Skip to content

POC evaluation scorecard

Fourteen weighted criteria that predict how a security tool behaves at month twelve, with a second column for the tool you already run.

v1.0CSVCurrent as of August 29, 2026No signup, generated in your browser

Most proof-of-concept scoring measures capability, which is the dimension the vendor configured and therefore the one carrying least information. This scorecard weights operational behavior at 60% of the total, because the failures that produce regret are cumulative: alert fatigue at month four, rule maintenance at month eight, an upgrade breaking an integration at month eleven. Use it during a trial, not after one.

Preview

The first 6 of 15 rows, rendered from the same data the download is built from.

CriterionGroupWeightCandidate score (1-5)Incumbent score (1-5)What a 5 looks like
Failure behaviorOperational8blankblankDegrades safely, alerts on its own outage, documented failure modes
Alert qualityOperational8blankblankSignal per alert high enough that the team still reads them at week four
Integration frictionOperational7blankblankConnected to your identity provider and SIEM without vendor engineering
Weekly human costOperational7blankblankUnder two hours per week of maintenance once tuned
Performance at your volumeOperational6blankblankTested at peak rather than average, with headroom stated
Upgrade behaviorOperational6blankblankAn upgrade observed, or a public record of clean releases

Formulas: The TOTAL row arrives empty. In your spreadsheet, set it to SUMPRODUCT of the weight column and the score column for each candidate. Maximum is 470.

How to use it

  1. Score each participant independently before any group discussion. Group scoring anchors on whichever number is said out loud first.
  2. Fill the incumbent column as well as the candidate. Without a baseline, every evaluation is structurally biased toward change.
  3. Treat any Operational criterion scoring 1 or 2 as a veto candidate regardless of the total. A tool the team stops reading is a subscription rather than a control.
  4. Do not share the weights with the vendor before the trial. Weights shared in advance become a configuration target.

The reasoning behind the weights

Changelog

v1.0 (August 29, 2026):
First release. Fourteen criteria, three weighted groups.

Common questions

Is the POC scorecard template free to download?
Yes, with no signup and no email gate. The file is generated in your browser from the same data rendered in the preview above, so nothing is requested from a server and nothing about your evaluation is transmitted anywhere.
Why does the template not score product capability?
Because capability is what the vendor selected the environment for and staffed the configuration around, so a trial measures its ceiling rather than your experience. If a product cannot do the job the evaluation should end before scoring starts, which makes capability a gate rather than a scored dimension.
What score means buy?
Above 380 out of 470 with no operational criterion under 3. Between 320 and 380, buy it if the gaps sit in evidence and support, which improve with account attention, and decline if they sit in operations, which do not. Below 320 the evaluation should have closed earlier.

Filed under Buying & Evaluation.