quote
From a panel of insurers. A better score means better terms.
Layer 1 — Score

The external scan

CertIQ scans any domain from the outside — no access to the client's systems required. Six independent data sources run in parallel and return results in under 10 seconds.

CertIQ:scan
Detects open ports and exposed services including RDP, SMB, Telnet, and known vulnerable software versions.
CertIQ:breach
Checks how many staff email addresses appear in public breach databases — a direct indicator of credential exposure.
CertIQ:reputation
Assesses domain reputation across dozens of security feeds. Flags malware associations, phishing history, and blacklist status.
CertIQ:mail
Checks email authentication records. Missing or weak DMARC and SPF policies mean the domain can be spoofed.
CertIQ:layer
Inspects certificate validity, expiry, and protocol version. TLS 1.0 and 1.1 are flagged as end-of-life risk.
Score weighting

Six signals share 100 points, weighted by how much each one tells us. See every weight to scale at the top of this page.

The external scan contributes 60% of the combined score. The remaining 40% comes from the Essential Eight self-assessment.
Layer 2 — Ready

The Essential Eight self-assessment

While the domain scan runs, the user answers seven plain-English questions mapped to the ASD Essential Eight framework. No IT knowledge required. Takes about 90 seconds.

10 pts
Multi-factor authentication enforced for all staff
8 pts
Admin accounts separate from daily-use accounts
8 pts
Security updates applied within Essential Eight timeframes (48 hours to one month)
8 pts
Backups taken regularly, tested, and stored offline
6 pts
Application control enforced on workstations
5 pts
Office macros disabled or restricted to signed sources
5 pts
Documented and tested incident response plan
How answers are scored
Yes
Full points awarded
Partial
Half points awarded
No
Zero points — gap flagged in report
Skipped
Zero — no penalty recorded
Self-assessment contributes 40% of the combined score. It rewards honest self-reporting without allowing gaming to dominate the result.
Layer 3 — Insure

From ready score to bound policy

When the external score reaches 65 or above, the self-assessment is complete, and no critical findings remain outstanding, the client is CertIQ Ready. A pre-filled cyber insurance quote can be sourced from a panel of insurers.

65+
CertIQ Ready threshold
The external score required to trigger an automatic cyber insurance quote, alongside a complete self-assessment and no outstanding critical findings.
Auto
Quote generated
A pre-filled quote is sent to the broker automatically — no ACORD form, no email chain, no manual submission required.
Better
Terms for ready clients
CertIQ Ready clients typically access broader cover with fewer exclusions. Better posture means better terms.
Get started

Ready to run your first scan?

3 free scans per month. No account required.

Run a scan