Measure CIS Controls v8 coverage across the 153 safeguards and 18 controls, scored against your IG1, IG2 or IG3 target.
The implementation groups are cumulative: IG1 is 56 safeguards, IG2 adds 74 for a total of 130, and IG3 adds the last 23 to reach all 153. Coverage is measured against your declared target group, but the IG1 baseline is weighted separately because CIS treats those 56 as the floor for every enterprise regardless of size, and automation is weighted in because a safeguard that depends on someone remembering is a safeguard that decays. CIS coverage is the most defensible way to answer are we doing the basics, and the IG1 figure in particular is the number that maps onto most cyber insurance questionnaires. It is a self-assessed management estimate, not a CIS assessment or certification.
CIS Controls Coverage
Implementation score = 0.55 × target group coverage + 0.20 × IG1 baseline coverage + 0.15 × controls fully complete ÷ 18 + 0.10 × safeguards automated ÷ 153.
Implementation score = 0.55 × target group coverage + 0.20 × IG1 baseline coverage + 0.15 × controls fully complete ÷ 18 + 0.10 × safeguards automated ÷ 153. The implementation groups are cumulative: IG1 is 56 safeguards, IG2 adds 74 for a total of 130, and IG3 adds the last 23 to reach all 153. Coverage is measured against your declared target group, but the IG1 baseline is weighted separately because CIS treats those 56 as the floor for every enterprise regardless of size, and automation is weighted in because a safeguard that depends on someone remembering is a safeguard that decays.
CIS coverage is the most defensible way to answer are we doing the basics, and the IG1 figure in particular is the number that maps onto most cyber insurance questionnaires. It is a self-assessed management estimate, not a CIS assessment or certification.
This calculator takes 6 inputs: Target implementation group, IG1 safeguards implemented (of 56), Additional IG2 safeguards implemented (of 74), Additional IG3 safeguards implemented (of 23), Of the 18 controls, how many have every in-scope safeguard done, Safeguards enforced or monitored automatically. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
IG1 if you have no dedicated IT security staff and lose only your own operational data; IG2 once you hold regulated or client data and have people whose job is infrastructure; IG3 when a breach has systemic consequences and you face targeted attackers. Picking too high a group and half-implementing it is worse than completing a lower one.
Because CIS safeguards are written as ongoing activities, not one-off projects. An inventory refreshed by a discovery tool stays true; an inventory refreshed by a quarterly spreadsheet exercise is wrong within weeks, and the audit evidence looks identical on day one.