What Are the CIS Critical Security Controls?

Also called: CIS Controls, CIS Top 20

Related problems: Need a practical security baseline, not a long framework document; Cyber insurer's application asks which controls we have in place; Don't know which security projects to tackle first with a small team; Want a way to compare MSPs' and security providers' coverage

The CIS Critical Security Controls, usually called the CIS Controls, are a prioritized set of cybersecurity safeguards published by the Center for Internet Security (CIS), a nonprofit. Rather than describing every possible security activity, they list specific actions that defend against common attacks, ordered and grouped so that an organization with limited staff knows where to start. The current version has 18 Controls, covering areas from asset inventory and secure configuration to incident response and penetration testing, broken into specific Safeguards and three Implementation Groups.

At a glance

  • The Controls are free to use and published by a nonprofit, not by a regulator.
  • The current version has 18 Controls made up of specific Safeguards.
  • Safeguards are grouped into three Implementation Groups (IG1 to IG3), and each group builds on the one before.
  • IG1 is described by CIS as essential cyber hygiene, a baseline for organizations of all sizes.
  • There is no official certification; organizations self-assess or use a third-party assessor.

What problem it solves

Broad frameworks tell you what outcomes to achieve but leave smaller teams asking where to begin. Mid-market IT teams often have a long list of possible security projects and limited time. The CIS Controls answer the “what first?” question by ordering safeguards around the attacks most organizations actually face, and by splitting them into groups sized to an organization’s resources.

The Controls also give a common language. Cyber insurers, auditors, MSPs and security providers often map their questions or services to them, so a buyer can compare coverage and spot gaps instead of reading each provider’s own terminology.

How it works

The Controls. The 18 Controls cover enterprise asset inventory, software inventory, data protection, secure configuration, account management, access control management, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, data recovery, network infrastructure management, network monitoring and defense, security awareness and skills training, service provider management, application software security, incident response management and penetration testing.

Safeguards. Each Control contains specific Safeguards, such as maintaining a software inventory or enforcing multi-factor authentication for remote access, which are concrete enough to check.

Implementation Groups. Safeguards are assigned to IG1, IG2 or IG3. An organization picks its target group by risk profile and resources, then works through the Safeguards in that group.

Assessment. Organizations score their implementation, often with CIS’s free assessment tool or a GRC platform, and track progress over time. Outside assessors can verify. Results feed a vulnerability management program, an IT asset management (ITAM) effort, security awareness training (SAT) and periodic penetration testing.

Mappings. CIS publishes mappings to other frameworks, so work on the Controls can support programs built on frameworks such as the NIST CSF or ISO/IEC 27001.

Implementation Groups

The groups are cumulative: IG2 includes everything in IG1, and IG3 includes all Safeguards. Which group fits is your decision; CIS gives guidance, not a mandate.

Group Who it is aimed at What’s required to reach it Typical evidence
IG1 Organizations of every size; small and mid-sized organizations with limited IT and security expertise often start here Implement the IG1 Safeguards (CIS describes these as essential cyber hygiene); self-assessed or third-party assessed Self-assessment scores, asset and software inventories, MFA and backup evidence
IG2 Organizations with sensitive client or company data, multiple departments or dedicated IT staff IG1 plus additional IG2 Safeguards; self-assessed or third-party assessed Assessment report, vulnerability management records, log review and configuration standards
IG3 Organizations with dedicated security specialists whose systems and data face regulatory scrutiny and more sophisticated attacks All Safeguards, including the most advanced ones; often third-party assessed Independent assessment, penetration test reports, detailed program documentation

When it matters for buyers

  • When building a security baseline with a small team. IG1 gives a defined starting list.
  • When completing cyber insurance applications. Many questions line up with IG1 Safeguards such as MFA, backups and endpoint protection; see cyber insurance.
  • When choosing an MSP or managed security provider. Ask which Safeguards the service covers and which stay with you.
  • When a customer asks what framework you follow. The CIS Controls are widely recognized, especially for mid-market organizations.

Our governance, risk and compliance and vulnerability management overviews cover services that assess and implement the Controls.

Questions to ask vendors

  • Which CIS Safeguards does your service implement or monitor, and which remain our responsibility?
  • Can you map your service to a specific Implementation Group, and show the mapping?
  • Do you harden systems using CIS Benchmarks or another configuration standard?
  • What reporting will show our progress against the Controls over time?
  • If you assess us, will you use CIS’s own tools or your own method, and can we keep the results?
  • How do your own internal controls compare with the Controls you recommend to us?

How it differs from the NIST Cybersecurity Framework

The NIST Cybersecurity Framework (NIST CSF) describes cybersecurity outcomes at a high level, organized into functions such as Govern, Identify, Protect, Detect, Respond and Recover, and leaves the choice of specific controls to you. The CIS Controls are more prescriptive: a specific, prioritized list of safeguards. Many organizations use both, with the CSF to structure the program and report to leadership, and the CIS Controls as the practical checklist. Neither is a certifiable standard in the way ISO/IEC 27001 is.

The CIS Controls are also different from CIS Benchmarks, which are detailed secure-configuration guides for specific products. Benchmarks are one way to implement the secure configuration Control.

Frequently Asked Questions

How many CIS Controls are there?
The current version has 18 Controls, broken down into a larger number of specific Safeguards. Earlier versions had 20 Controls, which is why you may still hear 'CIS Top 20'. Check the Center for Internet Security site for the latest version.
Can we get certified against the CIS Controls?
There is no official CIS certification for an organization's implementation. Organizations self-assess, often using CIS's free tools, or hire a third party to assess them, and the result is usually reported as coverage of a given Implementation Group.
What is the difference between the CIS Controls and CIS Benchmarks?
The CIS Controls are a program-level list of what to do across your environment. CIS Benchmarks are detailed configuration guides for specific products, such as an operating system or cloud platform. Secure configuration is one of the Controls, and Benchmarks are a common way to meet it.
Which Implementation Group should we aim for?
CIS describes Implementation Group 1 as essential cyber hygiene and a starting point for every organization. Organizations with more sensitive data, regulatory obligations or dedicated security staff typically work toward Implementation Group 2, and those with security specialists, heavily regulated data or more sophisticated attackers toward Implementation Group 3.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.