Three of the eighteen CIS Controls have no Implementation Group 1 safeguards at all. So an organisation that scores itself evenly across all eighteen is measuring something CIS never asked for — and most free checklists do exactly that.

This assessment scores 66 questions across all 18 Controls, with the Implementation Group of each safeguard shown on the question, so you find out whether essential cyber hygiene is actually covered before you worry about the rest. It is free, it saves as you go, and you can stop and come back to it.

What this is

CIS Controls v8.1 was published in June 2024 and did not change the safeguard set. Same 18 Controls, same 153 safeguards, same numbering and the same Implementation Group assignments as v8. What changed was the metadata: a new Govern security function to align with NIST CSF 2.0, revised asset classes with Applications renamed to Software and a new Documentation class, and an updated glossary. If you are working from v8 material the questions are still right; only the grouping changed.

The background is elsewhere — the controls explained, how to implement them, what it costs, benchmarks versus controls, against NIST CSF and mapped to ISO 27001. Come here when you want a score.

What it covers

66 questions, about 40 minutes.

SectionQuestions
Controls 1-2 – Know what you have6
Control 3 – Data protection8
Control 4 – Secure configuration5
Controls 5-6 – Accounts and access8
Controls 7-8 – Vulnerabilities and logs9
Controls 9-13 – Technical defences14
Controls 14-16 – People, suppliers and software11
Controls 17-18 – Response and testing5

How the scoring works

StatusWeightMeans
Not started0%No policy, process or activity exists
Planned25%Agreed and scheduled, nothing in place yet
Partially implemented50%In place for part of the scope, or applied inconsistently
Implemented, not evidenced75%Operating as intended, but you could not prove it today
Implemented and evidenced100%Operating as intended, with records someone could sample
Not applicable—A justified exclusion, removed from the score

IG1 is treated as a floor rather than a beginner tier, which is how CIS positions it: an emerging minimum standard for all enterprises, achievable with commercial off-the-shelf tooling and no specialist security staff.

Free score, or the full report

The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by section, a prioritised gap list, and the documents from the CIS Controls Toolkit that close each gap — as a PDF and a working Excel file.

How long does it take?

About 40 minutes. Controls 3 and 16 take the longest — data protection has fourteen safeguards and application security has fourteen with none at IG1.

What to do with your score

Below 40% — work IG1 only. Fifty-six safeguards, and the CIS Community Defense Model reports that IG1 alone defends against 84 to 89 per cent of the techniques in the five most common attack patterns. That is the cheapest security you will ever buy.

40–70% — the usual shape. Inventory, patching and endpoint protection are in place; logging review, service provider management and application security are not.

Above 70% — move to IG2 or IG3 deliberately rather than by accident, and check Control 8. Centralised logs that nobody reviews is the most common high-score blind spot.

Frequently asked questions

Is this assessment really free?

Yes. All 66 questions, the breakdown by Control and your overall score cost nothing. The $39 report is optional.

Is there a CIS Controls certification?

No. CIS does not certify organisations against the Controls. You can be assessed, and you can use the Controls as the basis for an ISO 27001 or SOC 2 programme, but there is no CIS certificate.

Should I answer for IG1, IG2 or IG3?

Pick the group that matches your organisation and answer against it. Where a safeguard sits above your group, mark it not applicable and note why — that is a legitimate answer, not a gap.

Is v9 coming?

CIS has said publicly it is working on ideas for a version 9, framed around AI and ambient computing. There is no draft, no comment period and no date.

Can I use this for a client?

Yes. Run one assessment per client organisation.

What happens to my answers?

They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.