A CIS risk assessment scores how likely a foreseeable threat is to defeat each CIS Critical Security Control safeguard you have not fully implemented, how much harm would follow, and whether that risk sits above or below the level your organization agreed to accept. The method is CIS RAM v2.1, aligned to CIS Controls v8.1.
In December 2024 an attacker logged into PowerSchool’s customer support portal with a stolen credential and downloaded records on 62.4 million students and 9.5 million teachers from about 6,500 of the company’s 18,000 customers. On September 4, 2025, Texas Attorney General Ken Paxton sued, naming more than 880,000 Texans and one missing control: multifactor authentication.
The suit says PowerSchool marketed the highest security standards while lacking multifactor authentication, adequate access controls, and proper encryption. The Record reported that the data included Social Security numbers, disability records, and bus stop information, and that a Massachusetts college student pleaded guilty to the intrusion.
| CIS Risk Assessment: Key Takeaways |
| A CIS risk assessment scores each CIS Controls v8.1 safeguard gap by expectancy and impact, compares the score with an acceptable-risk line the organization set in advance, and treats what sits above the line. The CIS risk assessment method is CIS RAM v2.1, released August 2022 and free from the Center for Internet Security. |
| The original of this article said CIS has 20 controls and offered the Pentagon’s CMMC as the justification for CIS RAM. Controls v8.1 has 18 controls and 153 safeguards, and CIS RAM’s justification is duty of care under the DoCRA standard, which is what regulators and courts test. |
| PowerSchool lost records on 62.4 million students and 9.5 million teachers in December 2024 through a support portal with no multifactor authentication. Texas sued on September 4, 2025 over that missing control. Safeguard 6.5 in IG1 would have flagged it at a score of 20. |
| Verizon’s 2026 DBIR puts vulnerability exploitation in 31 percent of breaches, a third party in 48 percent, and median time to patch at 43 days. Those numbers set the expectancy column for most organizations. |
| IG1 is 56 safeguards and, per the CIS Community Defense Model v2.0, defends against 78 percent of ransomware ATT&CK techniques; all 153 safeguards reach 92 percent. Start the CIS risk assessment at your Implementation Group, then rise. |
| The worked register below scores six safeguards for a 400-person firm, sets acceptable risk at 9, and shows two rows falling from 20 and 16 to 4 after treatment. |
Every one of those controls is a numbered safeguard in CIS Controls v8.1, and every one is in Implementation Group 1, the baseline for any organization. A CIS risk assessment exists to put a number on the gap before an attorney general does. Below is the CIS risk assessment scoring and the PowerSchool row in a register.
What a CIS Risk Assessment Measures and Why the Method Is Called CIS RAM
The Center for Internet Security publishes two things that fit together. CIS Controls v8.1, released June 2024, is the prioritized list of 18 controls and 153 safeguards, grouped into three Implementation Groups. CIS RAM v2.1 is the risk assessment method that decides how far each organization needs to go with those safeguards, and it superseded v2.0 in 2022.
CIS RAM is built on the Duty of Care Risk Analysis standard. Risk is evaluated the way a regulator or court would evaluate it after a breach: were the safeguards reasonable given the foreseeable harm and the burden of preventing it. CIS’s own description calls the acceptable-risk definition a line: due care below it, treatment above it.
| Term in CIS RAM v2.1 | What it means | How it is scored |
| Safeguard | One of the 153 specific actions in Controls v8.1, such as 6.5, require MFA for administrative access | Assessed as implemented, partially implemented, or not implemented |
| Expectancy | The estimate that a foreseeable threat will succeed against the safeguard as it stands; v2.1 replaced the word likelihood because it does not imply probability over time | 1 to 5, from not expected to expected |
| Impact | The harm to the mission, to objectives, or to obligations to others if the threat succeeds | 1 to 5 per impact category; the highest category counts |
| Risk score | Expectancy multiplied by impact | 1 to 25 |
| Acceptable risk | The score at or below which the organization accepts the risk without further safeguards, agreed before scoring starts | A single number, commonly between 4 and 9 depending on the impact definitions |
| Risk treatment | A safeguard or change that brings the score to or below acceptable risk without creating a burden greater than the risk it removes | Re-scored as residual expectancy times residual impact |
The change from likelihood to expectancy is the practical difference between v2.0 and v2.1. Our CIS RAM v2.0 guide walks the seven-step workflow in detail; this page stays with the CIS risk assessment scoring and a worked register. The risk assessment pillar explains where both sit among the generic methods.
| CIS RAM v2.1 document | Audience | Contents | Use it when |
| CIS RAM Core | Any organization | Principles, the scoring model, acceptable risk, and a bare-essentials workbook | You need a defensible CIS risk assessment in a week |
| CIS RAM for IG1 | Small and medium organizations with limited security staff | Workbook and guide scoped to the 56 IG1 safeguards | You have never assessed against CIS Controls before |
| CIS RAM for IG2 | Organizations with dedicated security staff and sensitive data | Workbook and guide scoped to the 130 IG2 safeguards, with threat modelling per asset class | You hold regulated data or run multiple business lines |
| CIS RAM for IG3 | Organizations facing targeted attackers | Announced by CIS; check the current release status before relying on it | You are a likely target of state or organized crime actors |
Why the Acceptable-Risk Line in a CIS Risk Assessment Matters More Than the Gap List
Most organizations already have a gap assessment against the CIS Controls, and most are ignored because they rank 153 items with no way to stop. HALOCK’s guide to the IG2 workbook makes the point that a gap list tells you what is missing; a CIS risk assessment tells you which gaps a reasonable organization in your position would have closed.
The DoCRA test is the one regulators apply. The FTC’s data security guidance frames enforcement around reasonable security for the sensitivity of the data held, and state attorneys general use the same word. PowerSchool’s problem in Texas is not that it lacked every safeguard; it is that it lacked a safeguard whose burden was trivial against the harm it prevented.

Figure 1. Five findings from the Verizon 2026 Data Breach Investigations Report that feed the expectancy column.
Expectancy is not guesswork when the breach data is this consistent. Verizon’s 2026 DBIR, drawn from more than 31,000 incidents and 22,000 confirmed breaches across 145 countries, put vulnerability exploitation in 31 percent of breaches, up 55 percent in a year, and found the median time to patch had risen from 32 to 43 days.
Help Net Security’s summary adds that a third party featured in 48 percent of breaches, the human element in 62 percent, ransomware in 48 percent, and that only 26 percent of CISA Known Exploited Vulnerabilities were fully remediated in 2025, down from 38 percent. A partially implemented Control 7 safeguard starts at expectancy 4.
| DBIR 2026 finding | CIS Control it points at | IG1 safeguards involved | Expectancy it implies for a gap |
| 31% of breaches involve vulnerability exploitation; 43-day median patch time | 7, Continuous Vulnerability Management | 7.1 to 7.4: process, remediation, automated patching of OS and applications | 4 to 5 for any internet-facing asset |
| 48% involve a third party | 15, Service Provider Management | 15.1: inventory of service providers | 4 where a provider holds credentials or data |
| 62% involve the human element | 14, Security Awareness and Skills Training | 14.1 to 14.6: programme, phishing, credential handling | 3 to 4 for untrained staff with privileged access |
| 13% involve credential abuse | 5 and 6, Account and Access Control Management | 5.2 unique passwords; 6.3 and 6.5 MFA for external and administrative access | 5 for any external login without MFA; this is the PowerSchool row |
| 26% of KEV items remediated | 7 and 10, Malware Defenses | 7.2 remediation process; 10.1 anti-malware deployed | 4 while KEV items sit open past CISA’s deadline |
The table is why we set expectancy from published breach data before touching the organization’s own history. Most firms have one or two incidents to learn from; the DBIR has 22,000. The cybersecurity KRI template turns the same figures into monthly indicators, and the risk appetite guide shows how to write the acceptable-risk statement the board signs.
How to Run a CIS Risk Assessment in Six Steps
CIS RAM Core lays the work out as a sequence, and it maps onto the generic risk assessment guide on this site with two CIS-specific additions: the safeguard set comes from your Implementation Group, and the acceptable-risk criteria are written before any scoring. Salesforce’s Trailhead module on CIS RAM is a useful free primer for the team.
| Step | What you do | Output | Source in CIS RAM v2.1 |
| 1. Choose the Implementation Group | Answer the IG questions: sensitivity of data, size of security team, regulatory exposure, and whether you are a likely target | IG1, IG2 or IG3 and the matching workbook | Core, section on scope |
| 2. Define impact criteria | Write 1 to 5 scales for each impact category: mission, objectives, and obligations to others | Impact definitions table | Core, risk evaluation criteria |
| 3. Set acceptable risk | Agree the score at or below which no further action is required, and record who agreed it | Acceptable-risk statement signed by management | Core, risk acceptance criteria |
| 4. Model threats per safeguard | For each safeguard not fully implemented, name the foreseeable threat and the asset class it hits | Risk register rows with safeguard, asset, threat | IG workbook, threat modelling |
| 5. Score expectancy and impact | Rate each row 1 to 5 on both axes using breach data and your own incident history; multiply | Inherent risk score | Core, risk analysis |
| 6. Treat above-the-line rows | Propose a safeguard, re-score the residual, and check the safeguard’s burden does not exceed the risk it removes | Residual scores and treatment plan | Core, risk treatment |
The order matters. Writing the acceptable-risk number after the scores are known is the most common way a CIS risk assessment becomes a rationalisation, so the risk identification guide sequence of context first, scoring second, applies here in full. Steps two and three take a workshop; steps four to six take about two days per Implementation Group for a mid-sized firm.

Figure 2. Safeguard counts per Implementation Group and the ransomware coverage the CIS Community Defense Model v2.0 attributes to them.
The Implementation Group chosen at step one sets the CIS risk assessment register size. CIS’s Implementation Group page defines IG1 as 56 safeguards of essential cyber hygiene, IG2 as 130, and IG3 as all 153. The Community Defense Model v2.0 found IG1 alone defends against 78 percent of ransomware ATT&CK techniques, and the full set 92 percent.
Steps four and five use the threat vocabulary of MITRE ATT&CK, which the Community Defense Model maps to each safeguard, so the threat column is a technique ID. The risk matrix template and the register template carry the scoring; the risk assessment tool guide covers the techniques behind step four.
Step four goes quickly only when the inputs already exist. Gather these six documents before the scoring workshop, because each one fills a workbook column, and hunting for them mid-session is what stretches a two-day CIS risk assessment into a two-week one:
- The current CIS Controls self-assessment or gap list, with each safeguard marked implemented, partial, or not implemented
- The asset inventory by class: devices, software, data, users, network, and the new v8.1 documentation class
- Incident and near-miss records for the past three years, including phishing simulation results
- The list of external logins, remote access paths, and service providers with standing access
- Open items on CISA’s Known Exploited Vulnerabilities list that touch your stack
- The regulatory and contractual obligations that define the obligations-to-others impact category
A Worked CIS Risk Assessment Register: Six Safeguards Scored for a 400-Person Firm
The register below is for a 400-employee professional services firm at IG2, holding client financial data, with a two-person security team. Impact scales run 1 to 5 across mission, objectives, and obligations, the highest category counts, and acceptable risk was set at 9 before scoring. Row one is the PowerSchool scenario in this firm’s context.
| Safeguard gap (v8.1) | Foreseeable threat | Inherent (E x I) | Treatment | Residual |
| 6.5 MFA for administrative access: client support portal admin logins use password only | Stolen credential reused against the portal, mass export of client records (ATT&CK T1078) | 5 x 4 = 20 | Enforce MFA on all portal admin and support accounts; conditional access by device; alert on bulk export | 1 x 4 = 4 |
| 7.4 Automated application patch management: partial, 43-day median on internet-facing systems | Exploitation of a KEV-listed vulnerability on the VPN appliance (T1190) | 4 x 4 = 16 | 72-hour patch SLA for KEV items; weekly scan; compensating firewall rule until patched | 1 x 4 = 4 |
| 15.1 Service provider inventory: not implemented | A provider with standing access is breached and its credentials reused (T1199) | 4 x 3 = 12 | Inventory with data and access classification; quarterly review; contract clause on MFA and notification | 2 x 3 = 6 |
| 3.6 Encryption on end-user devices: 30 percent of laptops unencrypted | Laptop theft exposing client files (T1200 physical access) | 3 x 3 = 9 | Full-disk encryption enforced by MDM; asset report to confirm coverage | 1 x 3 = 3 |
| 14.2 Role-specific security awareness: partial | Finance staff act on a deepfake voice request for a wire transfer (T1566) | 3 x 4 = 12 | Payment call-back procedure; quarterly finance-specific training; simulation with voice lures | 2 x 4 = 8 |
| 11.4 Isolated recovery data: backups on the same domain | Ransomware encrypts production and backups together (T1486) | 3 x 5 = 15 | Immutable off-domain backup; monthly restore test; recovery time recorded | 1 x 5 = 5 |

Figure 3. The scoring grid and acceptable-risk line the worked register uses; 9 or below is accepted as due care.
Three rows sit above the line before treatment and none after. Row one drops from 20 to 4 because MFA cuts expectancy from expected to remote while impact is unchanged, the same arithmetic the HIPAA assessment and insider threat template use. Row three stays at 6 because an inventory cannot stop a provider being breached; it shortens the response.
The burden test in step six separates CIS RAM from a plain heat map. Full-disk encryption costs nothing beyond an MDM policy, so refusing it at a score of 9 would fail the reasonableness test even though 9 is acceptable; we would treat it and record why. The risk controls guide explains preventive against detective choices for each row.

Figure 4. The PowerSchool breach in four figures, from the Texas Attorney General’s release and press coverage.
Figure 4 is what row one looks like when it is left untreated. Security.org’s breach summary records the timeline and the data types, and the SaaS vendor assessment and vendor questionnaire on this site cover the customer-side question: whether your own providers have scored their portal logins.
Where the CIS Risk Assessment Sits Beside NIST, ISO 27005, and the CISA Goals
CIS RAM is a scoring method, not a control catalogue or a programme framework, so it slots under whichever of those an organization already runs. NIST SP 800-30 supplies the same threat, vulnerability, likelihood, impact structure; CIS RAM’s contribution is the expectancy definition and the acceptable-risk line. ISO/IEC 27005:2022 is the equivalent for an ISO 27001 information security management system.
| Framework | What it gives you | What CIS RAM adds | Where the crosswalk lives |
| NIST CSF 2.0 | Six functions including the new Govern function; outcome statements | Safeguard-level scoring under each outcome; v8.1 maps every safeguard to a CSF 2.0 function | CIS Controls v8.1 mapping tables |
| NIST SP 800-30 Rev. 1 | Federal risk assessment process and templates | Expectancy in place of likelihood; duty-of-care acceptance criteria | CIS RAM Core, terminology section |
| ISO/IEC 27005:2022 | Risk management for an ISMS; risk criteria and treatment options | A defensible acceptance line and safeguard-specific scoring | Annex mapping in CIS Controls v8.1 |
| CISA Cross-Sector Cybersecurity Performance Goals | Baseline goals for critical infrastructure with cost, complexity and impact ratings | A way to score which goals are above your line | CPG to CIS Controls mapping published by CISA |
| MITRE ATT&CK | Technique catalogue | Threat column for every register row; coverage figures from the Community Defense Model | CDM v2.0 mapping |
For US organizations choosing a home framework, the NIST CSF 2.0 pages and our NIST CSF risk assessment guide are the pair to read; the CSF against ISO 27001 comparison covers the certification question. CISA’s performance goals are the shortest path for utilities and small critical-infrastructure operators.
Regulated sectors get the same answer by a different route. The FFIEC assessment tool for banks, the OT risk assessment for plants, and the compliance risk management register all end in a scored list against an acceptance line, and a CIS risk assessment done once feeds all three.
Seven Traps That Derail CIS Risk Assessment Programs
The traps below come from assessments we have reviewed and from the failures the PowerSchool suit and the DBIR describe. Each has a correction that costs less than the finding it prevents. The types of risk assessment guide explains why a CIS risk assessment is a controls-gap method and should not replace a business impact analysis.
| Trap | How it shows up | Correction |
| Acceptable risk set after scoring | The line lands one point above the most expensive row | Sign the acceptable-risk statement in step three, dated, before any row is scored |
| Treating the gap list as the assessment | 153 findings, no priorities, nothing funded | Score only safeguards that are partial or missing; sort by inherent score; treat above the line |
| Likelihood argued from optimism | Expectancy 2 on an external login without MFA | Anchor expectancy to DBIR and KEV data; the PowerSchool row is a 5 |
| Wrong Implementation Group | IG1 chosen to keep the workbook short while holding regulated data | Answer the IG questions honestly; IG2 is the floor for sensitive data |
| Burden test skipped | Cheap safeguards refused because the score was under the line | Record burden against harm for every row at or near the line |
| Providers left out | 48 percent of breaches involve a third party; the register has none | Row per provider with standing access; safeguards 15.1 to 15.7 |
| No re-assessment trigger | Assessment dated 2023; portal migrated to a new vendor in 2025 | Re-score on new external access, new provider, major incident, KEV advisory, or annually |
The last trap is the one auditors find first. A CIS risk assessment is not a one-off exercise: CIS RAM expects re-scoring when the environment changes, and our guide on how often to run risk assessments sets the same annual floor with change triggers. A scenario-based CIS risk assessment against the ransomware row, using the ransomware business impact analysis, tests whether the residual scores are honest.
Tooling helps at scale but does not change the method. Risk assessment software and GRC platforms import the v8.1 safeguard list and hold the scoring; the workbook CIS publishes free does the same for one Implementation Group. The cyber risk management framework guide covers the programme that keeps the register current.
The CIS Risk Assessment Questions Boards and Executives Keep Asking
What is a CIS risk assessment?
A CIS risk assessment is a scored assessment of the gaps between your current safeguards and the CIS Critical Security Controls, using CIS RAM to rate each gap by expectancy and impact against an acceptable-risk line agreed in advance. The output is a register of above-the-line risks with treatments and residual scores a regulator can read.
Is a CIS risk assessment the same as CIS RAM?
CIS RAM is the method; the CIS risk assessment is the exercise you run with it. CIS RAM v2.1 has a Core document and workbooks for Implementation Groups 1 and 2, all free from the Center for Internet Security, and it aligns to CIS Controls v8.1. The v2.0 guide on this site covers the earlier edition’s seven-step workflow.
How is risk scored in a CIS risk assessment?
Expectancy from 1 to 5, the estimate that a foreseeable threat will succeed against the safeguard as it stands, multiplied by impact from 1 to 5 on the highest of mission, objectives, or obligations to others. The result from 1 to 25 is compared with the acceptable-risk number, and rows above it are treated and re-scored for residual risk.
Which Implementation Group should a CIS risk assessment use?
IG1, 56 safeguards, for organizations with limited security staff and low-sensitivity data; IG2, 130 safeguards, for organizations with dedicated security staff or regulated data; IG3, all 153, for likely targets of state or organized-crime actors. Choose by answering the IG questions honestly; the Community Defense Model shows IG1 alone defends against 78 percent of ransomware techniques.
Does a CIS risk assessment satisfy regulators?
It is built to. CIS RAM applies the Duty of Care Risk Analysis standard, so the acceptable-risk line and the burden test produce the reasonableness evidence the FTC, state attorneys general, and courts look for after a breach. The Texas suit against PowerSchool turns on exactly that question about multifactor authentication.
How long does a CIS risk assessment take?
For a mid-sized organization at IG1 or IG2, one workshop to set impact criteria and acceptable risk, then about two days of scoring per Implementation Group with the security lead and the asset owners. Larger estates or IG3 take longer because threat modelling runs per asset class. Re-scoring after the first pass takes a fraction of that.
How often should a CIS risk assessment be repeated?
Annually, and on any change trigger: a new external access path, a new service provider with standing access, a major incident, a CISA Known Exploited Vulnerabilities advisory affecting your stack, or a new CIS Controls release. The safeguard list itself last changed in June 2024 with v8.1, which added the Govern function and a documentation asset class.
Emerging Threats Your CIS Risk Assessment Register Is Not Scoring Yet
Initial access has moved, and the expectancy column should move with it. Stolen credentials fell to 13 percent of breaches while vulnerability exploitation rose to 31 percent, with edge devices the common entry point, so safeguards 7.1 to 7.4 climb the register for any organization on a 43-day patch cycle.
Shadow AI is the other blind spot. Help Net Security found 67 percent of users reaching AI services from corporate devices with personal accounts, and 45 percent using AI tools regularly, up from 15 percent. Controls 3 and 14 cover it, most 2024 registers never scored it, and the security awareness platform comparison shows which training products now include it.
Re-score the external-login rows this quarter: list every portal, remote path, and provider login a customer or supplier can reach, mark those without MFA, and score each expectancy 5. The IT risk management lifecycle and the cyber security risk management plan turn that list into a funded schedule, and the risk response guide covers the accept, treat, or transfer decision.
When an organization has a CIS Controls gap list but no scores behind it, we run CIS RAM v2.1 with the security lead over two sessions and return the register and treatment plan. Formats are on the services page and the contact page is where to start. The acceptable-risk statement is one page long.

Chris Ekai is a Risk Management expert with over 10 years of experience in the field. He has a Master’s(MSc) degree in Risk Management from University of Portsmouth and is a CPA and Finance professional. He currently works as a Content Manager at Risk Publishing, writing about Enterprise Risk Management, Business Continuity Management and Project Management.