Cloud Compliance Calculator
Turn CIS benchmark control results into a severity-weighted 0-100 compliance score and show how many critical controls close the gap to target.
Inputs
Weighted Compliance Score
75.1/ 100
Grade
B — Good
Unweighted Pass Rate
78.9%
Critical Control Pass Rate
67.9%
Failing Controls
38controls
Gap to Target
14.9points
Critical Fixes Needed
9controls
Verdict
Critical controls are the whole story — each one is worth several medium fixes at this weighting
Step by step
Values used
Critical controls in scope = 28 controls; Critical controls passing = 19 controls; High controls in scope = 52 controls; High controls passing = 40 controls; Medium controls in scope = 64 controls; Medium controls passing = 52 controls; Low controls in scope = 36 controls; Low controls passing = 31 controls; Target compliance score = 90 / 100
Cloud Compliance
Weighted score = critical pass rate × 0.40 + high × 0.30 + medium × 0.20 + low × 0.10, so each severity band contributes its weight in full only when every control in it passes.
Gap closure
Points per critical control = 40 ÷ critical controls in scope; critical fixes needed = ceil(gap ÷ points per critical), capped at the number still failing.
Weighted Compliance Score
= 75.1 / 100
Grade
= B — Good
Unweighted Pass Rate
= 78.9
Critical Control Pass Rate
= 67.9
Failing Controls
= 38 controls
Gap to Target
= 14.9 points
How it works
Unweighted pass rates flatter you: 142 of 180 controls passing reads as 79%, but if nine of the failures are critical the weighted score is lower and more honest. Weighting by severity also makes remediation planning arithmetic rather than argument — with 28 critical controls in scope each one is worth 1.43 points, while a low control is worth 0.28. Auditors and boards both ask for one number, and a raw pass rate that treats 'MFA not enforced on the root account' the same as 'S3 access logging disabled on a scratch bucket' will get you a clean report and a breach.
Formulas
Cloud Compliance
Weighted score = critical pass rate × 0.40 + high × 0.30 + medium × 0.20 + low × 0.10, so each severity band contributes its weight in full only when every control in it passes.
- criticalRate
- Critical controls passing ÷ critical controls in scope × 100
- complianceScore
- 0–100 severity-weighted score
- rawPassRate
- All passing controls ÷ all controls, unweighted
Gap closure
Points per critical control = 40 ÷ critical controls in scope; critical fixes needed = ceil(gap ÷ points per critical), capped at the number still failing.
- pointsPerCritical
- Score points earned by fixing one critical control
- scoreGap
- Target score minus current weighted score
Frequently Asked Questions
How is Cloud Compliance calculated?
Weighted score = critical pass rate × 0.40 + high × 0.30 + medium × 0.20 + low × 0.10, so each severity band contributes its weight in full only when every control in it passes. Unweighted pass rates flatter you: 142 of 180 controls passing reads as 79%, but if nine of the failures are critical the weighted score is lower and more honest. Weighting by severity also makes remediation planning arithmetic rather than argument — with 28 critical controls in scope each one is worth 1.43 points, while a low control is worth 0.28.
Why does Cloud Compliance matter?
Auditors and boards both ask for one number, and a raw pass rate that treats 'MFA not enforced on the root account' the same as 'S3 access logging disabled on a scratch bucket' will get you a clean report and a breach.
What values do I need to enter?
This calculator takes 9 inputs: Critical controls in scope, Critical controls passing, High controls in scope, High controls passing, Medium controls in scope, Medium controls passing, Low controls in scope, Low controls passing, Target compliance score. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Where do the 40/30/20/10 weights come from?
They mirror how CSPM tools and the CIS benchmarks themselves prioritise: the profile-1 critical items are the ones that prevent account takeover, so they carry most of the score. Adjust them if your risk appetite differs, but keep critical at least double high or the score stops distinguishing severity.
Should controls that do not apply count as failures?
No — scope them out. A control for a service you do not use is not a finding, and leaving it in as a failure permanently caps your score and trains people to ignore the number. Document the exclusion so the auditor sees a decision rather than a gap.
You might also need
- Cloud Misconfiguration CalculatorCommonly used together
- Security Hub Score CalculatorCommonly used together
- Cloud Security Maturity CalculatorCommonly used together
- Infrastructure as Code Risk CalculatorCommonly used together
- Cloud IAM Risk CalculatorAlso in Cloud Security
- Cloud Security Health Score CalculatorAlso in Cloud Security