Skip to main content
Change Risk Intel
Free tool

Change Risk Score

Score a proposed IT change against the current threat landscape — MSRC patch load, CISA KEV activity, end-of-life exposure, and regional change-freeze windows.

Data last refreshed July 21, 2026.

The Change Risk Score is a lightweight, second-opinion sanity check for change managers and CAB chairs. Paste a short description of the change, pick the planned implementation date, and choose the region it will run in. The tool scores the request client-side against a bundled snapshot of the signals a mature CAB already tracks: Microsoft's current Patch Tuesday load (critical vs. important CVEs), the last two weeks of additions to the CISA Known Exploited Vulnerabilities catalog, the products whose vendor support is about to lapse, and the calendar windows in which most enterprises voluntarily freeze non-emergency changes. Nothing leaves the browser — the result page is shareable because the inputs are packed into the URL hash. Use it before a meeting to prioritize which changes deserve deep review, or after a change to sanity-check whether a Sev-1 was foreseeable. It is a heuristic, not a compliance control; treat the score as an input to your CAB conversation, not a substitute for one. Data refreshes nightly.

How the score is computed

Base 20 points. +5 for each critical MSRC CVE in the current release, capped at +25. +3 per KEV addition in the last 14 days, capped at +18. +10 if the change touches a product whose vendor support ends within 90 days of the planned date. +15 if the planned date falls inside a regional freeze window. Capped at 100.