CIS Controls v8.1 Gap Assessment
CIS Controls v8.1 Gap Assessment is a 2-week, $4,000 fixed-price, evidence-based review of your organization against the CIS Critical Security Controls — all 56 Implementation Group 1 safeguards, and the IG2 safeguards where you choose that scope — scored from what your Microsoft 365, Entra ID, Intune, Defender, and Purview configuration actually shows rather than from a questionnaire. Every gap is mapped to the Microsoft-native fix you already license (or the license you would need), and the roadmap is sequenced by risk reduction per unit of effort. Said plainly, because someone should: there is no CIS certification for organizations. CIS publishes the Controls and provides a free self-assessment tool; it does not certify companies against them, and neither do we. What you get is a defensible, evidence-backed statement of where you stand — which is what an insurer, a customer, or a board is actually asking for.
What this engagement is
'Align to CIS' has become the default instruction from cyber-insurance carriers, enterprise customers' vendor-risk teams, and boards that want a recognizable yardstick without commissioning an ISO program. The yardstick is a good one. CIS Critical Security Controls v8.1, released by the Center for Internet Security in June 2024, organizes 18 Controls into 153 safeguards and sorts them into three Implementation Groups: IG1, the 56 safeguards CIS calls essential cyber hygiene and the floor for every enterprise; IG2, which adds safeguards for organizations handling sensitive data or carrying regulatory exposure; and IG3 for organizations with dedicated security staff facing targeted attacks. Version 8.1 also aligned the Controls with NIST CSF 2.0, adding governance as an explicit security function — which is why the process safeguards get scored here alongside the technical ones. The word that matters in this service's name is evidence. Most CIS 'assessments' are questionnaires answered by whoever is in the room, and a self-reported yes is not what a carrier or a customer is relying on. IT Partner scores each safeguard from the tenant itself: Entra ID for account inventory, MFA coverage, Conditional Access, and privileged roles; Intune for device inventory, configuration baselines, and update compliance; Defender for endpoint detection coverage, vulnerability management, and email protections; Purview for data inventory, classification, DLP, and retention; the unified audit log for logging and retention; and your backup platform for recovery evidence. Process safeguards — asset inventory ownership, incident response, security awareness, vendor management — are scored from documents and structured interviews, and the workbook records which kind of evidence backs each score. Each safeguard lands as implemented, partially implemented, not implemented, or not applicable, with the evidence reference beside it. What makes the roadmap useful rather than generic is the mapping. For every gap we name the Microsoft-native control that closes it — a Conditional Access policy, an Intune compliance policy, a Defender for Endpoint onboarding, a Purview DLP rule, an audit-retention setting — state whether it is configuration-only under your current licensing or requires a plan you do not hold, and estimate the effort. Quick wins that your own team can execute the week after the readout are separated from the projects that deserve their own engagement. Where a safeguard lives outside Microsoft 365 — network segmentation, an on-premises backup appliance, a non-Microsoft SaaS estate — the roadmap says so and names the owner rather than pretending the tenant is the whole enterprise. Two distinctions, because they cause real confusion. The CIS Controls are an enterprise-wide security program; the CIS Microsoft 365 Foundations Benchmark is a separate CIS publication of prescriptive tenant settings. This assessment scores the Controls and uses Benchmark-aligned settings as evidence where they map to a safeguard; a setting-by-setting Benchmark audit is a different engagement — closest to our SCuBA security audit. And Microsoft Secure Score is not a CIS score: it is useful evidence, weighted by Microsoft's priorities, and it will appear in the workbook where it supports a safeguard — never as a substitute for one. If your driver is a different framework, the NIST CSF Assessment covers the CSF 2.0 functions the same way.
Success criteria
What you receive
How the work unfolds
Choose IG1 or IG1 plus IG2, define the enterprise scope and the non-Microsoft systems that must be represented, identify stakeholders and document owners, and set up least-privilege, read-oriented access to the tenant.
Export and screenshot configuration from Entra ID, Intune, Defender, Purview, the audit log, and the backup platform; collect existing policies and prior assessments; run structured interviews for the process safeguards.
Score every in-scope safeguard against the evidence, map each gap to its closing Microsoft-native control with the licensing and effort flags, and draft the roadmap.
Walk the draft scores with your IT owner and compliance contact, resolve open evidence questions, and correct anything the evidence does not support.
Deliver the workbook, evidence pack, roadmap, and executive summary in a live session with leadership, and agree what your team executes internally versus what is scoped as follow-on work.
Prerequisites
Who does what
IT Partner
- Facilitate the Implementation Group and scope decision and document it.
- Collect configuration evidence from the tenant and conduct the process interviews.
- Score every in-scope safeguard from evidence and record the evidence reference and type.
- Map each gap to its closing Microsoft-native control with licensing and effort flags.
- Produce the roadmap, evidence pack, and executive summary, and deliver the readout.
- State scope limits explicitly in the report — what was assessed, what was not, and why.
Your team
- Provide access, documents, and stakeholder time on the agreed schedule.
- Choose the Implementation Group and confirm the enterprise scope.
- Validate draft scores for factual accuracy within the review window.
- Own risk acceptance for gaps deliberately left open, and own remediation priorities.
- Execute the roadmap internally or scope follow-on implementation separately.
- Re-assess as the environment changes — a point-in-time score ages.
What's not included
Limitations & technical notes
Frequently asked questions
What are the CIS Controls, and why is everyone asking us to align to them?
The CIS Critical Security Controls are a prioritized set of 18 Controls and 153 safeguards published by the Center for Internet Security, currently at version 8.1 (June 2024). They are popular with insurers, customers, and boards because they are specific, free to read, sorted into Implementation Groups by organizational maturity, and mapped to bigger frameworks such as NIST CSF, ISO 27001, and SOC 2. 'Align to CIS' usually means 'show us you have IG1 in place' — which is exactly what this assessment evidences.
Can you certify us as CIS compliant?
No — and neither can anyone else, because CIS does not certify organizations against the Controls. What exists is a free CIS self-assessment tool, an accreditation program for assessment providers, and vendor certification for products against CIS Benchmarks. None of those is an organizational certificate. If a vendor offers you 'CIS certification,' ask them who issues it. What we deliver is an evidence-backed assessment your insurer or customer can read and re-check.
IG1 or IG2 — which should we choose?
IG1 — the 56 safeguards CIS calls essential cyber hygiene — is the right scope for most SMBs and the floor every organization is expected to meet. Add IG2 when you hold sensitive customer or regulated data, face contractual security obligations, or have a customer explicitly asking for it; IG2 adds 74 safeguards, many of which are evidenced from the same Microsoft 365 configuration. We decide it together at kickoff, and IG1 is the default when you are unsure.
What is the difference between the CIS Controls and the CIS Microsoft 365 Foundations Benchmark?
The Controls are an enterprise-wide security program — people, process, and technology across every system you run. The Microsoft 365 Foundations Benchmark is a separate CIS publication listing prescriptive settings for a Microsoft 365 tenant. This assessment scores the Controls; where a Benchmark-aligned setting is the evidence for a safeguard, we use it. A setting-by-setting Benchmark audit is a different engagement, closest to our SCuBA security audit.
Is Microsoft Secure Score the same thing as a CIS score?
No. Secure Score is Microsoft's weighted measure of recommended actions in your tenant — useful evidence, and it appears in the workbook where it supports a safeguard. It says nothing about asset inventory ownership, incident response, awareness training, vendor management, or anything outside the tenant, and its weights are Microsoft's, not CIS's. A high Secure Score with no IG1 evidence is a common and slightly awkward finding.
What evidence do you actually collect, and how?
Configuration exports and dated screenshots from Entra ID (accounts, MFA, Conditional Access, privileged roles), Intune (device inventory, compliance, configuration baselines, update rings), Defender (endpoint coverage, vulnerability data, email protections), Purview (classification, DLP, retention), the unified audit log (completeness and retention), and your backup platform (what is protected, how isolated, restore evidence). Process safeguards are evidenced by documents and structured interviews, and the workbook records which type backs every score. Access is read-oriented and time-bound; we change nothing.
What does 'mapped to Microsoft-native fixes' mean in practice?
Every gap names the specific control that closes it — for example, a Conditional Access policy requiring compliant devices for Control 6, an Intune compliance policy and update ring for Control 7, Defender for Endpoint onboarding for Control 10, a Purview DLP rule for Control 3 — plus whether it is configuration-only under your current licenses or needs a plan you do not hold, and how much effort it takes. The point is that your team can start the week after the readout without translating findings into work first.
Do we need Microsoft 365 E5 to score well?
No. IG1 is largely achievable on Microsoft 365 Business Premium or E3 with Intune and Defender for Business or Defender for Endpoint Plan 1: MFA, Conditional Access, device compliance, endpoint protection, audit logging, and basic DLP are all there. E5 adds depth — Defender Vulnerability Management, extended audit retention, richer Purview — which matters more at IG2. The gap map flags exactly which items are licensing-bound so you never buy a plan a setting could have covered.
Our insurer or a customer asked for CIS alignment — what do they actually receive?
The executive summary and, where you choose, the scoring workbook and evidence pack: a dated statement of which safeguards are implemented, partially implemented, or not, with configuration evidence behind the technical scores and a roadmap for the gaps. That is a more credible answer than a questionnaire, and it is written to be handed over. What they will not receive is a certificate, because none exists.
What if much of our environment is not Microsoft?
The Controls are enterprise-wide, so non-Microsoft systems are in scope through inventory and interview evidence: they appear in the workbook with owners, and gaps there land in the roadmap. What this engagement does not do is test them — configuration review of network gear, other SaaS, or on-premises applications is separate work, and the scoping call is where we say honestly whether your estate fits a two-week Microsoft-centred assessment.
What happens after the readout — do we have to buy your remediation?
No. The roadmap is deliberately separate from any implementation quote so the findings stay honest and you keep leverage on what to fix and with whom. Quick wins are written so your own team can execute them; project-scale items map to services we run, each scoped separately if you want us. Many clients close most of IG1 themselves from the roadmap, which we consider a good outcome.
How does this relate to NIST CSF, SOC 2, or CMMC?
CIS v8.1 maps to NIST CSF 2.0 functions, and CIS publishes mappings to ISO 27001, SOC 2, and NIST SP 800-171 among others, so the evidence gathered here is reusable. If your driver is a specific framework, we run dedicated assessments for NIST CSF, SOC 1/SOC 2 pre-audit readiness, and CMMC and NIST 800-171; if you simply need a recognized yardstick without a certification program behind it, CIS is usually the right first step.
Why two weeks and $4,000?
Because the scope is fixed: one Microsoft 365 tenant, the IG1 safeguard set (with IG2 where it fits), a defined list of non-Microsoft systems, ten working days. The price is quoted in writing before work begins and you pay after you approve delivery. If your estate is genuinely bigger — multiple tenants, a large non-Microsoft footprint, an IG2 scope that needs testing rather than interviews — we say so at the scoping call and quote the difference before anything starts.