

CIS Gap Assessment Tool
The CIS Gap Assessment is a free tool that measures your organization against CIS Critical Security Controls v8.1, and provides a downloadable report with a prioritized remediation roadmap.
Cost / License
- Free
- Proprietary
Platforms
- Online
Features
CIS Gap Assessment Tool News & Activities
Recent activities
- IRM added CIS Gap Assessment Tool
- Maoholguin updated CIS Gap Assessment Tool
IRM added CIS Gap Assessment Tool as alternative to AlterRisk and Canadian Cybersecurity Assessment
CIS Gap Assessment Tool information
What is CIS Gap Assessment Tool?
The CIS Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against the CIS Critical Security Controls v8.1, published by the Center for Internet Security (CIS).
You choose your Assessment Scope: Implementation Group 1 (IG1), the 56 Safeguards CIS defines as essential cyber hygiene; IG2, which adds 74 Safeguards for a total of 130; or IG3, all 153 Safeguards of v8.1. You assess each Safeguard in your scope, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.
The assessment is built for small and medium organizations, startups, and growing companies that want to measure themselves against the industry-standard CIS Controls without engaging a consultant for the first pass.
IG1 is designed by CIS for enterprises with limited IT and cybersecurity expertise, using commercial off-the-shelf tooling, which makes it the right starting scope for most SMBs. Organizations with dedicated IT and security staff can select the IG2 scope, and mature organizations facing targeted attacks can assess the full IG3 set.
Safe and Secure to Use - We never see your assessment data, we do not store it, it stays in your local Browser.


