Three of the eighteen CIS Controls have no Implementation Group 1 safeguards at all. So an organisation that scores itself evenly across all eighteen is measuring something CIS never asked for — and most free checklists do exactly that.
This assessment scores 66 questions across all 18 Controls, with the Implementation Group of each safeguard shown on the question, so you find out whether essential cyber hygiene is actually covered before you worry about the rest. It is free, it saves as you go, and you can stop and come back to it.
What this is
CIS Controls v8.1 was published in June 2024 and did not change the safeguard set. Same 18 Controls, same 153 safeguards, same numbering and the same Implementation Group assignments as v8. What changed was the metadata: a new Govern security function to align with NIST CSF 2.0, revised asset classes with Applications renamed to Software and a new Documentation class, and an updated glossary. If you are working from v8 material the questions are still right; only the grouping changed.
The background is elsewhere — the controls explained, how to implement them, what it costs, benchmarks versus controls, against NIST CSF and mapped to ISO 27001. Come here when you want a score.
What it covers
66 questions, about 40 minutes.
| Section | Questions |
|---|---|
| Controls 1-2 – Know what you have | 6 |
| Control 3 – Data protection | 8 |
| Control 4 – Secure configuration | 5 |
| Controls 5-6 – Accounts and access | 8 |
| Controls 7-8 – Vulnerabilities and logs | 9 |
| Controls 9-13 – Technical defences | 14 |
| Controls 14-16 – People, suppliers and software | 11 |
| Controls 17-18 – Response and testing | 5 |
How the scoring works
| Status | Weight | Means |
|---|---|---|
| Not started | 0% | No policy, process or activity exists |
| Planned | 25% | Agreed and scheduled, nothing in place yet |
| Partially implemented | 50% | In place for part of the scope, or applied inconsistently |
| Implemented, not evidenced | 75% | Operating as intended, but you could not prove it today |
| Implemented and evidenced | 100% | Operating as intended, with records someone could sample |
| Not applicable | — | A justified exclusion, removed from the score |
IG1 is treated as a floor rather than a beginner tier, which is how CIS positions it: an emerging minimum standard for all enterprises, achievable with commercial off-the-shelf tooling and no specialist security staff.
Free score, or the full report
The assessment and your overall score are free. The full report is a one-off $39 and gives you every question with your status and notes, the score broken down by section, a prioritised gap list, and the documents from the CIS Controls Toolkit that close each gap — as a PDF and a working Excel file.
How long does it take?
About 40 minutes. Controls 3 and 16 take the longest — data protection has fourteen safeguards and application security has fourteen with none at IG1.
What to do with your score
Below 40% — work IG1 only. Fifty-six safeguards, and the CIS Community Defense Model reports that IG1 alone defends against 84 to 89 per cent of the techniques in the five most common attack patterns. That is the cheapest security you will ever buy.
40–70% — the usual shape. Inventory, patching and endpoint protection are in place; logging review, service provider management and application security are not.
Above 70% — move to IG2 or IG3 deliberately rather than by accident, and check Control 8. Centralised logs that nobody reviews is the most common high-score blind spot.
Frequently asked questions
Is this assessment really free?
Yes. All 66 questions, the breakdown by Control and your overall score cost nothing. The $39 report is optional.
Is there a CIS Controls certification?
No. CIS does not certify organisations against the Controls. You can be assessed, and you can use the Controls as the basis for an ISO 27001 or SOC 2 programme, but there is no CIS certificate.
Should I answer for IG1, IG2 or IG3?
Pick the group that matches your organisation and answer against it. Where a safeguard sits above your group, mark it not applicable and note why — that is a legitimate answer, not a gap.
Is v9 coming?
CIS has said publicly it is working on ideas for a version 9, framed around AI and ambient computing. There is no draft, no comment period and no date.
Can I use this for a client?
Yes. Run one assessment per client organisation.
What happens to my answers?
They are stored against your account so you can come back to them, and they are never shared. You can delete them at any time.