The CIS Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures your organization against the CIS Critical Security Controls v8.1, published by the Center for Internet Security (CIS).
You choose your Assessment Scope: Implementation Group 1 (IG1), the 56 Safeguards CIS defines as essential cyber hygiene; IG2, which adds 74 Safeguards for a total of 130; or IG3, all 153 Safeguards of v8.1. You assess each Safeguard in your scope, score gaps by likelihood and impact, and download a professional report with an executive summary, detailed findings, and a prioritized remediation roadmap.
The assessment is built for small and medium organizations, startups, and growing companies that want to measure themselves against the industry-standard CIS Controls without engaging a consultant for the first pass.
IG1 is designed by CIS for enterprises with limited IT and cybersecurity expertise, using commercial off-the-shelf tooling, which makes it the right starting scope for most SMBs. Organizations with dedicated IT and security staff can select the IG2 scope, and mature organizations facing targeted attacks can assess the full IG3 set.
Safe and Secure to Use - We never see your assessment data, we do not store it, it stays in your local Browser.