Security · Center for Internet Security
CIS Critical Security Controls v8.1
Fully implemented, the Controls defend against roughly 86% of MITRE ATT&CK techniques (CIS CDM v2.0). Our free checks score against IG1.
Who it applies to
The businesses that carry CIS Controls, and the pages written for them.
Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.
Which packages satisfy it
Cyber and Data Protection Assessment
Any business of 10 to 500 people that has never had a real assessment, or has not had one in a year
SOC 2 Readiness: Type 1 and Type 2
SaaS, AI and technology companies of 5 to 300 people, and professional firms whose clients require it
Practice Cybersecurity, Data Protection and HIPAA Package
Medical and dental practices, clinics, surgery centers, hospital departments and the business associates that serve them
What it asks for
In plain English, what CIS Controls expects you to have in place.
- Implementation Group 1 firstThe essential cyber hygiene set that every organization should have, which our free Cyber Hygiene Test scores against.
- Inventory of assets and softwareControls 1 and 2: know what you have, remove what you do not use.
- Data protection and secure configurationControls 3 and 4: classify, encrypt, dispose, and harden by default.
- Account and access managementControls 5 and 6: unique accounts, MFA, least privilege, access removed on exit.
- Vulnerability and log managementControls 7 and 8: patch on a rhythm, log enough to investigate.
- Email, malware, recovery, training, incident responseControls 9, 10, 11, 14 and 17: the ones that decide whether a Tuesday morning click becomes a bad month.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
Questions we get about CIS Controls
Do you certify CIS Controls compliance?
Where do we start with CIS Controls?
We also need other frameworks. Do we do CIS Controls separately?
Also in security: SOC 2 · NIST CSF 2.0 · ISO 27001 · every framework by industry
Next step
Thirty minutes, an engineer, a written scope for CIS Controls.
Book the demo and see how one control set carries CIS Controls and everything else you owe. Or leave your details and an engineer replies within one business day.