CIS Gap Assessment - IRM Consulting & Advisory
IRM Product

CIS Gap Assessment

The CIS Gap Assessment is a free tool that measures your organization against the 56 Implementation Group 1 (IG1) Safeguards of the CIS Critical Security Controls v8.1, the essential cyber hygiene baseline every enterprise should implement first, with likelihood and impact risk scoring, a ranked gap list, and a downloadable report with a prioritized remediation roadmap.

  • CIS Controls v8.1 IG1 aligned (56 Safeguards)
  • Risk-ranked gaps & remediation roadmap
  • FREE, built by an AI-Native vCISO for SMBs

What is the CIS Gap Assessment?

The CIS Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against the CIS Critical Security Controls v8.1, published by the Center for Internet Security (CIS).

You choose your Assessment Scope: Implementation Group 1 (IG1), the 56 Safeguards CIS defines as essential cyber hygiene; IG2, which adds 74 Safeguards for a total of 130; or IG3, all 153 Safeguards of v8.1. You assess each Safeguard in your scope, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.

What are the CIS Controls?

The CIS Critical Security Controls, commonly called the CIS Controls, are a prioritized set of cyber defense safeguards published by the Center for Internet Security (CIS) to stop the most common attacks. Version 8.1 organizes 153 Safeguards into 18 Controls and three Implementation Groups: IG1 (56 Safeguards, the essential cyber hygiene baseline), IG2 (adds 74 for a total of 130), and IG3 (all 153). The Controls are free to use, updated against real-world attack data, and map cleanly onto frameworks such as NIST CSF, ISO 27001, and most cyber insurance questionnaires, which makes them the most practical starting point for SMB security programs.

What you get

  • A gap assessment against CIS Controls v8.1 at your chosen Assessment Scope: IG1 (56 Safeguards), IG2 (130 Safeguards) or IG3 (all 153 Safeguards)
  • Likelihood and impact scoring for every gap on a 5x5 risk matrix
  • Gaps ranked Low, Medium, High, or Critical
  • An executive summary with your compliance score and top risks
  • A phased remediation roadmap across 30, 90, 180, and 365 day horizons
  • A professional, downloadable report in PDF or Word format with your company logo

Who it is for

The assessment is built for small and medium organizations, startups, and growing companies that want to measure themselves against the industry-standard CIS Controls without engaging a consultant for the first pass.

IG1 is designed by CIS for enterprises with limited IT and cybersecurity expertise, using commercial off-the-shelf tooling, which makes it the right starting scope for most SMBs. Organizations with dedicated IT and security staff can select the IG2 scope, and mature organizations facing targeted attacks can assess the full IG3 set.

How it works

Step 1

Capture your company profile

Enter your company name, website, and a description of what the company does, including your technology stack and the products and services you offer.

Step 2

Assess each Safeguard in your scope

Choose the IG1, IG2 or IG3 Assessment Scope, work through every Safeguard it contains (56, 130 or all 153 across the 18 CIS Controls), mark each one compliant, partially compliant, non-compliant, or not applicable, and rate the likelihood and impact of each gap.

Step 3

Download your report and roadmap

Review your compliance score and risk-ranked gaps, then download a PDF or Word report with an executive summary, detailed findings, and a phased remediation roadmap.

Not loading? Open the CIS Gap Assessment tool in a new tab.

This assessment is a self-serve working draft to support professional review and decision-making. It is not a certification or legal advice, and it is not affiliated with or endorsed by the Center for Internet Security (CIS). We recommend you seek advice from a Virtual CISO. Learn more about our Governance, Risk & Compliance services.

CIS Controls Gap Analysis explained

A CIS Controls gap analysis, also called a gap assessment, is a structured comparison of your organization's current security practices against the CIS Critical Security Controls v8.1, identifying which Safeguards you already meet, where you fall short, and what to fix first. Because the CIS Controls are prioritized by design, a gap assessment against Implementation Group 1 (IG1) is the standard starting point for any SMB security program.

A good gap assessment, sometimes called a CIS readiness assessment or self-assessment, answers three questions. Firstly, Coverage: which of the 18 CIS Controls and their Safeguards apply to you, and is IG1, the 56 Safeguards CIS defines as essential cyber hygiene, the right scope for your size and risk profile? Secondly, Conformance: for each applicable Safeguard, do you have the process, the tooling, and the evidence to show it is actually implemented?

Thirdly, Priority: of the gaps you find, which ones expose real risk to your customers, your data, and your operations, and in what order should you close them? The free assessment tool above works exactly this way: every gap is scored by likelihood and impact on a 5x5 risk matrix, so the output is a prioritized remediation roadmap rather than a flat checklist.

When to run a Gap assessment against CIS Controls v8.1

Run your first gap assessment before you invest in new security tooling or engage an auditor. IG1 was designed by CIS as the on-ramp: implementing it defends against the most common attacks, and most cyber insurance questionnaires, customer security reviews, and frameworks such as NIST CSF map cleanly onto it. The gap assessment tells you what you already have, what is missing, and what the remediation effort really looks like before you commit budget.

Repeat the assessment after major remediation work, after significant changes to your technology stack or business, and on an annual cycle thereafter. Because the tool on this page saves progress in your browser and is free, re-running it costs nothing but an afternoon.

What the 56 IG1 Safeguards cover

The 56 IG1 Safeguards span 15 of the 18 CIS Controls. Three Controls, 13 (Network Monitoring and Defense), 16 (Application Software Security), and 18 (Penetration Testing), contain no IG1 Safeguards; they enter scope at IG2 and IG3, so select the IG2 or IG3 Assessment Scope in the tool to assess them. The table below shows what each Control contributes to the IG1 baseline.

The 15 CIS Controls with IG1 Safeguards and what they cover
ControlNameIG1 SafeguardsWhat it covers
Control 1Inventory and Control of Enterprise Assets2Maintain an accurate inventory of all enterprise assets (end-user devices, network devices, servers) and address unauthorized assets on a defined cadence.
Control 2Inventory and Control of Software Assets3Inventory all software, ensure only currently supported software is installed, and address unauthorized software.
Control 3Data Protection6A data management process, data inventory, access rules, retention, secure disposal, and encryption on end-user devices.
Control 4Secure Configuration of Enterprise Assets and Software7Secure configuration processes for assets, software and network infrastructure, session locking, host firewalls, and management of default accounts.
Control 5Account Management4An account inventory, unique passwords, disabling dormant accounts, and restricting administrator privileges to dedicated accounts.
Control 6Access Control Management5Processes for granting and revoking access, plus multi-factor authentication for externally exposed applications, remote network access, and administrative access.
Control 7Continuous Vulnerability Management4A vulnerability management process, a remediation process, and automated operating system and application patch management.
Control 8Audit Log Management3An audit log management process, collection of audit logs, and adequate log storage.
Control 9Email and Web Browser Protections2Using only fully supported browsers and email clients, and DNS filtering services.
Control 10Malware Defenses3Deploying and maintaining anti-malware software, automatic signature updates, and disabling autorun and autoplay for removable media.
Control 11Data Recovery4A data recovery process, automated backups, protection of recovery data, and an isolated instance of recovery data.
Control 12Network Infrastructure Management1Keeping network infrastructure up to date and supported.
Control 14Security Awareness and Skills Training8A security awareness program covering phishing, authentication best practices, data handling, unintentional exposure, incident recognition and reporting, missing updates, and insecure networks.
Control 15Service Provider Management1An inventory of service providers that hold sensitive data or support critical IT platforms.
Control 17Incident Response Management3Designated incident-handling personnel, contact information for reporting incidents, and an enterprise process for reporting them.

IG1 vs IG2 vs IG3

CIS organizes the 153 Safeguards of v8.1 into three cumulative Implementation Groups. Each group builds on the previous one, so an organization that completes IG1 has a defined next step rather than a new framework to learn. The tool on this page covers all three groups: select IG1, IG2 or IG3 as your Assessment Scope and your assessment, results and downloadable report reflect exactly the Safeguards in that group.

Comparison of CIS Implementation Groups IG1, IG2 and IG3
IG1IG2IG3
Who it is designed forSmall and medium enterprises with limited IT and cybersecurity expertise.Organizations with dedicated IT and security staff managing multiple departments with differing risk profiles.Mature organizations with security experts that face targeted and sophisticated attacks.
Safeguards56 Safeguards, the essential cyber hygiene baseline.130 Safeguards (the 56 IG1 Safeguards plus 74 more).All 153 Safeguards of CIS Controls v8.1.
FocusDefending against the most common, non-targeted attacks: keeping systems inventoried, configured, patched, backed up, and staff trained.Protecting sensitive client and enterprise information with deeper logging, monitoring, and application controls.Reducing the impact of sophisticated adversaries, including targeted and zero-day attacks.
Typical toolingCommercial off-the-shelf hardware and software.Enterprise-grade configuration management and monitoring tooling.Specialized security tooling with expert staffing.

Closing the gaps is where most organizations want help. IRM's Governance, Risk & Compliance services turn assessment findings into implemented controls and evidence habits, and our Virtual CISO services take teams from IG1 remediation through certification readiness for SOC 2, ISO 27001, ISO 42001 and CMMC.

floating circle
Frequently Asked Questions

CIS Gap Assessment FAQs

Yes. The CIS Gap Assessment is a free, self-serve tool. You capture your company profile, choose the IG1, IG2 or IG3 Assessment Scope, assess each Safeguard of CIS Controls v8.1 in that scope, and download a professional report with a remediation roadmap at no cost.

The CIS Critical Security Controls v8.1, published by the Center for Internet Security (CIS), are a prioritized set of safeguards to mitigate the most common cyber attacks, organized into three cumulative Implementation Groups. IG1 is the foundational set of 56 Safeguards, called essential cyber hygiene, designed for small to medium-sized organizations with limited IT and cybersecurity expertise. IG2 adds 74 Safeguards (130 total) for organizations with dedicated IT and security staff, and IG3 covers all 153 Safeguards for mature organizations facing targeted and sophisticated attacks. This tool lets you assess at any of the three scopes.

Each Safeguard is marked compliant, partially compliant, non-compliant, or not applicable. For every gap you rate Likelihood (1 to 5) and Impact (1 to 5); the Risk Score is Likelihood times Impact on a 5x5 risk matrix, ranked Low (1 to 4), Medium (5 to 9), High (10 to 15), or Critical (16 to 25).

The report includes an executive summary with your compliance score and top risks, detailed findings for every Safeguard in your selected IG1, IG2 or IG3 scope with its Implementation Group shown, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. It downloads in PDF or Word format with your company logo.

No. The tool runs entirely in your browser. Your answers are saved locally on your device and the PDF and Word reports are generated client-side, so your assessment data is not transmitted to IRM or any third party.

No. The assessment is a self-serve working draft to support professional review and decision-making. It is not a certification, audit, or legal advice, and it is an independent tool that is not affiliated with or endorsed by the Center for Internet Security. We recommend you seek advice from a Virtual CISO to validate findings and close the gaps identified.

Get in touch

Contact Us

Contact Us
Our Blogs

Cybersecurity & AI insights

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.