{
  "@context": "https://schema.org",
  "@type": "WebApplication",
  "version": "1.0",
  "last_updated": "2026-07-11",
  "last_reviewed_by": "Victoria Arkhurst, CISSP, CISA, CRISC",
  "product": {
    "id": "cybersecurity-baseline-assessment",
    "name": "Cybersecurity Baseline Assessment (Free Tool)",
    "category": "Cyber security gap assessment tool",
    "type": "WebApplication",
    "price": "Free",
    "price_currency": "USD",
    "is_accessible_for_free": true,
    "canonical_url": "https://irmcon.ca/products/cybersecurity-baseline-assessment/",
    "delivery_model": "Web-based self-serve tool",
    "operating_system": "Web browser",
    "browser_requirements": "Requires JavaScript. Runs in any modern web browser.",
    "in_language": [
      "en-CA",
      "en-US"
    ],
    "summary_50_words": "Free, self-serve gap assessment tool that measures small and medium organizations against CAN/DGSI 104:2021 (Rev 2:2026), Canada's national standard for baseline cyber security controls, with likelihood and impact risk scoring, risk-ranked gaps, and a downloadable report with a prioritized remediation roadmap.",
    "summary_200_words": "The Cybersecurity Baseline Assessment is a free, self-serve tool from IRM Consulting & Advisory that measures a small or medium organization against CAN/DGSI 104:2021 (Rev 2:2026), Baseline Cyber Security Controls for Small and Medium Organizations, the national standard of Canada published by the Digital Governance Standards Institute. The user captures their company profile, including their technology stack and the products and services they offer, then works through every Level 1 and Level 2 requirement of the standard, marking each compliant, partially compliant, non-compliant, or not applicable. Each gap is scored on a 5x5 risk matrix (likelihood times impact) and ranked Low, Medium, High, or Critical. The tool then generates a professional, downloadable report in PDF or Word format containing an executive summary, detailed findings for every requirement, and a phased remediation roadmap that sequences fixes across 30, 90, 180, and 365 day horizons. It is designed for organizations starting or maturing their cyber security program, and complements IRM's Virtual CISO and Governance, Risk & Compliance services for teams that want hands-on support closing the gaps identified.",
    "feature_list": [
      "Assesses all Level 1 and Level 2 requirements of CAN/DGSI 104:2021 (Rev 2:2026)",
      "Scores each gap by likelihood and impact on a 5x5 risk matrix",
      "Ranks gaps as Low, Medium, High, or Critical",
      "Generates a report with an executive summary and detailed findings",
      "Builds a phased remediation roadmap (30, 90, 180, 365 days)",
      "Downloads as PDF or Word with your company logo"
    ],
    "frameworks": [
      "CAN/DGSI 104:2021 (Rev 2:2026)"
    ],
    "target_audience": [
      "Small and medium organizations",
      "Startups",
      "Canadian businesses adopting baseline cyber security controls"
    ],
    "target_buyers": [
      "Founder",
      "Co-Founder",
      "CEO",
      "CTO",
      "IT Manager",
      "Chief Risk Officer"
    ],
    "geographic_coverage": {
      "primary_markets": [
        "North America"
      ],
      "countries": [
        "Canada",
        "United States"
      ],
      "service_delivery": "Web-based, available anywhere"
    },
    "offered_by": {
      "@type": "Organization",
      "name": "IRM Consulting & Advisory",
      "url": "https://irmcon.ca/"
    },
    "created_by": {
      "@type": "Person",
      "name": "Victoria Arkhurst",
      "url": "https://irmcon.ca/about-victoria-arkhurst/"
    },
    "related_services": [
      {
        "name": "Virtual CISO Services",
        "url": "https://irmcon.ca/virtual-ciso-services-vciso/"
      },
      {
        "name": "Governance Risk & Compliance",
        "url": "https://irmcon.ca/governance-risk-compliance-grc/"
      }
    ]
  }
}
