# How CHQ Ratings Work

**Methodology for the CHQ Structural Condition Report**

*Published so readers can attack the criteria rather than take the ratings on faith. This page governs every rating CHQ publishes. Where a rating and this methodology conflict, the rating is wrong.*

## What CHQ rates

CHQ does not rate vendors, products, or incidents. It rates structural conditions: durable properties of how systems are built and operated that make classes of attack possible. An incident is evidence. The condition is what persists after the incident is patched.

The board carries six to ten conditions at a time. A condition is added only when defined evidence thresholds are met, and every addition, change, and removal is published as a rating action.

## The rating scale

Ratings are three defined states, not letter grades. Each maps to a mechanical evidence threshold, so any reader can check whether a rating is justified.

EMERGING. Condition observed, but evidence remains limited, contested, or below the condition's defined confirmation threshold.

STRENGTHENING. Recurring across two or more independent instances; evidence accumulating toward the condition's defined confirmation threshold.

CONFIRMED. The condition has crossed its declared confirmation threshold through sustained independent evidence or a qualifying real-world event.

For exploitation conditions, the confirmation threshold is confirmed production exploitation; each non-exploitation condition declares its own threshold in the registry. "Under review" is an analytical status, not a rating; the last valid rating remains displayed until a valid criterion produces a subsequent action.

CHQ does not use lettered scales. Letters borrow the authority of statistical calibration that these conditions do not yet have. When CHQ's own track record is long enough to support base rates, that record will be published rather than implied.

## Independence of instances

Two incidents count as independent evidence only if they differ in domain, observation source, and failure mode. The same flaw class in five products from one root cause is one observation, not five. This rule exists because the fastest way to inflate a rating is to count the same event repeatedly.

## What every rating must carry

No condition is rated without five items, defined in advance and on record:

1. Current evidence. The instances that justify the state.
2. An up-trigger. The mechanical condition that raises the rating.
3. A down-criterion. The mechanical condition that lowers it. No rating is issued that cannot be lowered.
4. A watch condition. The evidence state that places it on Watch.
5. A materialization event. A publicly checkable event class, declared in advance, that counts as the condition happening. The rating is thereafter accountable to the frequency of that event, not to editorial judgment.

## Outlook is not a forecast

Outlook describes the direction of evidence accumulation in the trailing window: Accumulating, Stable, Receding. It is not a prediction.

## The maintenance rules

Every rated condition is reviewed every issue. Conditions that did not move are published as Affirmed, because an affirmation only carries information if review was mandatory. De-escalation is mandatory when a down-criterion is met. A condition with no supporting evidence across a defined number of cycles is withdrawn, publicly, with the reason stated. Every rating action is recorded in an append-only transition log that will, over time, constitute the board's public track record: how long conditions take to confirm, how often Watch resolves into reclassification, and how often CHQ was wrong.

## Being wrong in public

CHQ maintains internal, dated, falsifiable predictions tied to rated conditions. They resolve on their expiry dates as confirmed or disconfirmed, and the resolutions are published at equal fidelity, including the misses. The first scored prediction in this program resolved as a miss, and was published as one. A rating or a call that cannot be wrong is marketing, and CHQ does not publish marketing as analysis.

## Independence

The ratings are not sponsored and cannot be. Sponsored work is disclosed, separate, and governed by the CHQ Independence and Sponsorship Policy, published alongside this page. No commercial relationship influences what is rated or how.

*This methodology is versioned. Material changes to it are themselves published as actions, with reasons. Current version: v1.2, applied from 18 August 2026.*
