| Evaluation Criteria | Weighting |
|---|---|
Product or Service | High |
Overall Viability | High |
Sales Execution/Pricing | Medium |
Market Responsiveness/Record | High |
Marketing Execution | Low |
Customer Experience | High |
Operations | Medium |
| Evaluation Criteria | Weighting |
|---|---|
Market Understanding | High |
Marketing Strategy | Low |
Sales Strategy | Medium |
Offering (Product) Strategy | High |
Business Model | NotRated |
Vertical/Industry Strategy | Low |
Innovation | High |
Geographic Strategy | Medium |
| AEV | adversarial exposure validation |
| ASCA | automated security control assessment |
| ASPM | application security posture management |
| CAASM | cyber asset attack surface management |
| CDR | cloud detection and response |
| CIS | Center for Internet Security |
| CMDB | configuration management database |
| CMMC | Cybersecurity Maturity Model Certification |
| CNAPP | cloud-native application protection platform |
| CPS | cyber-physical systems |
| CTEM | continuous threat exposure management |
| CVSS | Common Vulnerability Scoring System |
| DISA STIG | Defense Information Systems Agency Security Technical Implementation Guide |
| DoD | Department of Defense |
| DoDIN APL | Department of Defense Information Network Approved Products List |
| DRPS | digital risk protection services |
| EAP | exposure assessment platform |
| EASM | external attack surface management |
| EDR | endpoint detection and response |
| EPSS | Exploit Prediction Scoring System |
| FedRAMP | Federal Risk and Authorization Management Program |
| FIPS | Federal Information Processing Standards |
| GDPR | General Data Protection Regulation |
| GRC | governance, risk, and compliance |
| HIPAA | Health Insurance Portability and Accountability Act |
| IoC | indicator of compromise |
| IoMT | Internet of Medical Things |
| IoT | Internet of Things |
| IPS | intrusion prevention system |
| ISO | International Organization for Standardization |
| ITSM | IT service management |
| LLM | large language model |
| M&A | mergers and acquisitions |
| MSSP | managed security service provider |
| NIST SP | National Institute of Standards and Technology Special Publication |
| OT | operational technology |
| PCI DSS | Payment Card Industry Data Security Standard |
| PTaaS | penetration testing as a service |
| RBAC | role-based access control |
| SIEM | security information and event management |
| SLA | service-level agreement |
| SOAR | security orchestration, automation and response |
| TDIR | threat detection, investigation, and response |
| TIP | threat intelligence platform |
| VA | vulnerability assessment |