Skip to main content
Change Risk Intel
Free tool

Change Risk Score

Score a proposed IT change against the current threat landscape — MSRC patch load, CISA KEV activity, end-of-life exposure, and regional change-freeze windows.

Data last refreshed July 21, 2026.

The Change Risk Score is a lightweight, second-opinion sanity check for change managers and CAB chairs. Paste a short description of the change, pick the planned implementation date, and choose the region it will run in. The tool scores the request client-side against a bundled snapshot of the signals a mature CAB already tracks: Microsoft's current Patch Tuesday load (critical vs. important CVEs), the last two weeks of additions to the CISA Known Exploited Vulnerabilities catalog, the products whose vendor support is about to lapse, and the calendar windows in which most enterprises voluntarily freeze non-emergency changes. Nothing leaves the browser — the result page is shareable because the inputs are packed into the URL hash. Use it before a meeting to prioritize which changes deserve deep review, or after a change to sanity-check whether a Sev-1 was foreseeable. It is a heuristic, not a compliance control; treat the score as an input to your CAB conversation, not a substitute for one. Data refreshes nightly.

How the score is computed

Base 20 points. +5 for each critical MSRC CVE in the current release, capped at +25. +3 per KEV addition in the last 14 days, capped at +18. +10 if the change touches a product whose vendor support ends within 90 days of the planned date. +15 if the planned date falls inside a regional freeze window. Capped at 100.

About this tool

A request can look routine in a ticket while the surrounding conditions make it harder to execute safely. This score brings together signals that often live in separate checks: Microsoft release cadence, CISA Known Exploited Vulnerabilities entries, product end-of-life context, and the regional freeze windows selected for the change. It is useful when a change manager needs to surface why a particular window deserves more review than an otherwise similar request in the schedule.

Read the result as a structured prompt, not an authorization. A higher result means the request intersects more conditions that can increase coordination, exposure, or rollback pressure. Review the contributing flags with the service owner and confirm which affected assets actually exist in scope. Then record the business reason, test evidence, implementation plan, rollback trigger, and approver decision in the system that governs the change. A low result does not make a change standard or pre-approved.

How to read the output

  • Inspect each contributing signal before treating the total as meaningful.
  • Compare affected products with the current asset inventory and service dependencies.
  • Escalate conflicting signals to the change owner or CAB chair.
  • Document the decision and rollback conditions in the authoritative change record.

What this does not tell you

  • The score cannot confirm whether a listed vulnerability affects the organization's actual versions, configurations, or compensating controls.
  • End-of-life and freeze-window inputs simplify local policy and may not capture contractual, regulatory, or business-event exceptions.
  • A triage score does not replace CAB judgment, owner accountability, testing evidence, or an approved emergency-change process.

Data sources

Free to use, no account required, and nothing you enter is transmitted to this site — the tool runs entirely in your browser.