Skip to content
Calcrivo

Cloud Compliance Calculator

Turn CIS benchmark control results into a severity-weighted 0-100 compliance score and show how many critical controls close the gap to target.

Inputs

controls
controls
controls
controls
controls
controls
controls
controls
/ 100

Weighted Compliance Score

75.1/ 100

Grade

B — Good

Unweighted Pass Rate

78.9%

Critical Control Pass Rate

67.9%

Failing Controls

38controls

Gap to Target

14.9points

Critical Fixes Needed

9controls

Verdict

Critical controls are the whole story — each one is worth several medium fixes at this weighting

Step by step

  1. Values used

    Critical controls in scope = 28 controls; Critical controls passing = 19 controls; High controls in scope = 52 controls; High controls passing = 40 controls; Medium controls in scope = 64 controls; Medium controls passing = 52 controls; Low controls in scope = 36 controls; Low controls passing = 31 controls; Target compliance score = 90 / 100

  2. Cloud Compliance

    Weighted score = critical pass rate × 0.40 + high × 0.30 + medium × 0.20 + low × 0.10, so each severity band contributes its weight in full only when every control in it passes.

  3. Gap closure

    Points per critical control = 40 ÷ critical controls in scope; critical fixes needed = ceil(gap ÷ points per critical), capped at the number still failing.

  4. Weighted Compliance Score

    = 75.1 / 100

  5. Grade

    = B — Good

  6. Unweighted Pass Rate

    = 78.9

  7. Critical Control Pass Rate

    = 67.9

  8. Failing Controls

    = 38 controls

  9. Gap to Target

    = 14.9 points

How it works

Unweighted pass rates flatter you: 142 of 180 controls passing reads as 79%, but if nine of the failures are critical the weighted score is lower and more honest. Weighting by severity also makes remediation planning arithmetic rather than argument — with 28 critical controls in scope each one is worth 1.43 points, while a low control is worth 0.28. Auditors and boards both ask for one number, and a raw pass rate that treats 'MFA not enforced on the root account' the same as 'S3 access logging disabled on a scratch bucket' will get you a clean report and a breach.

Formulas

Cloud Compliance

Weighted score = critical pass rate × 0.40 + high × 0.30 + medium × 0.20 + low × 0.10, so each severity band contributes its weight in full only when every control in it passes.

criticalRate
Critical controls passing ÷ critical controls in scope × 100
complianceScore
0–100 severity-weighted score
rawPassRate
All passing controls ÷ all controls, unweighted

Gap closure

Points per critical control = 40 ÷ critical controls in scope; critical fixes needed = ceil(gap ÷ points per critical), capped at the number still failing.

pointsPerCritical
Score points earned by fixing one critical control
scoreGap
Target score minus current weighted score

Frequently Asked Questions

How is Cloud Compliance calculated?

Weighted score = critical pass rate × 0.40 + high × 0.30 + medium × 0.20 + low × 0.10, so each severity band contributes its weight in full only when every control in it passes. Unweighted pass rates flatter you: 142 of 180 controls passing reads as 79%, but if nine of the failures are critical the weighted score is lower and more honest. Weighting by severity also makes remediation planning arithmetic rather than argument — with 28 critical controls in scope each one is worth 1.43 points, while a low control is worth 0.28.

Why does Cloud Compliance matter?

Auditors and boards both ask for one number, and a raw pass rate that treats 'MFA not enforced on the root account' the same as 'S3 access logging disabled on a scratch bucket' will get you a clean report and a breach.

What values do I need to enter?

This calculator takes 9 inputs: Critical controls in scope, Critical controls passing, High controls in scope, High controls passing, Medium controls in scope, Medium controls passing, Low controls in scope, Low controls passing, Target compliance score. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.

Where do the 40/30/20/10 weights come from?

They mirror how CSPM tools and the CIS benchmarks themselves prioritise: the profile-1 critical items are the ones that prevent account takeover, so they carry most of the score. Adjust them if your risk appetite differs, but keep critical at least double high or the score stops distinguishing severity.

Should controls that do not apply count as failures?

No — scope them out. A control for a service you do not use is not a finding, and leaving it in as a failure permanently caps your score and trains people to ignore the number. Document the exclusion so the auditor sees a decision rather than a gap.

You might also need