Cybersecurity Baseline Assessment - IRM Consulting & Advisory
IRM Product

Cybersecurity Baseline Assessment

The Cybersecurity Baseline Assessment is a free tool that measures a small or medium organization against CAN/DGSI 104:2021 (Rev 2:2026), Canada's national standard for baseline cyber security controls, with likelihood and impact risk scoring, a ranked gap list, and a downloadable report with a prioritized remediation roadmap.

  • CAN/DGSI 104:2021 (Rev 2:2026) aligned
  • Risk-ranked gaps & remediation roadmap
  • FREE, built by an AI-Native vCISO for SMBs

What is the Cybersecurity Baseline Assessment?

The Cybersecurity Baseline Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures a small or medium organization against CAN/DGSI 104:2021 (Rev 2:2026), Baseline Cyber Security Controls for Small and Medium Organizations, the National Standard of Canada published by the Digital Governance Standards Institute (DGSI). You assess each requirement, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.

What is CAN/DGSI 104?

CAN/DGSI 104, Baseline Cyber Security Controls for Small and Medium Organizations, is the National Standard of Canada for SMB cyber security, published by the Digital Governance Standards Institute (DGSI). It defines a practical baseline of organizational, baseline, and operating environment controls at two levels: Level 1 for organizations starting their cyber security journey and Level 2 for organizations maturing an established program. It is the Canadian counterpart to frameworks like the CIS Controls IG1, sized so that a small organization can realistically implement it without a dedicated security team.

What you get

  • A gap assessment against every Level 1 and Level 2 requirement of CAN/DGSI 104:2021 (Rev 2:2026)
  • Likelihood and impact scoring for every gap on a 5x5 risk matrix
  • Gaps ranked Low, Medium, High, or Critical
  • An executive summary with your compliance score and top risks
  • A phased remediation roadmap across 30, 90, 180, and 365 day horizons
  • A professional, downloadable report in PDF or Word format with your company logo

Who it is for

The assessment is built for small and medium organizations, startups, and growing companies that want to measure themselves against Canada's baseline cyber security controls, whether they are starting their cyber security journey (Level 1) or maturing an established program (Level 2), without engaging a consultant for the first pass.

How it works

Step 1

Capture your company profile

Enter your company name, website, and a description of what the company does, including your technology stack and the products and services you offer.

Step 2

Assess each control requirement

Work through the CAN/DGSI 104 requirements, mark each one compliant, partially compliant, non-compliant, or not applicable, and rate the likelihood and impact of each gap.

Step 3

Download your report and roadmap

Review your compliance score and risk-ranked gaps, then download a PDF or Word report with an executive summary, detailed findings, and a phased remediation roadmap.

Not loading? Open the Cybersecurity Baseline Assessment tool in a new tab.

This assessment is a self-serve working draft to support professional review and decision-making. It is not a certification or legal advice. We recommend you seek advice from a Virtual CISO. Learn more about our Governance, Risk & Compliance services.

Cybersecurity Baseline Assessment explained

A cybersecurity baseline assessment, sometimes called a CAN/DGSI 104 gap analysis, is a structured comparison of your organization's current security practices against CAN/DGSI 104:2021 (Rev 2:2026), Baseline Cyber Security Controls for Small and Medium Organizations, the National Standard of Canada published by the Digital Governance Standards Institute (DGSI). It identifies which baseline requirements you already meet, where you fall short, and what to fix first.

A good baseline assessment answers three questions. Firstly, Coverage: which level fits you, Level 1 for organizations starting their cyber security journey, or Level 2 for organizations maturing an established program, and which of the standard's organizational, baseline, and operating environment controls apply to your business? Secondly, Conformance: for each applicable requirement, do you have the process, the tooling, and the evidence to show it is actually in place?

Thirdly, Priority: of the gaps you find, which ones expose real risk to your customers, your data, and your operations, and in what order should you close them? The free assessment tool above works exactly this way: every gap is scored by likelihood and impact on a 5x5 risk matrix, so the output is a prioritized remediation roadmap rather than a flat checklist.

When to run a Baseline assessment

Run your first baseline assessment before you invest in new security tooling or pursue a certification. CAN/DGSI 104 was written specifically for Canadian small and medium organizations, and it underpins the CyberSecure Canada certification program, so a baseline assessment doubles as an early readiness check if certification is on your roadmap. The assessment tells you what you already have, what is missing, and what the remediation effort really looks like before you commit budget.

Repeat the assessment after major remediation work, after significant changes to your technology stack or business, and on an annual cycle thereafter. Because the tool on this page saves progress in your browser and is free, re-running it costs nothing but an afternoon.

What the CAN/DGSI 104 Control areas cover

The standard organizes its requirements into organizational controls (clause 4), baseline controls (clause 5), and operating environment controls (clause 6). The table below shows every control area and what it covers; the assessment walks you through all 60 underlying requirements at Level 2, or the 32 Level 1 requirements at Level 1.

CAN/DGSI 104 control areas and what they cover
ClauseControl areaRequirementsWhat it covers
4.1Leadership1Assigning a member of leadership with specific responsibility for IT and cyber security.
4.2Accountability1Establishing clear accountability for cyber security decisions and outcomes across the organization.
4.3Cyber Security Training2Baseline awareness training for all personnel, with additional training for roles with elevated responsibilities.
4.4Cyber Security Risk Assessment8Identifying systems and sensitive information, assessing threats and potential injury, and reviewing the risk assessment on a defined cycle.
5.1Incident Response Plan4A written incident response plan with roles, contact lists, recovery steps, and reporting obligations.
5.2Automatically Patch Operating Systems and Applications5Enabling automatic patching or an equivalent documented process, handling exceptions by risk decision, and replacing unsupported systems.
5.3Enable Security Software2Anti-malware and defensive software on devices, configured to update automatically.
5.4Secure Configuration Process1Securely configuring devices: changing default passwords and disabling unnecessary features.
5.5Strong User Authentication5Multi-factor authentication where available, password policies, and secure credential management.
5.6Backup and Encrypt Data5Regular backups, secure and separate storage, restoration testing, and encryption of stored and backed-up data.
5.7Basic Perimeter Defences8Firewalls, secure Wi-Fi, VPN for remote access, DNS filtering, and email domain protections.
5.8Access Control and Authorization4Least privilege, separated administrator accounts, provisioning and deprovisioning, and periodic access review.
6.1Secure Mobility3Mobile device policy, separation of work and personal data, and device protections such as encryption and remote wipe.
6.2Secure Cloud and Outsourced IT Services4Evaluating providers, contractual security requirements, understanding shared responsibility, and securely configuring cloud services.
6.3Secure Websites3Secure hosting, HTTPS, and protecting web applications in line with recognized web security guidance.
6.4Secure Portable Media2Controlling and encrypting portable storage media and wiping or destroying them before disposal.
6.5Point of Sale (POS) and Financial Systems1Securing point of sale and financial technology and meeting the related payment industry obligations.
6.6Computer Security Log Management1Retaining and reviewing computer security logs (a Level 2 control area).

Level 1 vs Level 2

CAN/DGSI 104 defines two implementation levels so that organizations can adopt the baseline progressively. Level 2 is cumulative: it contains every Level 1 requirement plus additional requirements in most control areas. The tool lets you assess at either level, so your results always reflect the scope you actually chose.

Comparison of CAN/DGSI 104 Level 1 and Level 2
Level 1Level 2
Who it is forSmall and medium organizations starting their cyber security journey.Organizations maturing an established program, or facing higher risk and customer expectations.
Requirements32 Level 1 requirements, the starting baseline.All 60 requirements: every Level 1 requirement plus 28 additional Level 2 requirements.
What Level 2 addsCore controls in every area: leadership, training, risk assessment, incident response, patching, authentication, backup, perimeter, access control, and the operating environment.Deeper requirements in most areas, for example expanded training, risk assessment, patching, authentication and perimeter requirements, plus computer security log management (control area 6.6).
How this tool maps to itSelect Level 1 in the tool to assess the Level 1 requirements only.Select Level 2 in the tool to assess all 60 requirements; this is the default.

Closing the gaps is where most organizations want help. IRM's Governance, Risk & Compliance services turn assessment findings into implemented controls and evidence habits, and our Virtual CISO services take teams from baseline remediation through certification readiness for SOC 2, ISO 27001, ISO 42001 and CMMC.

floating circle
Frequently Asked Questions

Cybersecurity Baseline Assessment FAQs

Yes. The Cybersecurity Baseline Assessment is a free, self-serve tool. You capture your company profile, assess each requirement of CAN/DGSI 104, and download a professional report with a remediation roadmap at no cost.

CAN/DGSI 104:2021, Baseline Cyber Security Controls for Small and Medium Organizations, is a National Standard of Canada published by the Digital Governance Standards Institute (DGSI). It defines Level 1 and Level 2 requirements across organizational controls, baseline controls, and controls by operating environment, designed for organizations starting or maturing their cyber security program.

Each requirement is marked compliant, partially compliant, non-compliant, or not applicable. For every gap you rate Likelihood (1 to 5) and Impact (1 to 5); the Risk Score is Likelihood times Impact on a 5x5 risk matrix, ranked Low (1 to 4), Medium (5 to 9), High (10 to 15), or Critical (16 to 25).

The report includes an executive summary with your compliance score and top risks, detailed findings for every requirement, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. It downloads in PDF or Word format with your company logo.

No. The tool runs entirely in your browser. Your answers are saved locally on your device and the PDF and Word reports are generated client-side, so your assessment data is not transmitted to IRM or any third party.

No. The assessment is a self-serve working draft to support professional review and decision-making. It is not a certification, audit, or legal advice. We recommend you seek advice from a Virtual CISO to validate findings and close the gaps identified.

Get in touch

Contact Us

Contact Us
Our Blogs

Cybersecurity & AI insights

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.