The Cybersecurity Baseline Assessment is a free tool that measures a small or medium organization against CAN/DGSI 104:2021 (Rev 2:2026), Canada's national standard for baseline cyber security controls, with likelihood and impact risk scoring, a ranked gap list, and a downloadable report with a prioritized remediation roadmap.
The Cybersecurity Baseline Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures a small or medium organization against CAN/DGSI 104:2021 (Rev 2:2026), Baseline Cyber Security Controls for Small and Medium Organizations, the National Standard of Canada published by the Digital Governance Standards Institute (DGSI). You assess each requirement, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.
CAN/DGSI 104, Baseline Cyber Security Controls for Small and Medium Organizations, is the National Standard of Canada for SMB cyber security, published by the Digital Governance Standards Institute (DGSI). It defines a practical baseline of organizational, baseline, and operating environment controls at two levels: Level 1 for organizations starting their cyber security journey and Level 2 for organizations maturing an established program. It is the Canadian counterpart to frameworks like the CIS Controls IG1, sized so that a small organization can realistically implement it without a dedicated security team.
The assessment is built for small and medium organizations, startups, and growing companies that want to measure themselves against Canada's baseline cyber security controls, whether they are starting their cyber security journey (Level 1) or maturing an established program (Level 2), without engaging a consultant for the first pass.
Enter your company name, website, and a description of what the company does, including your technology stack and the products and services you offer.
Work through the CAN/DGSI 104 requirements, mark each one compliant, partially compliant, non-compliant, or not applicable, and rate the likelihood and impact of each gap.
Review your compliance score and risk-ranked gaps, then download a PDF or Word report with an executive summary, detailed findings, and a phased remediation roadmap.
Not loading? Open the Cybersecurity Baseline Assessment tool in a new tab.
This assessment is a self-serve working draft to support professional review and decision-making. It is not a certification or legal advice. We recommend you seek advice from a Virtual CISO. Learn more about our Governance, Risk & Compliance services.
A cybersecurity baseline assessment, sometimes called a CAN/DGSI 104 gap analysis, is a structured comparison of your organization's current security practices against CAN/DGSI 104:2021 (Rev 2:2026), Baseline Cyber Security Controls for Small and Medium Organizations, the National Standard of Canada published by the Digital Governance Standards Institute (DGSI). It identifies which baseline requirements you already meet, where you fall short, and what to fix first.
A good baseline assessment answers three questions. Firstly, Coverage: which level fits you, Level 1 for organizations starting their cyber security journey, or Level 2 for organizations maturing an established program, and which of the standard's organizational, baseline, and operating environment controls apply to your business? Secondly, Conformance: for each applicable requirement, do you have the process, the tooling, and the evidence to show it is actually in place?
Thirdly, Priority: of the gaps you find, which ones expose real risk to your customers, your data, and your operations, and in what order should you close them? The free assessment tool above works exactly this way: every gap is scored by likelihood and impact on a 5x5 risk matrix, so the output is a prioritized remediation roadmap rather than a flat checklist.
Run your first baseline assessment before you invest in new security tooling or pursue a certification. CAN/DGSI 104 was written specifically for Canadian small and medium organizations, and it underpins the CyberSecure Canada certification program, so a baseline assessment doubles as an early readiness check if certification is on your roadmap. The assessment tells you what you already have, what is missing, and what the remediation effort really looks like before you commit budget.
Repeat the assessment after major remediation work, after significant changes to your technology stack or business, and on an annual cycle thereafter. Because the tool on this page saves progress in your browser and is free, re-running it costs nothing but an afternoon.
The standard organizes its requirements into organizational controls (clause 4), baseline controls (clause 5), and operating environment controls (clause 6). The table below shows every control area and what it covers; the assessment walks you through all 60 underlying requirements at Level 2, or the 32 Level 1 requirements at Level 1.
| Clause | Control area | Requirements | What it covers |
|---|---|---|---|
| 4.1 | Leadership | 1 | Assigning a member of leadership with specific responsibility for IT and cyber security. |
| 4.2 | Accountability | 1 | Establishing clear accountability for cyber security decisions and outcomes across the organization. |
| 4.3 | Cyber Security Training | 2 | Baseline awareness training for all personnel, with additional training for roles with elevated responsibilities. |
| 4.4 | Cyber Security Risk Assessment | 8 | Identifying systems and sensitive information, assessing threats and potential injury, and reviewing the risk assessment on a defined cycle. |
| 5.1 | Incident Response Plan | 4 | A written incident response plan with roles, contact lists, recovery steps, and reporting obligations. |
| 5.2 | Automatically Patch Operating Systems and Applications | 5 | Enabling automatic patching or an equivalent documented process, handling exceptions by risk decision, and replacing unsupported systems. |
| 5.3 | Enable Security Software | 2 | Anti-malware and defensive software on devices, configured to update automatically. |
| 5.4 | Secure Configuration Process | 1 | Securely configuring devices: changing default passwords and disabling unnecessary features. |
| 5.5 | Strong User Authentication | 5 | Multi-factor authentication where available, password policies, and secure credential management. |
| 5.6 | Backup and Encrypt Data | 5 | Regular backups, secure and separate storage, restoration testing, and encryption of stored and backed-up data. |
| 5.7 | Basic Perimeter Defences | 8 | Firewalls, secure Wi-Fi, VPN for remote access, DNS filtering, and email domain protections. |
| 5.8 | Access Control and Authorization | 4 | Least privilege, separated administrator accounts, provisioning and deprovisioning, and periodic access review. |
| 6.1 | Secure Mobility | 3 | Mobile device policy, separation of work and personal data, and device protections such as encryption and remote wipe. |
| 6.2 | Secure Cloud and Outsourced IT Services | 4 | Evaluating providers, contractual security requirements, understanding shared responsibility, and securely configuring cloud services. |
| 6.3 | Secure Websites | 3 | Secure hosting, HTTPS, and protecting web applications in line with recognized web security guidance. |
| 6.4 | Secure Portable Media | 2 | Controlling and encrypting portable storage media and wiping or destroying them before disposal. |
| 6.5 | Point of Sale (POS) and Financial Systems | 1 | Securing point of sale and financial technology and meeting the related payment industry obligations. |
| 6.6 | Computer Security Log Management | 1 | Retaining and reviewing computer security logs (a Level 2 control area). |
CAN/DGSI 104 defines two implementation levels so that organizations can adopt the baseline progressively. Level 2 is cumulative: it contains every Level 1 requirement plus additional requirements in most control areas. The tool lets you assess at either level, so your results always reflect the scope you actually chose.
| Level 1 | Level 2 | |
|---|---|---|
| Who it is for | Small and medium organizations starting their cyber security journey. | Organizations maturing an established program, or facing higher risk and customer expectations. |
| Requirements | 32 Level 1 requirements, the starting baseline. | All 60 requirements: every Level 1 requirement plus 28 additional Level 2 requirements. |
| What Level 2 adds | Core controls in every area: leadership, training, risk assessment, incident response, patching, authentication, backup, perimeter, access control, and the operating environment. | Deeper requirements in most areas, for example expanded training, risk assessment, patching, authentication and perimeter requirements, plus computer security log management (control area 6.6). |
| How this tool maps to it | Select Level 1 in the tool to assess the Level 1 requirements only. | Select Level 2 in the tool to assess all 60 requirements; this is the default. |
Closing the gaps is where most organizations want help. IRM's Governance, Risk & Compliance services turn assessment findings into implemented controls and evidence habits, and our Virtual CISO services take teams from baseline remediation through certification readiness for SOC 2, ISO 27001, ISO 42001 and CMMC.
Yes. The Cybersecurity Baseline Assessment is a free, self-serve tool. You capture your company profile, assess each requirement of CAN/DGSI 104, and download a professional report with a remediation roadmap at no cost.
CAN/DGSI 104:2021, Baseline Cyber Security Controls for Small and Medium Organizations, is a National Standard of Canada published by the Digital Governance Standards Institute (DGSI). It defines Level 1 and Level 2 requirements across organizational controls, baseline controls, and controls by operating environment, designed for organizations starting or maturing their cyber security program.
Each requirement is marked compliant, partially compliant, non-compliant, or not applicable. For every gap you rate Likelihood (1 to 5) and Impact (1 to 5); the Risk Score is Likelihood times Impact on a 5x5 risk matrix, ranked Low (1 to 4), Medium (5 to 9), High (10 to 15), or Critical (16 to 25).
The report includes an executive summary with your compliance score and top risks, detailed findings for every requirement, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. It downloads in PDF or Word format with your company logo.
No. The tool runs entirely in your browser. Your answers are saved locally on your device and the PDF and Word reports are generated client-side, so your assessment data is not transmitted to IRM or any third party.
No. The assessment is a self-serve working draft to support professional review and decision-making. It is not a certification, audit, or legal advice. We recommend you seek advice from a Virtual CISO to validate findings and close the gaps identified.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.


