INTOCERT / METHODOLOGY

Know what the grade means.

IntoCert Essentials is an independently defined, evidence-based score for the observed endpoint.

35%

Certificate

Trust, hostname match and validity. Invalid trust or expiration produces F.

25%

Protocol

Measured TLS 1.3 and 1.2 handshakes. TLS 1.3 earns the strongest category.

20%

Public key

Key type and strength from the served certificate.

20%

Cipher

Strength of the negotiated cipher in our TLS connection.

How to read a result

A is 90–100, B is 75–89, C is 60–74, D is 40–59, and F is below 40 or a failed certificate trust/validity check. Fewer than 30 days until expiration caps the grade at B. The score is withheld when the required evidence cannot be measured.

We test up to two public IPv4 addresses returned for the hostname and show the lowest endpoint grade as the summary. The report names each endpoint and time. HSTS and the hostname CAA record are supporting signals, not inputs to this grade. IPv6, every address, the full cipher matrix, chain diagnostics and OCSP stapling are not part of Essentials yet.

Recent scans may be reused for up to ten minutes; the report always shows the actual measurement time. These are IntoCert's own criteria.