The CIS Gap Assessment is a free tool that measures your organization against the 56 Implementation Group 1 (IG1) Safeguards of the CIS Critical Security Controls v8.1, the essential cyber hygiene baseline every enterprise should implement first, with likelihood and impact risk scoring, a ranked gap list, and a downloadable report with a prioritized remediation roadmap.
The CIS Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against the CIS Critical Security Controls v8.1, published by the Center for Internet Security (CIS).
You choose your Assessment Scope: Implementation Group 1 (IG1), the 56 Safeguards CIS defines as essential cyber hygiene; IG2, which adds 74 Safeguards for a total of 130; or IG3, all 153 Safeguards of v8.1. You assess each Safeguard in your scope, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.
The CIS Critical Security Controls, commonly called the CIS Controls, are a prioritized set of cyber defense safeguards published by the Center for Internet Security (CIS) to stop the most common attacks. Version 8.1 organizes 153 Safeguards into 18 Controls and three Implementation Groups: IG1 (56 Safeguards, the essential cyber hygiene baseline), IG2 (adds 74 for a total of 130), and IG3 (all 153). The Controls are free to use, updated against real-world attack data, and map cleanly onto frameworks such as NIST CSF, ISO 27001, and most cyber insurance questionnaires, which makes them the most practical starting point for SMB security programs.
The assessment is built for small and medium organizations, startups, and growing companies that want to measure themselves against the industry-standard CIS Controls without engaging a consultant for the first pass.
IG1 is designed by CIS for enterprises with limited IT and cybersecurity expertise, using commercial off-the-shelf tooling, which makes it the right starting scope for most SMBs. Organizations with dedicated IT and security staff can select the IG2 scope, and mature organizations facing targeted attacks can assess the full IG3 set.
Enter your company name, website, and a description of what the company does, including your technology stack and the products and services you offer.
Choose the IG1, IG2 or IG3 Assessment Scope, work through every Safeguard it contains (56, 130 or all 153 across the 18 CIS Controls), mark each one compliant, partially compliant, non-compliant, or not applicable, and rate the likelihood and impact of each gap.
Review your compliance score and risk-ranked gaps, then download a PDF or Word report with an executive summary, detailed findings, and a phased remediation roadmap.
Not loading? Open the CIS Gap Assessment tool in a new tab.
This assessment is a self-serve working draft to support professional review and decision-making. It is not a certification or legal advice, and it is not affiliated with or endorsed by the Center for Internet Security (CIS). We recommend you seek advice from a Virtual CISO. Learn more about our Governance, Risk & Compliance services.
A CIS Controls gap analysis, also called a gap assessment, is a structured comparison of your organization's current security practices against the CIS Critical Security Controls v8.1, identifying which Safeguards you already meet, where you fall short, and what to fix first. Because the CIS Controls are prioritized by design, a gap assessment against Implementation Group 1 (IG1) is the standard starting point for any SMB security program.
A good gap assessment, sometimes called a CIS readiness assessment or self-assessment, answers three questions. Firstly, Coverage: which of the 18 CIS Controls and their Safeguards apply to you, and is IG1, the 56 Safeguards CIS defines as essential cyber hygiene, the right scope for your size and risk profile? Secondly, Conformance: for each applicable Safeguard, do you have the process, the tooling, and the evidence to show it is actually implemented?
Thirdly, Priority: of the gaps you find, which ones expose real risk to your customers, your data, and your operations, and in what order should you close them? The free assessment tool above works exactly this way: every gap is scored by likelihood and impact on a 5x5 risk matrix, so the output is a prioritized remediation roadmap rather than a flat checklist.
Run your first gap assessment before you invest in new security tooling or engage an auditor. IG1 was designed by CIS as the on-ramp: implementing it defends against the most common attacks, and most cyber insurance questionnaires, customer security reviews, and frameworks such as NIST CSF map cleanly onto it. The gap assessment tells you what you already have, what is missing, and what the remediation effort really looks like before you commit budget.
Repeat the assessment after major remediation work, after significant changes to your technology stack or business, and on an annual cycle thereafter. Because the tool on this page saves progress in your browser and is free, re-running it costs nothing but an afternoon.
The 56 IG1 Safeguards span 15 of the 18 CIS Controls. Three Controls, 13 (Network Monitoring and Defense), 16 (Application Software Security), and 18 (Penetration Testing), contain no IG1 Safeguards; they enter scope at IG2 and IG3, so select the IG2 or IG3 Assessment Scope in the tool to assess them. The table below shows what each Control contributes to the IG1 baseline.
| Control | Name | IG1 Safeguards | What it covers |
|---|---|---|---|
| Control 1 | Inventory and Control of Enterprise Assets | 2 | Maintain an accurate inventory of all enterprise assets (end-user devices, network devices, servers) and address unauthorized assets on a defined cadence. |
| Control 2 | Inventory and Control of Software Assets | 3 | Inventory all software, ensure only currently supported software is installed, and address unauthorized software. |
| Control 3 | Data Protection | 6 | A data management process, data inventory, access rules, retention, secure disposal, and encryption on end-user devices. |
| Control 4 | Secure Configuration of Enterprise Assets and Software | 7 | Secure configuration processes for assets, software and network infrastructure, session locking, host firewalls, and management of default accounts. |
| Control 5 | Account Management | 4 | An account inventory, unique passwords, disabling dormant accounts, and restricting administrator privileges to dedicated accounts. |
| Control 6 | Access Control Management | 5 | Processes for granting and revoking access, plus multi-factor authentication for externally exposed applications, remote network access, and administrative access. |
| Control 7 | Continuous Vulnerability Management | 4 | A vulnerability management process, a remediation process, and automated operating system and application patch management. |
| Control 8 | Audit Log Management | 3 | An audit log management process, collection of audit logs, and adequate log storage. |
| Control 9 | Email and Web Browser Protections | 2 | Using only fully supported browsers and email clients, and DNS filtering services. |
| Control 10 | Malware Defenses | 3 | Deploying and maintaining anti-malware software, automatic signature updates, and disabling autorun and autoplay for removable media. |
| Control 11 | Data Recovery | 4 | A data recovery process, automated backups, protection of recovery data, and an isolated instance of recovery data. |
| Control 12 | Network Infrastructure Management | 1 | Keeping network infrastructure up to date and supported. |
| Control 14 | Security Awareness and Skills Training | 8 | A security awareness program covering phishing, authentication best practices, data handling, unintentional exposure, incident recognition and reporting, missing updates, and insecure networks. |
| Control 15 | Service Provider Management | 1 | An inventory of service providers that hold sensitive data or support critical IT platforms. |
| Control 17 | Incident Response Management | 3 | Designated incident-handling personnel, contact information for reporting incidents, and an enterprise process for reporting them. |
CIS organizes the 153 Safeguards of v8.1 into three cumulative Implementation Groups. Each group builds on the previous one, so an organization that completes IG1 has a defined next step rather than a new framework to learn. The tool on this page covers all three groups: select IG1, IG2 or IG3 as your Assessment Scope and your assessment, results and downloadable report reflect exactly the Safeguards in that group.
| IG1 | IG2 | IG3 | |
|---|---|---|---|
| Who it is designed for | Small and medium enterprises with limited IT and cybersecurity expertise. | Organizations with dedicated IT and security staff managing multiple departments with differing risk profiles. | Mature organizations with security experts that face targeted and sophisticated attacks. |
| Safeguards | 56 Safeguards, the essential cyber hygiene baseline. | 130 Safeguards (the 56 IG1 Safeguards plus 74 more). | All 153 Safeguards of CIS Controls v8.1. |
| Focus | Defending against the most common, non-targeted attacks: keeping systems inventoried, configured, patched, backed up, and staff trained. | Protecting sensitive client and enterprise information with deeper logging, monitoring, and application controls. | Reducing the impact of sophisticated adversaries, including targeted and zero-day attacks. |
| Typical tooling | Commercial off-the-shelf hardware and software. | Enterprise-grade configuration management and monitoring tooling. | Specialized security tooling with expert staffing. |
Closing the gaps is where most organizations want help. IRM's Governance, Risk & Compliance services turn assessment findings into implemented controls and evidence habits, and our Virtual CISO services take teams from IG1 remediation through certification readiness for SOC 2, ISO 27001, ISO 42001 and CMMC.
Yes. The CIS Gap Assessment is a free, self-serve tool. You capture your company profile, choose the IG1, IG2 or IG3 Assessment Scope, assess each Safeguard of CIS Controls v8.1 in that scope, and download a professional report with a remediation roadmap at no cost.
The CIS Critical Security Controls v8.1, published by the Center for Internet Security (CIS), are a prioritized set of safeguards to mitigate the most common cyber attacks, organized into three cumulative Implementation Groups. IG1 is the foundational set of 56 Safeguards, called essential cyber hygiene, designed for small to medium-sized organizations with limited IT and cybersecurity expertise. IG2 adds 74 Safeguards (130 total) for organizations with dedicated IT and security staff, and IG3 covers all 153 Safeguards for mature organizations facing targeted and sophisticated attacks. This tool lets you assess at any of the three scopes.
Each Safeguard is marked compliant, partially compliant, non-compliant, or not applicable. For every gap you rate Likelihood (1 to 5) and Impact (1 to 5); the Risk Score is Likelihood times Impact on a 5x5 risk matrix, ranked Low (1 to 4), Medium (5 to 9), High (10 to 15), or Critical (16 to 25).
The report includes an executive summary with your compliance score and top risks, detailed findings for every Safeguard in your selected IG1, IG2 or IG3 scope with its Implementation Group shown, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. It downloads in PDF or Word format with your company logo.
No. The tool runs entirely in your browser. Your answers are saved locally on your device and the PDF and Word reports are generated client-side, so your assessment data is not transmitted to IRM or any third party.
No. The assessment is a self-serve working draft to support professional review and decision-making. It is not a certification, audit, or legal advice, and it is an independent tool that is not affiliated with or endorsed by the Center for Internet Security. We recommend you seek advice from a Virtual CISO to validate findings and close the gaps identified.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


