The CIS Critical Security Controls are published by the Center for Internet Security, a nonprofit that also maintains the CIS Benchmarks for secure configuration. Where frameworks such as ISO 27001 tell you to build a management system and decide your own controls, the CIS Controls start from the other end: a prioritized list of specific defensive actions drawn from how real attacks succeed. That makes them a favorite with IT leads who need to know what to do first on Monday.
Version 8 was released in 2021 and reorganized the controls around activities rather than who manages a device, reflecting cloud, remote work, and outsourced services. It contains 18 controls and 153 safeguards. CIS published version 8.1 in June 2024, which added a Govern security function to align with NIST CSF 2.0, refined safeguard wording and asset classes, and expanded the glossary. The core structure of 18 controls stayed the same, so a v8 program carries forward to v8.1 with targeted updates rather than a rebuild.
Implementation Groups: the part people skip
Every safeguard is assigned to one of three Implementation Groups. The groups are cumulative: IG2 includes all of IG1, and IG3 includes everything. They exist so an organization can pick a realistic target based on its resources, the sensitivity of its data, and the attackers it is likely to face, instead of treating all 153 safeguards as equally urgent.
The 18 controls
CIS Critical Security Controls v8
The ordering is intentional. Controls 1 and 2 come first because you cannot configure, patch, monitor, or recover assets you do not know about. Many later safeguards assume those inventories exist, so an organization that jumps to network monitoring before it has an asset list usually ends up with alerts it cannot attribute to an owner.
A 12-month path to IG1
The sequence is a suggestion, not a mandate from CIS. Adjust it to your gaps: a company with mature identity tooling may finish Controls 5 and 6 in weeks, while one with a large unmanaged endpoint fleet will spend longer on Control 1. Keep network infrastructure up to date (Control 12) alongside patching. Controls 13, 16, and 18 have no IG1 safeguards and come into play as you move toward IG2 and IG3.
Evidence that proves a safeguard is in place
The CIS Controls are not a certification, so there is no mandated artefact list. But customers, insurers, auditors, and boards may still ask you to show CIS alignment, and self-assessments are only as credible as the evidence behind them. CIS offers the CIS Controls Self Assessment Tool (CSAT) for tracking implementation. The records below are what a reviewer will reasonably ask for.
Records worth keeping
- Asset and software inventory exports with the date they were generated and the sources they draw from
- Configuration baselines, such as CIS Benchmark profiles, plus compliance scan results against them
- MFA enforcement settings for externally exposed applications, remote access, and administrative accounts
- Vulnerability scan reports with remediation tickets showing closure within your defined timelines
- Backup job logs and the results of periodic restore tests
- Audit log configuration and retention settings
- Security awareness training completion records
- A service provider inventory and the incident response plan with named roles
Mistakes that stall CIS programs
- Targeting IG3 on day one. A 153-safeguard backlog overwhelms small teams. Finish IG1, then expand.
- Scoring by policy instead of coverage. Having an MFA policy is not the safeguard; MFA enforced across the in-scope accounts is.
- Inventories that drift. A one-time spreadsheet goes stale within weeks. Inventories need automated feeds and reconciliation.
- Confusing Controls with Benchmarks. The CIS Benchmarks are configuration guides for specific products. Control 4 expects a secure configuration process, which Benchmarks can support.
- Treating it as a certification. CIS alignment does not replace SOC 2 or ISO 27001 where customers require those, though it strengthens both.
How the CIS Controls map to other frameworks
CIS publishes mappings from the Controls to a range of frameworks, including NIST CSF 2.0, NIST SP 800-53, ISO/IEC 27001, and PCI DSS. In practice, a CIS program gives you strong technical evidence for the operational controls of those frameworks, while they add the governance, risk assessment, and management system layers CIS does not emphasize. The evidence reuse article explains how to avoid collecting the same proof twice.
How Asurvo helps
Asurvo includes CIS Controls v8 with Implementation Group scoping, so you can filter the safeguard list to IG1, IG2, or IG3 and track progress against the target you choose. Native integrations with systems such as Okta, Entra ID, CrowdStrike, Defender, Wazuh, Qualys, and major cloud platforms feed inventory, configuration, and vulnerability evidence continuously, and AI cross-mapping links each safeguard to NIST CSF and ISO 27001. Teams starting out can pair it with the free access control policy template.