Skip to content
IjyaLabs logo
IjyaLabs
Beta — under testing and trial. Do not use for live compliance decisions, statutory submissions, or regulatory reliance. Readiness preparation only, not a certification or audit.
⚙️Beta

CIS Controls v8

Implementation Group readiness across all 18 CIS v8 control families. Profile your org → auto-derive IG1/IG2/IG3 → score applicable safeguards → get a prioritised gap register.

Before you start — what to have ready for CIS Controls

Gather these first. Every one of them is something the assessment will ask for, and finding them mid-way is where an assessment stalls.

Decide your scope first

This module works out which controls apply to you from your answers, so complete the scope step first. Starting without it assesses a population you did not choose.

  • Which systems, services and locations are in scope — write this down before you answer anything.
  • Who owns each area, so an answer about it is somebody’s to give.
  • The period the evidence should cover, where the framework opines on a period rather than a moment.

Gather these documents

What CIS Controls is assessed against. Find them before you start — the assessment reads what you upload, not what you tell it.

  • Asset and software inventory
  • Secure configuration standards / baselines
  • Access control and account management records
  • Vulnerability management (scan reports and remediation records)
  • Audit log configuration
  • Data protection and backup procedures

Have the right people

Who needs to be involved, and what changes if it is only you.

  • Someone who can find the documents — usually whoever owns the control day to day.
  • A second person to review what was uploaded, if you want reviewed coverage. They must not be the person who submitted or attached that evidence: no one reviews their own work.
  • One person can complete the whole assessment. Reviewed coverage will read zero, and that is accurate rather than a fault.
  • A reviewer’s acceptance is what raises a control from partial to proven, and every workspace has that during the open beta. It becomes something a plan includes once there is anything to buy.

Prepare the files

Upload only what the assessment needs. You are responsible for removing or masking personal and sensitive data that a control does not require — do it before you upload. Inventories and scan reports carry internal IPs, hostnames and account names. Mask them, and remove any credentials, before uploading — the standards and procedures are what is assessed.

  • Upload digital documents only — a Word file, a spreadsheet, or a PDF with real text. A photograph or a scanned paper has no readable text, so it cannot be assessed or prove a control.
  • A scan or a photograph has no text to read, so it cannot prove a control. Export the original instead.
  • The same file cannot be uploaded twice to one library — it is recognised by its contents, not its name.
  • Upload the document itself, not a summary of it. A summary is your description of the evidence, not the evidence.
  • A document that is not about this framework will be accepted and matched against nothing. It still counts against your library, so it is worth checking before you send it.

Know what you will get

So the result is what you expected when you started.

  • You get a readiness position derived from the evidence you upload, and a list of where the gaps are.
  • You do not get an audit, an opinion, or a certification. Only a licensed auditor, an accredited certification body, or the relevant regulator can give you those.
  • Controls you upload nothing for are reported as UNEXAMINED — not as failed. That distinction is deliberate.
  • A document can support a control without proving it. Supporting evidence raises a control to partial; reaching proven takes evidence a second person independently reviewed and accepted.
18
Control families
CIS v8
3
Implementation Groups
IG1 · IG2 · IG3
₹0
Free to start
10 critical controls free

Your assessment journey

Four steps from your implementation group to an evidence-backed safeguard position.

1
Profile5 min

Your organisation size, sector and risk exposure, which derive the Implementation Group and so which safeguards apply to you.

Open →
2
Assessment15 - 20 min

The eighteen CIS Controls families in scope for your Implementation Group. Anything left unanswered counts as zero.

Open →
3
ResultsInstant

Your position by control family with the gaps ordered by weight, each raisable as a corrective action you can track.

Open →
4
Evidence LibraryAs needed

Each family names the artefacts that would prove it - an asset inventory with owners, a scan report with its remediation record. Upload them and the score stops being self-declared.

Open →

Implementation Groups

Implementation Group 1

Essential cyber hygiene — small orgs, limited IT/security staff

Implementation Group 2

Foundational + additional safeguards — orgs with dedicated IT staff

Implementation Group 3

All safeguards — large orgs with dedicated security function

Note: This assessment covers one representative safeguard per control family (18 total). CIS Controls v8 defines 153 individual safeguards across the 18 families — full safeguard-level coverage is available via CIS SecureSuite. This is a self-assessed readiness indicator and does not constitute a CIS-certified assessment.