Security Stack Logo

Methodology

How matching works

TL;DRProducts are ranked by how many of your requirements their documented data covers.

Every evaluation has a Matches stage: a ranking of catalog products against the requirements you set. This page explains exactly what that ranking is and how to read it.

What gets scored§

Your requirement set is the scoreboard. A requirement is a capability, a compliance certification, or an integration, and each carries a priority of High, Medium, or Low. When what you add matches a name the catalog already tracks, the row takes the catalog's spelling and scores automatically against every product's documented data.

A requirement the catalog does not recognize becomes a custom row. Matching never guesses at custom rows: one counts as covered only when you mark it yourself in the scorecard, and until then it is unknown. Unknown never counts against a product; only an explicit miss does.

How products are ranked§

Product matches could be any published product in the catalog. Domain and Category labels grant no advantage: a product from an adjacent Domain that covers your requirements will appear. Products covering none of your requirements are left off the list.

The order they appear in is calculated from their coverage for your Requirements, which are weighted by the priority you set for each. High-priority requirements count the most, Medium have standard weight, and Low is informational (it shows in the coverage fraction but doesn't influence a product's position). Each explicit High-priority requirement a product misses flags the result and ranks it lower, to ensure that missing a must-have is easy to identify.

Reading a matched product row§

Each product in your results shows a coverage fraction (i.e., 3/4 high priority requirements). If you click on the product row, you see the full breakdown: which of your requirements the product covers and which it misses, organized per type (features, integrations, etc.).

The "Add to shortlist" button creates a shortlist associated to that Evaluation if it doesn't yet exist, or otherwise adds the product to the existing one.

Packs and matching§

When you load an Evaluation Pack, you get researcher-curated capability requirements tailored to the Domain you chose. The Matching tool treats requirements seeded from an Evaluation Pack exactly like those you added yourself. Packs simply add to your requirements list, they don't influence how products score against them.

Keeping it honest§

Vendors don't influence matching or ranking. There is no paid placement and no sponsored rank. The way a product ranks higher is to document a capability or attribute it actually has, in materials our researchers can review.

Last updated on