CVSS v3.1 vs v4.0: what actually changed
Version 4.0 has been published since November 2023 and almost every Canadian penetration test report still quotes 3.1. That is a defensible choice rather than laziness, but you should know what the two scales disagree about before you put them in the same spreadsheet.
CVSS v4.0 removed the Scope metric, split impact into two separate sets covering the vulnerable system and any subsequent system, added an Attack Requirements metric, gave User Interaction a third value, and replaced the published arithmetic with a lookup table. The severity bands did not change. A v3.1 score and a v4.0 score for the same flaw are different numbers on different scales, and putting them in one column of a risk register produces a ranking that means nothing.
Nov 2023 CVSS v4.0 published by FIRST
8 to 11 Base metrics, v3.1 against v4.0
Unchanged Severity bands, 0.1 to 10.0
Which version should a report use?
Ask for v3.1 unless you have a specific reason to want v4.0, and say so in the scope document rather than discovering the answer at the readout. Three reasons it is still the right default in 2026:
- Your other inputs are v3.1. The National Vulnerability Database, most scanners and most vendor advisories still publish 3.1 vectors, sometimes alongside 4.0 and sometimes not. A report in a version nothing else speaks makes correlation manual.
- Your contracts probably name it. Severity language in customer security schedules and in remediation policies written before 2024 says "CVSS 3.1" or just "CVSS", and a supplier who switches unilaterally invites an argument about whether a 7.4 is the 7.4 that was agreed.
- Your auditor does not care which one, only that you use one consistently and meet the timelines attached to it. That is covered under SOC 2 penetration testing and under ISO 27001 penetration testing.
The counter-case, which is real
If you are a product vendor issuing your own advisories, v4.0 is the better scale and you should move. It was designed to fix the complaint that 3.1 scores cluster in the high band and say little about what an attacker achieves. Supplemental metrics such as Safety and Automatable exist because operational technology and medical device vendors could not express their risk in 3.1. If you make a device that can hurt somebody, 4.0 has vocabulary for that and 3.1 does not.
What changed in the base metrics
| v3.1 | v4.0 | Why |
|---|---|---|
| Attack Vector (N/A/L/P) | Attack Vector, unchanged | The one metric nobody argued about |
| Attack Complexity (L/H) | Attack Complexity, narrowed | Now means evasion of a security mechanism, not any precondition |
| No equivalent | Attack Requirements (N/P) | The deployment or execution conditions that used to be crammed into Complexity |
| Privileges Required (N/L/H) | Privileges Required, unchanged | |
| User Interaction (N/R) | User Interaction (N/Passive/Active) | Clicking a link and merely rendering a page are not the same risk |
| Scope (U/C) | Removed | The most misapplied metric in 3.1, replaced by explicit second impact set |
| C, I, A impact | VC, VI, VA on the vulnerable system | Impact where the flaw lives |
| Folded into Scope | SC, SI, SA on subsequent systems | Impact past the boundary, stated rather than implied by a multiplier |
Scope is the change worth dwelling on, and the metric our CVSS calculator warns about. In 3.1, a scope change applies a 1.08 multiplier and swaps in higher privileges-required weights, so setting it casually moves a score by more than a point. In 4.0 you instead score the subsequent system's confidentiality, integrity and availability directly. It is more work per finding and far harder to get wrong.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
The score is no longer a formula
CVSS v3.1 base scoring is published arithmetic: an impact sub-score, an exploitability sub-score, a minimum, a specified rounding rule. Anyone can implement it in twenty lines, which is why our calculator shows its own sub-scores and why you can check it.
CVSS v4.0 does not work that way. Metric combinations are grouped into equivalence classes, and the score comes from a lookup table of values derived from expert scoring, with interpolation between neighbouring entries. There is no closed-form equation to reimplement. That was a deliberate trade: the 3.1 formula produced orderings its own authors disagreed with, and a table lets the scale match human judgement. The cost is that you cannot derive a 4.0 score with a pen, and you cannot audit the number the way you can audit a 3.1 vector.
CVSS-B, CVSS-BT, CVSS-BTE
Version 4.0 introduced names for how much of the standard you used, and they are worth insisting on in a report.
- CVSS-B
- Base metrics only. This is what almost every report and every advisory publishes, and it is what people mean when they say "the CVSS score".
- CVSS-BT
- Base plus Threat. The Threat group replaces 3.1's Temporal group and has been cut to one metric, Exploit Maturity. Remediation Level and Report Confidence are gone, because nobody maintained them.
- CVSS-BE and CVSS-BTE
- With Environmental metrics, meaning your requirements for confidentiality, integrity and availability plus any modified base metrics. This is the only version that is about your risk rather than the flaw's characteristics, and it is the one nearly nobody computes.
The supplemental group is new and affects no score. It records Safety, Automatable, Recovery, Value Density, Vulnerability Response Effort and Provider Urgency as information for the consumer to act on. Treat it as structured commentary rather than as arithmetic.
Does the same flaw score higher or lower in 4.0?
There is no reliable conversion. Two patterns show up often enough to name. Findings that were scope-unchanged with total impact on one system tend to land in a similar place. Findings where 3.1 forced a scope change to express second-order impact, such as stored cross-site scripting or a container escape, move noticeably. Version 4.0 asks you to state what the subsequent impact was instead of applying a flat multiplier.
Do not rescore your backlog
If you adopt 4.0, adopt it for findings from a chosen date forward and leave the old ones on 3.1 with the version recorded next to each score. Rescoring a two-year backlog costs real time, produces numbers you cannot defend to whoever agreed the original remediation dates, and changes nothing about which bug to fix next. Record the version in the vector string, which is why the prefix exists.
Telling the two apart at a glance
The prefix does it. A 3.1 vector begins CVSS:3.1/ and has eight
metrics. A 4.0 vector begins CVSS:4.0/, carries eleven base
metrics, and contains AT: and VC: which have no 3.1
equivalent. If a report prints a bare number with no vector, ask for it, for
either version. A number you cannot check is an opinion with a decimal point.
How to press on that is part of
reading a penetration test
report.
| Version | Vector |
|---|---|
| v3.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| v4.0 | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
What to write in your scope document
One sentence settles it before testing starts: "Findings will be scored using CVSS v3.1 base metrics, and every finding will carry its full vector string." Add the version to the severity definitions in your remediation policy at the same time. The rest of what belongs in the scope is on how to write a penetration test scope and in the rules of engagement.
Score a finding, or get a test that produces some
The calculator is free and ungated. If you need the test that comes before the scoring, one scope goes to several Canadian firms.
Open the CVSS calculatorCommon questions
Should we ask our penetration testing firm for CVSS 4.0 scores?
Only if your other tooling speaks 4.0, which for most Canadian buyers it does not yet. Ask for v3.1 with full vector strings, and put that in the scope document so it is not a surprise. If the firm offers both, take both, because the marginal cost to them is small and it future-proofs the register.
Is a CVSS 4.0 score of 7.0 the same risk as a 3.1 score of 7.0?
No. They sit in the same severity band, High, because the bands were not changed, but they are produced by different metrics through different machinery. Comparing them directly is the single most common mistake once a team starts mixing versions. Record the version beside every score and sort within a version, never across.
Why can I not find the CVSS 4.0 equation?
Because there is not one in the sense 3.1 had. Version 4.0 scores come from a lookup over metric equivalence classes with interpolation, derived from expert scoring rather than from a closed-form formula. Implementations ship the table. This is why our own calculator covers 3.1, where the arithmetic is published and checkable.
Does PCI DSS require a particular CVSS version?
PCI DSS ties ASV scanning outcomes to CVSS-derived thresholds and requires that penetration test findings which are exploitable be corrected and the testing repeated, under requirement 11.4.4. It does not mandate that your penetration test report use a specific CVSS version. What matters is that your ranking method is defined and applied consistently. See PCI DSS penetration testing.
Our scanner reports 3.1 and our vendor reports 4.0. What now?
Keep both vectors on the finding and pick one version as the field you sort and report on, normally whichever your remediation policy names. Do not average them and do not convert. If you have to choose one to standardise on across a mixed estate today, 3.1 is still the version with the widest coverage in Canadian tooling and contracts.