How the numbers work
Every score, percentage, and comparison in PolicyAlign, explained. No black boxes.
How is my overall coverage score calculated?
Your documents are analyzed against all 106 subcategories of the NIST Cybersecurity Framework 2.0. Each subcategory ends up in one of three states:
- Covered — at least one document fully addresses it
- Partial — documents touch it, but incompletely, with weak language, or with a flagged concern
- Missing — no document addresses it
score = (covered + 0.5 × partial) ÷ 106 × 100
A partial counts as half a point: written-but-weak policy is real progress, but it shouldn't score the same as a complete one. Scores are rounded to one decimal place.
How are the section (function) scores calculated?
The same formula, applied per CSF function using only that function's subcategories: Govern has 31, Identify 21, Protect 22, Detect 11, Respond 13, and Recover 8. So “Protect: 77.3%” means your Protect-function controls earned 77.3% of the points available in that function alone. Category scores (like “Risk Assessment” in the Weakest Areas widget) work identically over each category's controls.
Where do the sector comparison numbers come from?
The sector lines (Non-profits, Health & human services, Education, Small business baseline) are estimates synthesized from published, freely available sector security research — they are not yet measurements of PolicyAlign customers. We state this in the product footnote wherever they appear. The estimates are informed by:
- UK Cyber Security Breaches Survey (DSIT, annual)Free government survey with dedicated charity and education-institution chapters — policy/documentation adoption rates by org size
- NTEN publications (nonprofit technology research)Nonprofit-specific technology and security practice surveys, including the annual Tech Accelerate benchmarking report
- Verizon Data Breach Investigations ReportFree annual report with small-business and industry cuts (healthcare, education)
- Microsoft Digital Defense ReportFree annual report; nonprofit/NGO targeting trends (Microsoft's permalink — always points to the current edition)
- HHS 405(d) Health Industry Cybersecurity PracticesFree HHS program — expected practices for small healthcare organizations
As the PolicyAlign customer base grows, these estimates will be replaced by live cohort medians— see the privacy question below for exactly what that does and doesn't use.
Will my organization's data be used in those benchmarks?
When live cohort benchmarks ship, they will use only aggregate scores — the same per-function percentages you see on your own dashboard — pooled across at least a minimum number of organizations per sector, so no individual organization is identifiable. They will never include document contents, document names, findings text, tool names, or anything traceable to your organization. Your uploaded documents stay private to your organization, full stop.
How is HIPAA Security Rule readiness derived?
Your documents are analyzed once, against the CSF. The HIPAA view re-projects those findings through a crosswalk informed by NIST SP 800-66 Rev. 2 (the official HIPAA-to-CSF implementation guide). Each safeguard maps to the CSF subcategories that evidence it:
- Addressed — at least one mapped control is fully covered and none are missing
- Partial — a mix: some coverage exists but gaps remain
- Gap — every mapped control is missing from your documents
Citations like §164.308(a)(2) are the exact paragraphs of the Security Rule (45 CFR Part 164) — each safeguard links to its official text on eCFR. This view reflects what is written in your policies; it is not a legal compliance determination or a certification of practice.
What does "Flagged for review" mean?
The analyzer doesn't just check whether a topic is mentioned — it checks substance. A policy gets flagged when it documents an outdated practice (for example, scheduled password rotation, which current NIST SP 800-63B guidance recommends against) or when a document admits a control isn't actually implemented. Flagged items are capped at partial credit and carry an amber note explaining the concern.
Why did my score change between assessments when my documents didn't?
Two honest reasons. First, the control catalog grows: assessments run before the full CSF 2.0 catalog shipped were scored over fewer controls and read higher — newer scores over all 106 subcategories are the comparable baseline going forward. Second, AI analysis has a small amount of run-to-run variance (typically a point or two); the trend across assessments matters more than any single decimal.