Skip to main content
The grade counts requirement violations only. A letter has to mean something a reader can check, and “violates a stated MUST” is observable and citable; a weighted blend of requirements and recommendations is a taste judgement dressed as a measurement. Recommendations a server does not follow are still reported — as advisories — and do not decide the letter.

The scale

The worst unresolved MUST violation decides the grade:

Ungraded findings

Some findings are deliberately ungraded, because no document is violated to earn them: an authorization or token endpoint that answers nothing, a listed authorization server beyond the first that does not resolve, and an Entra credential that has expired. There is no MUST anywhere that a server be up. They are reported at the severity the outage deserves — an endpoint that answers nothing is critical — but severity describes the outage and the grade describes conformance, and those are different claims.

Heuristics say so

A small number of checks are heuristics — scope minimization matches scope names against a conventional list, for example. Each one says so in the message it emits, so a heuristic is never mistaken for a cited requirement.