CIS Controls
A prioritized, practical answer to "what should we secure first?"
What it is
The CIS Critical Security Controls are a consensus-built, prioritized set of best practices maintained by the Center for Internet Security. The current release, v8.1 (June 2024), organizes 153 safeguards across 18 controls and adds a Govern function aligned to NIST CSF 2.0. Safeguards are grouped into three Implementation Groups: IG1 (56 safeguards — "essential cyber hygiene" for small orgs), IG2, and IG3 (full set, for high-risk/regulated orgs).
Certifiable?
Not directly — organizations align with the Controls rather than certify to them.
Where it's used
Universal starting baseline, especially valuable for SMBs that find NIST 800-53 too heavy.
Effort level
Scalable: start at IG1 in ~90 days, grow into IG2/IG3 over 12–18 months.
Typical trigger
A team wants concrete, ordered next steps rather than an abstract framework.
Related frameworks
Maps to SOC 2, ISO 27001, NIST CSF, PCI DSS, HIPAA — one assessment can produce evidence for several.
Why it matters
CIS Controls give teams a prioritized, consensus-driven list of security actions. Instead of asking 'what should we do?' you get an ordered answer: start here, then here, then here. It's the most practical on-ramp to structured security for any team size.
When is it needed?
When your team needs a concrete starting point for building a security program, when you want to map one effort to multiple compliance targets, or when NIST 800-53 feels too heavy for your current maturity.
Use cases
- SMBs building their first security program
- Teams prioritizing security investments
- Organizations preparing for ISO 27001 or SOC 2
- Managed service providers standardizing client baselines
- Incident response teams identifying control gaps post-breach
Who asks for it?
- Internal security leadership setting roadmaps
- Cyber insurance providers assessing maturity
- Auditors looking for evidence of due care
- MSSPs and consultants recommending starting points
- Regulators accepting CIS as a recognized baseline
Benefits
- Prioritized — Implementation Groups let you start small and grow
- Maps to major frameworks: ISO 27001, SOC 2, NIST, PCI DSS, HIPAA
- Community-maintained and updated regularly
- Free to use — no licensing cost
- Practical and technical rather than abstract
- Widely accepted as evidence of 'reasonable security'
Legal requirements
Not legally required itself, but increasingly referenced as a reasonable security baseline by regulators, courts, and insurance providers when assessing due care.
Key control areas
Want to see how Compscan maps your environment to CIS Controls?