Skip to content
Calcrivo

CIS Controls Coverage Calculator

Measure CIS Controls v8 coverage across the 153 safeguards and 18 controls, scored against your IG1, IG2 or IG3 target.

Inputs

safeguards
safeguards
safeguards
controls
safeguards

CIS Implementation Score

66.3%

Target Group Coverage

68.5%

Coverage of All 153 Safeguards

62.1%

IG1 Baseline Coverage

85.7%

Controls Fully Complete

50.0%

Safeguards Automated

40.5%

Safeguards Remaining in Target Group

41safeguards

Implementation Group

IG2 — 130 safeguards: enterprise with dedicated IT staff and regulatory or sensitive-data exposure

Next Move

Finish IG1 first — those 56 safeguards are the essential cyber hygiene baseline, and skipping ahead leaves the cheapest risk reduction on the table

Step by step

  1. Values used

    Target implementation group = IG2 — 130 safeguards; IG1 safeguards implemented (of 56) = 48 safeguards; Additional IG2 safeguards implemented (of 74) = 41 safeguards; Additional IG3 safeguards implemented (of 23) = 6 safeguards; Of the 18 controls, how many have every in-scope safeguard done = 9 controls; Safeguards enforced or monitored automatically = 62 safeguards

  2. CIS Controls Coverage

    Implementation score = 0.55 × target group coverage + 0.20 × IG1 baseline coverage + 0.15 × controls fully complete ÷ 18 + 0.10 × safeguards automated ÷ 153.

  3. CIS Implementation Score

    = 66.3

  4. Target Group Coverage

    = 68.5

  5. Coverage of All 153 Safeguards

    = 62.1

  6. IG1 Baseline Coverage

    = 85.7

  7. Controls Fully Complete

    = 50.0

  8. Safeguards Automated

    = 40.5

How it works

The implementation groups are cumulative: IG1 is 56 safeguards, IG2 adds 74 for a total of 130, and IG3 adds the last 23 to reach all 153. Coverage is measured against your declared target group, but the IG1 baseline is weighted separately because CIS treats those 56 as the floor for every enterprise regardless of size, and automation is weighted in because a safeguard that depends on someone remembering is a safeguard that decays. CIS coverage is the most defensible way to answer are we doing the basics, and the IG1 figure in particular is the number that maps onto most cyber insurance questionnaires. It is a self-assessed management estimate, not a CIS assessment or certification.

Formula

CIS Controls Coverage

Implementation score = 0.55 × target group coverage + 0.20 × IG1 baseline coverage + 0.15 × controls fully complete ÷ 18 + 0.10 × safeguards automated ÷ 153.

18
CIS controls
153
Safeguards in CIS Controls v8
56 / 130 / 153
Cumulative safeguard counts for IG1, IG2 and IG3

Frequently Asked Questions

How is CIS Controls Coverage calculated?

Implementation score = 0.55 × target group coverage + 0.20 × IG1 baseline coverage + 0.15 × controls fully complete ÷ 18 + 0.10 × safeguards automated ÷ 153. The implementation groups are cumulative: IG1 is 56 safeguards, IG2 adds 74 for a total of 130, and IG3 adds the last 23 to reach all 153. Coverage is measured against your declared target group, but the IG1 baseline is weighted separately because CIS treats those 56 as the floor for every enterprise regardless of size, and automation is weighted in because a safeguard that depends on someone remembering is a safeguard that decays.

Why does CIS Controls Coverage matter?

CIS coverage is the most defensible way to answer are we doing the basics, and the IG1 figure in particular is the number that maps onto most cyber insurance questionnaires. It is a self-assessed management estimate, not a CIS assessment or certification.

What values do I need to enter?

This calculator takes 6 inputs: Target implementation group, IG1 safeguards implemented (of 56), Additional IG2 safeguards implemented (of 74), Additional IG3 safeguards implemented (of 23), Of the 18 controls, how many have every in-scope safeguard done, Safeguards enforced or monitored automatically. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Which implementation group should I pick?

IG1 if you have no dedicated IT security staff and lose only your own operational data; IG2 once you hold regulated or client data and have people whose job is infrastructure; IG3 when a breach has systemic consequences and you face targeted attackers. Picking too high a group and half-implementing it is worse than completing a lower one.

Why weight automation separately?

Because CIS safeguards are written as ongoing activities, not one-off projects. An inventory refreshed by a discovery tool stays true; an inventory refreshed by a quarterly spreadsheet exercise is wrong within weeks, and the audit evidence looks identical on day one.

You might also need