Skip to content
03/14FrameworkSupported in Compscan

CIS Controls

A prioritized, practical answer to "what should we secure first?"

What it is

The CIS Critical Security Controls are a consensus-built, prioritized set of best practices maintained by the Center for Internet Security. The current release, v8.1 (June 2024), organizes 153 safeguards across 18 controls and adds a Govern function aligned to NIST CSF 2.0. Safeguards are grouped into three Implementation Groups: IG1 (56 safeguards — "essential cyber hygiene" for small orgs), IG2, and IG3 (full set, for high-risk/regulated orgs).

Certifiable?

Not directly — organizations align with the Controls rather than certify to them.

Where it's used

Universal starting baseline, especially valuable for SMBs that find NIST 800-53 too heavy.

Effort level

Scalable: start at IG1 in ~90 days, grow into IG2/IG3 over 12–18 months.

Typical trigger

A team wants concrete, ordered next steps rather than an abstract framework.

Related frameworks

Maps to SOC 2, ISO 27001, NIST CSF, PCI DSS, HIPAA — one assessment can produce evidence for several.

Why it matters

CIS Controls give teams a prioritized, consensus-driven list of security actions. Instead of asking 'what should we do?' you get an ordered answer: start here, then here, then here. It's the most practical on-ramp to structured security for any team size.

When is it needed?

When your team needs a concrete starting point for building a security program, when you want to map one effort to multiple compliance targets, or when NIST 800-53 feels too heavy for your current maturity.

Use cases

  • SMBs building their first security program
  • Teams prioritizing security investments
  • Organizations preparing for ISO 27001 or SOC 2
  • Managed service providers standardizing client baselines
  • Incident response teams identifying control gaps post-breach

Who asks for it?

  • Internal security leadership setting roadmaps
  • Cyber insurance providers assessing maturity
  • Auditors looking for evidence of due care
  • MSSPs and consultants recommending starting points
  • Regulators accepting CIS as a recognized baseline

Benefits

  • Prioritized — Implementation Groups let you start small and grow
  • Maps to major frameworks: ISO 27001, SOC 2, NIST, PCI DSS, HIPAA
  • Community-maintained and updated regularly
  • Free to use — no licensing cost
  • Practical and technical rather than abstract
  • Widely accepted as evidence of 'reasonable security'

Legal requirements

Not legally required itself, but increasingly referenced as a reasonable security baseline by regulators, courts, and insurance providers when assessing due care.

Key control areas

Inventory of enterprise and software assets
Data protection and recovery
Secure configuration of assets
Account and access control management
Continuous vulnerability management
Audit log management
Email and web browser protections
Malware defenses
Network monitoring and defense
Security awareness training

Want to see how Compscan maps your environment to CIS Controls?