{
  "@context": "https://schema.org",
  "@type": "WebApplication",
  "version": "1.0",
  "last_updated": "2026-07-11",
  "last_reviewed_by": "Victoria Arkhurst, CISSP, CISA, CRISC",
  "product": {
    "id": "cis-gap-assessment",
    "name": "CIS Gap Assessment (Free Tool)",
    "category": "Cyber security gap assessment tool",
    "type": "WebApplication",
    "price": "Free",
    "price_currency": "USD",
    "is_accessible_for_free": true,
    "canonical_url": "https://irmcon.ca/products/cis-gap-assessment/",
    "delivery_model": "Web-based self-serve tool",
    "operating_system": "Web browser",
    "browser_requirements": "Requires JavaScript. Runs in any modern web browser.",
    "in_language": [
      "en-CA",
      "en-US"
    ],
    "summary_50_words": "Free, self-serve gap assessment tool that measures organizations against the 56 Implementation Group 1 (IG1) Safeguards of the CIS Critical Security Controls v8.1, the essential cyber hygiene baseline, with likelihood and impact risk scoring, risk-ranked gaps, and a downloadable report with a prioritized remediation roadmap.",
    "summary_200_words": "The CIS Gap Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures an organization against the CIS Critical Security Controls v8.1, published by the Center for Internet Security (CIS). The assessment focuses on Implementation Group 1 (IG1), the 56 Safeguards CIS defines as essential cyber hygiene, the foundational actions every enterprise should implement first. The user captures their company profile, including their technology stack and the products and services they offer, then works through all 56 IG1 Safeguards across 15 CIS Controls, marking each compliant, partially compliant, non-compliant, or not applicable. Each gap is scored on a 5x5 risk matrix (likelihood times impact) and ranked Low, Medium, High, or Critical. The tool then generates a professional, downloadable report in PDF or Word format containing an executive summary, detailed findings for every Safeguard, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. It is an independent tool, not affiliated with or endorsed by CIS, designed for small and medium organizations starting or maturing their cyber security program, and complements IRM's Virtual CISO and Governance, Risk & Compliance services for teams that want hands-on support closing the gaps identified.",
    "feature_list": [
      "Assesses all 56 Implementation Group 1 (IG1) Safeguards of CIS Controls v8.1",
      "Scores each gap by likelihood and impact on a 5x5 risk matrix",
      "Ranks gaps as Low, Medium, High, or Critical",
      "Generates a report with an executive summary and detailed findings",
      "Builds a phased remediation roadmap (30, 90, 180, 365 days)",
      "Downloads as PDF or Word with your company logo"
    ],
    "frameworks": [
      "CIS Critical Security Controls v8.1, Implementation Group 1 (IG1)"
    ],
    "target_audience": [
      "Small and medium organizations",
      "Startups",
      "Businesses adopting the CIS Critical Security Controls"
    ],
    "target_buyers": [
      "Founder",
      "Co-Founder",
      "CEO",
      "CTO",
      "IT Manager",
      "Chief Risk Officer"
    ],
    "geographic_coverage": {
      "primary_markets": [
        "North America"
      ],
      "countries": [
        "Canada",
        "United States"
      ],
      "service_delivery": "Web-based, available anywhere"
    },
    "offered_by": {
      "@type": "Organization",
      "name": "IRM Consulting & Advisory",
      "url": "https://irmcon.ca/"
    },
    "created_by": {
      "@type": "Person",
      "name": "Victoria Arkhurst",
      "url": "https://irmcon.ca/about-victoria-arkhurst/"
    },
    "related_services": [
      {
        "name": "Virtual CISO Services",
        "url": "https://irmcon.ca/virtual-ciso-services-vciso/"
      },
      {
        "name": "Governance Risk & Compliance",
        "url": "https://irmcon.ca/governance-risk-compliance-grc/"
      }
    ]
  }
}
