Skip to content
Methodology v2026.1

Benchmark Intelligence
Methodology

Composite scoring and benchmarking methodology for PCI DSS compliance programmes. Aggregates voluntary submissions across 7 industry verticals, applying k-anonymity protections and minimum sample thresholds before publication.

Status: activeMin Threshold: 30 per cohortPrivacy: k-anonymity k≥5

Composite Maturity Score Weighting

Maturity score (0–100) is a weighted composite of: control coverage (40%), evidence quality (25%), automation adoption (20%), and remediation velocity (15%). Raw scores are normalised to a 0–100 scale.

Control Coverage40%
Evidence Quality25%
Automation Adoption20%
Remediation Velocity15%

Publication Rules

Statistics are only published as factual when sample size ≥ 30 per industry cohort and verification status is "verified". Provisional datasets (sample < 30 or unverified) are labeled explicitly. Illustrative examples are never mixed into factual summaries.

Factual
Sourced directly from PCI SSC primary documents, ISO, or AICPA. verificationStatus=verified. Not subject to sample size thresholds.
Provisional
Derived from GRCTrack benchmark dataset. Sample ≥30 per cohort. Values are directionally indicative. Labeled explicitly on all pages.
Illustrative
Example data only. Never published as factual or provisional. Always labeled with a warning. Not cited externally.

Normalization

All raw values normalised using min-max scaling within each industry cohort. Cross-industry comparison uses global min-max.

Rounding Rules

Maturity scores rounded to nearest integer. Cost values rounded to nearest $1,000. Hours rounded to nearest 10. Rates rounded to nearest whole percent. Remediation days rounded to 1 decimal place.

Sample Handling

Outliers >3 standard deviations from cohort mean are excluded. Organisations with incomplete submissions (>20% missing fields) are excluded from aggregation.

Outlier Policy

Winsorization at 3σ — values beyond 3 standard deviations from cohort mean are replaced with the 3σ boundary value before aggregation.

API Access: Methodology records at /api/intelligence/methodologies. Full changelog at /intelligence/changelog →