CIS Controls

The CIS Controls,
explained plainly

The CIS Critical Security Controls are a prioritized set of cybersecurity safeguards maintained by the Center for Internet Security. Here is what they actually are: the 18 Controls, the Safeguards beneath them, and the IG1 to IG3 implementation groups that tell you what to do first — and how teams run the whole program in one Swiss-hosted workspace.

Book a conversation
Every framework
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
ISO/IEC 27001SOC 2GDPRHIPAASwiss nFADPNIST CSF 2.0OWASPEU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
  • HIPAA
  • Swiss nFADP
  • NIST CSF 2.0
  • OWASP
  • EU AI Act
The safeguards

What the CIS Controls actually are.

The CIS Controls are a voluntary, prioritized list of what to do to defend an organization — not a certifiable standard you pass. The current v8.1 set pairs 18 Controls with more than 150 Safeguards, and sorts them into implementation groups so you know where to start.

The 18 Controls

From inventory of enterprise assets and software through data protection, access control, logging and incident response — the top-level areas every program is organized around.

The Safeguards

More than 150 concrete actions sit beneath the 18 Controls. The Safeguard, not the Control, is the unit you actually implement and measure.

Implementation groups

IG1 is essential cyber hygiene every organization starts with; IG2 and IG3 add safeguards as your data sensitivity and threat exposure grow.

Voluntary, not certified

There is no CIS Controls certificate and no auditor. You adopt the safeguards, measure your progress, and show where you stand.

The full picture

CIS Controls, explained in full.

A plain-language walkthrough — what it is, what it asks for, and what it takes to keep it current.

01

What are the CIS Controls?

The CIS Critical Security Controls, commonly just "the CIS Controls", are a prioritized set of cybersecurity safeguards maintained by the Center for Internet Security (CIS). They are not a regulation and not a certifiable standard; they are a community-built, opinionated answer to one question: of everything you could do to defend an organization, what should you actually do, and in what order?

That framing is the whole point. Most frameworks tell you to consider a broad set of requirements and leave the sequencing to you. The CIS Controls instead rank the work, so a team with limited time and people knows which safeguards to put in place first and which can wait until the basics are solid. You implement them, you measure your progress against them — you do not "pass" them.

The current version is v8.1. Version 8 was published in 2021 and reduced the set from 20 controls to 18; v8.1, released in 2024, refines that set and updates the mapping so it lines up cleanly with NIST CSF 2.0. If you read older material referring to 20 controls, that describes v7 — the structure below is v8.1.

Controls vs Safeguards

The two terms are easy to blur, so it is worth being precise. A Control is one of the 18 top-level areas — "inventory and control of enterprise assets", for example. A Safeguard is a specific action within that Control, such as establishing and maintaining a detailed asset inventory. There are 18 Controls and more than 150 Safeguards in total. You organize your thinking around the Controls, but the Safeguard is the thing you actually implement, evidence and measure.

02

The 18 Controls and their Safeguards

The 18 Controls run roughly from "know what you have" to "be ready when something goes wrong". They open with the foundations almost nothing else works without, inventory and control of enterprise assets, and inventory and control of software assets, because you cannot protect or patch what you do not know you run. From there they move through data protection, secure configuration, account and access management, vulnerability management, audit log management, and defenses for email, browsers and malware.

The later Controls cover the operational side of security: network infrastructure and monitoring, security awareness and skills training, service-provider management, application software security, incident response management, and penetration testing. Taken together they describe a complete defensive program, but the value is in the ordering — the early Controls carry far more risk reduction per unit of effort than the later ones.

Crucially, you do not work through all 18 Controls and every Safeguard at once. Which Safeguards you take on, and when, is decided by the implementation groups — the mechanism that turns a long list into a sequenced plan.

03

Implementation groups (IG1, IG2, IG3) and why prioritization matters

The defining feature of the CIS Controls is that the Safeguards are sorted into three implementation groups, each a self-assessed category describing who should do what. IG1 is essential cyber hygiene: the foundational Safeguards every organization should put in place first, achievable by a small team without deep security specialism. It is not a watered-down tier — it is the baseline that defends against the most common, untargeted attacks, and it is where almost everyone should begin.

IG2 builds on IG1 for organizations that manage more sensitive data, run more complex environments, or have the resources to go further. IG3 adds the remaining Safeguards for mature organizations facing sophisticated, targeted threats — the kind that need to withstand a determined adversary. Each group is cumulative: IG2 includes everything in IG1, and IG3 includes everything in IG2.

The intended path is to start at IG1 and grow. That is what separates the CIS Controls from a flat checklist: instead of staring at more than 150 Safeguards and freezing, a team implements IG1 first, gets real protection from a defined and achievable set, and expands to IG2 or IG3 only as its risk profile and capacity justify it.

04

CIS Controls vs CIS Benchmarks

CIS publishes two things that get confused constantly, and the distinction matters. The CIS Controls are the safeguards: the "what to do" across your whole program. The CIS Benchmarks are detailed secure-configuration guides for specific products — the "how to harden this particular system", with precise recommended settings for an operating system, database, browser or cloud platform.

You use them together, not interchangeably. A Safeguard under the secure-configuration Control might say "establish and maintain secure configurations" — and the relevant CIS Benchmark is where you find the exact settings to apply on a given platform to satisfy it. The Controls tell you the configuration needs to be secure and managed; the Benchmark tells you what "secure" means for that specific product.

The wider CIS toolkit

Around the Controls and Benchmarks, CIS also provides supporting tooling. CIS-CAT and the CIS Controls Self Assessment Tool (CSAT) help you assess where you stand against the Benchmarks and Controls, and CIS Hardened Images ship preconfigured to a Benchmark for common cloud platforms. None of these is required to adopt the Controls — they are aids, not a certification scheme.

05

How the CIS Controls map to NIST CSF and ISO 27001

The CIS Controls were built to interoperate, not to compete with the broader frameworks. CIS publishes mappings from the Safeguards to NIST CSF, ISO 27001, PCI DSS and others, and v8.1 specifically realigned its mapping to NIST CSF 2.0. That means the work you do to implement a CIS Safeguard does not sit in isolation — it can be pointed at the corresponding requirement in a framework you are also pursuing.

This is why so many teams treat the CIS Controls as a practical entry point. Because the Safeguards are concrete and prioritized, they give you a clear order of operations; because they map outward, that work feeds straight into a NIST CSF profile or an ISO 27001 control set when you take one of those on. You get a defined starting list and a head start on the broader framework at the same time.

06

Who uses the CIS Controls, and why

The CIS Controls appeal to teams that want a concrete, prioritized "what do we actually do first" list rather than a broad set of requirements to interpret. That is often a growing software company, a lean IT or security team, or a managed-service provider that needs to improve its defensive posture quickly and does not have months to spend deciding where to begin.

In practice the Controls show up in two roles. They are the on-ramp before a broader framework: a way to make tangible progress and reduce real risk while a longer ISO 27001 or NIST CSF effort is still being scoped. And they are the backbone underneath one — the concrete safeguards that satisfy much of what those frameworks ask for, mapped across so the same work counts twice. Either way, the draw is the same: a prioritized list beats a blank page.

07

Voluntary and uncertified: how you show progress

There is no CIS Controls certificate, no accredited auditor, and no pass mark. Nobody issues you a CIS Controls badge, because that is not how a voluntary safeguard set works. This sometimes reads as a weakness, but it is just a different model: the Controls are a tool for genuinely improving and demonstrating your security, not a label to acquire.

So you show progress by measuring it. Because the unit of work is the Safeguard, you can track which Safeguards are implemented, which are partial, and which are not yet started — by implementation group, so "we have completed IG1 and are part way through IG2" becomes a clear, honest statement of where you stand. CIS-CAT and CSAT exist precisely to support this self-assessment.

For customers and partners, that measured position is what you present: not a certificate, but a clear, evidenced picture of which safeguards you have in place and the group you are working toward. Kept current, it answers the security question a prospect is really asking, what do you actually do to defend this, without waiting on an audit cycle.

08

Getting started with IG1

The right first move with the CIS Controls is almost always the same: implement Implementation Group 1. IG1 is a defined, achievable set of essential-hygiene Safeguards that any organization can put in place, and it defends against the bulk of common, opportunistic attacks. Starting there gives a small team real, measurable protection quickly, without first deciding which of more than 150 Safeguards matter.

In practice that means working the early Controls first — knowing what assets and software you run, managing accounts and access, keeping configurations secure, patching known vulnerabilities, and recording where each IG1 Safeguard stands as you go. Once IG1 is genuinely solid, you expand toward IG2 or IG3 in line with your data sensitivity, complexity and threat exposure, rather than all at once.

09

Keeping pace with new versions

The CIS Controls are revised periodically as the threat landscape shifts, so part of running a program is keeping it current with the latest version. The move from v7 to v8 reorganized the set from 20 controls to 18 and regrouped the Safeguards; v8.1 then refined that work and realigned the mappings with NIST CSF 2.0. Each revision can move Safeguards between Controls or change which implementation group they fall into.

The practical implication is that a CIS Controls program is not a one-time exercise. When a new version lands, you reconcile your existing implementation against it — noting what moved, what is new, and where your measured position changes, rather than starting over. Teams that keep their safeguard status in one connected place absorb a version change as an update; teams that track it in scattered spreadsheets reconstruct it from scratch each time.

The real problem

Audit-ready is a state you keep, not a sprint you survive.

Most tools optimize for getting the first certificate. The expensive part is the years after — the spreadsheet sprawl, the evidence you reassemble from memory the week before an audit, the client (or control) you haven't looked at since last cycle. That's the part no first-cert tool was built for.

Spreadsheet sprawl across drives, tabs and inboxes
The week-before scramble, reassembled from memory
The control you haven't looked at since last cycle
Audit-readiness over time
Year over year
audit-readyYear 1Year 2Year 3
Point-in-time tools — scramble & drift
devguard — a state you keep
Run it in devguard

Your CIS Controls program, in one workspace.

Every Safeguard, its evidence, its implementation group and its mapping — connected and current, not scattered across spreadsheets. Pick one to see it.

Every Safeguard, by implementation group

See all 18 Controls and their Safeguards, filtered by IG1, IG2 and IG3, with where you stand on each — so "we have completed IG1 and are part way through IG2" is a live view, not a number you reconstruct.

Learn more
Control coverage64%
Asset managementCovered
CryptographyPartial
Supplier securityGap
Implement once. Map across every framework you add.

The CIS Controls map heavily onto NIST CSF and ISO 27001. Implement a Safeguard once in devguard and the same policy and evidence point at the matching requirement everywhere it appears — so the broader framework is a fraction of the work once the safeguards are in place.

See the full feature comparison

Already certified and dreading the next cycle? See how we help certified companies stay audit-ready.

Already working through the CIS Controls? Move your program across.

If you are already implementing the CIS Controls, you do not want to rebuild your safeguard tracking from a blank page. In a scoped conversation we agree exactly what moves — your safeguard status by implementation group, policies, evidence and review history, and run that migration with you, for a fixed scope and a date set before we start. Your existing setup stays untouched and exportable until you are satisfied the new one holds up side by side.

Book a conversation
CIS Controls FAQ

CIS Controls, answered plainly.

Can you get certified in the CIS Controls?

No. The CIS Controls are a voluntary, prioritized set of safeguards, not a certifiable standard — there is no CIS Controls certificate and no accredited auditor. You adopt the safeguards, measure your progress, and show where you stand. CIS provides self-assessment tools such as CIS-CAT and CSAT to support that.

How many CIS Controls are there?

The current v8.1 set has 18 Controls, broken down into more than 150 Safeguards. Older material citing 20 controls describes v7 — version 8 reduced the set to 18 in 2021, and v8.1 refined it in 2024 and realigned the mapping with NIST CSF 2.0.

What are the CIS implementation groups (IG1, IG2, IG3)?

They sort the Safeguards by who should implement them. IG1 is essential cyber hygiene for every organization; IG2 builds on it for organizations with more sensitive data or complexity; IG3 adds the rest for mature organizations facing sophisticated threats. Each group includes the ones below it, and the intended path is to start at IG1 and grow.

What is the difference between the CIS Controls and CIS Benchmarks?

The CIS Controls are the safeguards: the "what to do" across your whole program. The CIS Benchmarks are detailed secure-configuration guides for specific products — the "how to harden this system", with precise recommended settings. You use them together: the Controls say configurations must be secure, the Benchmarks say what secure means for a given platform.

How do the CIS Controls relate to NIST CSF and ISO 27001?

CIS publishes mappings from the Safeguards to NIST CSF, ISO 27001, PCI DSS and others, and v8.1 realigned its mapping to NIST CSF 2.0. Because the Safeguards are concrete and prioritized, many teams use the CIS Controls as a practical on-ramp to, or the backbone underneath, a broader ISO 27001 or NIST CSF effort.

Where should we start with the CIS Controls?

Implement Implementation Group 1. IG1 is a defined, achievable set of essential-hygiene Safeguards that gives a small team real, measurable protection against common attacks without first deciding which of more than 150 Safeguards matter. Once IG1 is solid, expand to IG2 or IG3 as your data sensitivity and threat exposure grow.

See how your CIS Controls program would look in devguard.

The fastest way to know if this fits is a short conversation about how you run the CIS Controls today — which Safeguards are in place, where the tracking effort goes, and what moving it would involve. No deck unless you want one.

Book a conversation
Sign in
Start for free
Book a conversationStart for free