CIS Controls Coverage Calculator
Measure CIS Controls v8 coverage across the 153 safeguards and 18 controls, scored against your IG1, IG2 or IG3 target.
Inputs
CIS Implementation Score
66.3%
Target Group Coverage
68.5%
Coverage of All 153 Safeguards
62.1%
IG1 Baseline Coverage
85.7%
Controls Fully Complete
50.0%
Safeguards Automated
40.5%
Safeguards Remaining in Target Group
41safeguards
Implementation Group
IG2 — 130 safeguards: enterprise with dedicated IT staff and regulatory or sensitive-data exposure
Next Move
Finish IG1 first — those 56 safeguards are the essential cyber hygiene baseline, and skipping ahead leaves the cheapest risk reduction on the table
Step by step
Values used
Target implementation group = IG2 — 130 safeguards; IG1 safeguards implemented (of 56) = 48 safeguards; Additional IG2 safeguards implemented (of 74) = 41 safeguards; Additional IG3 safeguards implemented (of 23) = 6 safeguards; Of the 18 controls, how many have every in-scope safeguard done = 9 controls; Safeguards enforced or monitored automatically = 62 safeguards
CIS Controls Coverage
Implementation score = 0.55 × target group coverage + 0.20 × IG1 baseline coverage + 0.15 × controls fully complete ÷ 18 + 0.10 × safeguards automated ÷ 153.
CIS Implementation Score
= 66.3
Target Group Coverage
= 68.5
Coverage of All 153 Safeguards
= 62.1
IG1 Baseline Coverage
= 85.7
Controls Fully Complete
= 50.0
Safeguards Automated
= 40.5
How it works
The implementation groups are cumulative: IG1 is 56 safeguards, IG2 adds 74 for a total of 130, and IG3 adds the last 23 to reach all 153. Coverage is measured against your declared target group, but the IG1 baseline is weighted separately because CIS treats those 56 as the floor for every enterprise regardless of size, and automation is weighted in because a safeguard that depends on someone remembering is a safeguard that decays. CIS coverage is the most defensible way to answer are we doing the basics, and the IG1 figure in particular is the number that maps onto most cyber insurance questionnaires. It is a self-assessed management estimate, not a CIS assessment or certification.
Formula
CIS Controls Coverage
Implementation score = 0.55 × target group coverage + 0.20 × IG1 baseline coverage + 0.15 × controls fully complete ÷ 18 + 0.10 × safeguards automated ÷ 153.
- 18
- CIS controls
- 153
- Safeguards in CIS Controls v8
- 56 / 130 / 153
- Cumulative safeguard counts for IG1, IG2 and IG3
Frequently Asked Questions
How is CIS Controls Coverage calculated?
Implementation score = 0.55 × target group coverage + 0.20 × IG1 baseline coverage + 0.15 × controls fully complete ÷ 18 + 0.10 × safeguards automated ÷ 153. The implementation groups are cumulative: IG1 is 56 safeguards, IG2 adds 74 for a total of 130, and IG3 adds the last 23 to reach all 153. Coverage is measured against your declared target group, but the IG1 baseline is weighted separately because CIS treats those 56 as the floor for every enterprise regardless of size, and automation is weighted in because a safeguard that depends on someone remembering is a safeguard that decays.
Why does CIS Controls Coverage matter?
CIS coverage is the most defensible way to answer are we doing the basics, and the IG1 figure in particular is the number that maps onto most cyber insurance questionnaires. It is a self-assessed management estimate, not a CIS assessment or certification.
What values do I need to enter?
This calculator takes 6 inputs: Target implementation group, IG1 safeguards implemented (of 56), Additional IG2 safeguards implemented (of 74), Additional IG3 safeguards implemented (of 23), Of the 18 controls, how many have every in-scope safeguard done, Safeguards enforced or monitored automatically. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Which implementation group should I pick?
IG1 if you have no dedicated IT security staff and lose only your own operational data; IG2 once you hold regulated or client data and have people whose job is infrastructure; IG3 when a breach has systemic consequences and you face targeted attackers. Picking too high a group and half-implementing it is worse than completing a lower one.
Why weight automation separately?
Because CIS safeguards are written as ongoing activities, not one-off projects. An inventory refreshed by a discovery tool stays true; an inventory refreshed by a quarterly spreadsheet exercise is wrong within weeks, and the audit evidence looks identical on day one.
You might also need
- Cyber Resilience CalculatorCommonly used together
- Control Gap CalculatorCommonly used together
- NIST CSF Maturity CalculatorCommonly used together
- Residual Risk CalculatorAlso in Compliance & GRC
- Disaster Recovery RTO CalculatorAlso in Compliance & GRC
- Security Investment ROI CalculatorAlso in Compliance & GRC