Industry benchmark · Government & public sector
Government website security benchmarks — how .gov sites score
U.S. federal .gov sites are subject to mandatory directives (HSTS preload, TLS 1.2+, DMARC enforcement) that make them surprisingly strong on the metrics those directives address. State and municipal sites, lacking the same federal mandates, score across a much wider range. The most consistent failure across the sector is Content-Security-Policy — even federal sites often skip CSP because the procurement and review cycle to ship a new header is slow.
Typical government & public sector score range
70–90/ 100
Approximate range based on common findings in this sector. For live data, scan any of the representative sites listed below.
What they tend to get right
Federal .gov sites have HSTS with preload, TLS 1.2+ enforced, and DMARC at p=reject — the result of explicit OMB and CISA directives (M-15-13, BOD 18-01). Most major federal sites use shared infrastructure (cloud.gov, login.gov) that delivers consistent baseline hardening.
Where they fall short
CSP adoption is uneven; many federal sites lack it entirely. State and local government sites lag the federal baseline by 15-25 points on average — they aren't bound by the same directives and often run on legacy infrastructure. Server banners frequently leak (IIS, Apache versions). Permissions-Policy is rare across the sector.
Common findings in this sector
Findings that show up frequently across government & public sector sites we’ve scanned, ranked by approximate prevalence.
- ~60% of sites
Procurement cycles slow header rollout even at federal level
- ~80% of sites
Almost universally absent across .gov
- ~35% of sites
ASP.NET and PHP banners commonly leak on state/local sites
- ~40% of sites
IIS/Apache versions visible on legacy state sites
- ~30% of sites
When present, CSP allowlists are often broad
Scan a representative government & public sector site
Click any host below to run a free scan and see how it actually scores today.
Regulatory context
Federal .gov sites operate under OMB Memo M-15-13 (HTTPS-only) and CISA Binding Operational Directive 18-01 (DMARC enforcement). State sites are not bound by those directives and post much wider score variance.
Where does your site fall?
Run a free scan to see how your site compares to others in the government & public sector sector. The full 0–100 hardening score takes ~10 seconds.