The method, printed in full
How an edition of the Granworth Index is built: what is observed, how the 20-topic score is counted, what an edition is not, and how to check any of it. The method is held fixed across editions so scores compare; changes to it are versioned and dated on this page. Current version: 2026-09-02.
What an edition is not
An edition is not a security assessment, a vulnerability scan, or a gap report — it says nothing about a company's actual security. It records how the trust story reads from the public web. Benchmarking means loading public pages in a logged-out browser: nothing is scanned, nothing is probed, and no system is interacted with beyond loading pages any stranger can load.
Only sales-relevant public trust signals are observed. Per artifact, one observable question:
| Artifact | Observable question |
|---|---|
| Trust/security page | Does a public trust or security page exist, and is it linked from the site footer or navigation? |
| SOC 2 / ISO 27001 visibility | Is the attestation stated publicly? Is the report reachable — self-serve NDA gate, “email us,” or no stated path? |
| Security answers availability | Of the 20 standard questionnaire topics below, how many are publicly answerable without emailing anyone? Reported as a count: n/20. |
| Subprocessor list & DPA | Is there a public subprocessor page? Is the DPA downloadable, or on request only? |
| Enterprise signals on pricing | Does the pricing page name SSO/SAML, audit logs, an SLA — and a BAA where the buyer is in healthcare — on an enterprise tier? |
Cells record one of three states — Published, Partial, or Not found (as of the stated date) — each with a URL and a fetch date. “Not found” means not reachable by a public visitor on that date; it never means the thing doesn't exist internally. Every cell is re-verified on the day an edition ships; a cell that can't be re-verified is corrected or its row is cut.
Each edition reports, per company, how many of these 20 topics a reviewer can answer from the public web alone — the n/20 figure the side-by-side table and the meters carry. The list is the Index's own rubric: the questions that recur on enterprise security questionnaires, held fixed across editions and disclosed in full so any score can be re-checked. The mapping table below anchors each topic to the public questionnaire standards reviewers use.
A topic counts as publicly answerable when a logged-out visitor can reach the answer itself — on the company's site, trust center, docs, pricing, or status pages — without emailing anyone, submitting a form, or creating an account.
Sections that defer to “happy to provide details upon request” count as not publicly answerable: the reviewer still has to ask, and the asking is the thing being measured. One exception is deliberate — a report behind a self-serve NDA gate counts for the report-access topic, because the path is public even where the document is not.
Scores are reported as n/20 — arithmetic on the enumerated topics, nothing else. Every edition carries a topic ledger naming which topics counted for each scored company, so any score can be re-checked against the public web as of the edition's date.
The 20 topics are the Index's rubric, not an industry standard — so here is the anchor an auditor would ask for. CAIQ-Lite is the Cloud Security Alliance's condensed Consensus Assessments Initiative Questionnaire (announced 2019-03-01, drawn from CAIQ v3.0.1 and CCM 3.0.1); the question IDs below use that v3.0.1 numbering, which is what publicly posted CAIQ-Lite responses carry, and were verified against a vendor-published CAIQ-Lite on 2026-09-02. SIG question text and numbering are licensed by Shared Assessments, so the SIG column names the closest risk domain in the SIG library rather than a question ID. Where a topic has no clean anchor, the table says so instead of forcing one.
| Index topic | CAIQ-Lite anchor (v3.0.1 IDs) | Closest SIG risk domain | Note |
|---|---|---|---|
| Encryption at rest | EKM-03.1 · DSI-03.1 | Asset and Information Management | |
| Encryption in transit | DSI-03.2 | Network Security | Nearest anchor — the CAIQ-Lite question asks about open encryption methodologies for infrastructure communication, not TLS in transit by name. |
| SSO / SAML | none in CAIQ-Lite · full CAIQ IAM-12.1 | Access Control | CAIQ-Lite's IAM questions cover the vendor's own staff access; identity federation (SAML) for customers appears only in the full CAIQ. |
| Access control | IAM-02.1 · IAM-08.1 · IAM-10.1 | Access Control | |
| Subprocessor list | STA-05.4 · STA-09.1 | Supply Chain Risk Management | Nearest anchor — CAIQ asks whether third parties are governed; a published list is a transparency practice no questionnaire mandates. |
| Data processing agreement | no clean mapping | Privacy | A contract artifact, not a questionnaire control; reviewers request it alongside the questionnaire. |
| Data residency | no clean mapping in CAIQ-Lite | Cloud Services | Reviewers ask it constantly; the Lite set carries no direct storage-geography question. |
| Pentest cadence | AAC-02.2 · AAC-02.3 | Threat Management | |
| Incident response | SEF-02.1 · SEF-02.4 · SEF-03.1 | Cybersecurity Incident Management | |
| Backups | BCR-11.3 · BCR-11.7 | Operational Resilience | |
| Uptime SLA | no clean mapping | — | A commercial term — it lives in the order form, not in a control questionnaire. Buyers check for it anyway, so the Index counts it. |
| Vulnerability management | TVM-01.1 · TVM-02.5 | Threat Management | |
| Employee security training | HRS-09.5 · HRS-02.1 | Human Resources Security | |
| BC/DR | BCR-02.1 | Operational Resilience | |
| Vendor risk management | STA-09.1 | Supply Chain Risk Management | |
| Data retention & deletion | BCR-11.1 · DSI-07.1 · DSI-07.2 | Privacy | |
| Change management | CCC-04.1 · GRM-01.1 | IT Operations Management | The Lite set keeps a narrow slice of the CAIQ change-control domain; the topic is broader. |
| Logging & monitoring | IVS-01.1 · IVS-01.5 · IAM-01.2 | IT Operations Management | |
| Physical / hosting security | DCS-02.1 · DCS-09.1 | Cloud Services | For cloud-hosted vendors these controls are typically inherited from the hosting provider; the public answer names the provider and the inheritance. |
| Compliance report access path | AAC-02.1 | Compliance and Operational Risk | AAC-02.1 asks exactly this: whether buyers can view the SOC 2 / ISO 27001 report. |
Sources: cloudsecurityalliance.org/blog/2019/03/01/introducing-caiq-lite (CAIQ-Lite scope and lineage) · octopus.com/docs/security/caiq (a vendor-published CAIQ-Lite response; question IDs verified against it 2026-09-02) · upguard.com/blog/sig-questionnaire (SIG risk-domain names, fetched 2026-09-02).
CSA's current CAIQ v4 reorganizes these domains — encryption moves to CEK, data lifecycle to DSP — without changing what the topics ask. The Index cites v3.0.1 IDs because publicly posted CAIQ-Lite responses use them.
Every edition carries a 16-character build id, in a meta tag and printed in its footer. It is a content fingerprint: the first 16 hex characters of a SHA-256 digest computed over the edition's template and source text. The same sources always recompute to the same id; a single changed byte changes it.
What it is for: provenance of copies. An edition is a single self-contained file — zero JavaScript, no external requests, fonts embedded — so it gets forwarded, and a forwarded copy can be checked: compare its footer build id and its bytes against the edition published here. Matching ids on matching bytes mean an unaltered copy. The id is recomputable, which means it can be caught wrong — that is the point.
The self-contained posture is also why every edition's “No scripts, no tracking” line is checkable in the file's own source: an edition renders identically offline, and a correction changes the build id in the open.
If anything in a published edition is out of date or wrong, tell the author: linkedin.com/in/jgarcia2. Expect a response within 24 hours. The edition is corrected, rebuilt — which changes its build id in the open — republished here, and re-sent to whoever received it. This holds whether or not anyone ever books anything, on every edition, with no expiry.