The CIS Critical Security Controls, usually called the CIS Controls, are a prioritized set of cybersecurity safeguards published by the Center for Internet Security (CIS), a nonprofit. Rather than describing every possible security activity, they list specific actions that defend against common attacks, ordered and grouped so that an organization with limited staff knows where to start. The current version has 18 Controls, covering areas from asset inventory and secure configuration to incident response and penetration testing, broken into specific Safeguards and three Implementation Groups.
At a glance
- The Controls are free to use and published by a nonprofit, not by a regulator.
- The current version has 18 Controls made up of specific Safeguards.
- Safeguards are grouped into three Implementation Groups (IG1 to IG3), and each group builds on the one before.
- IG1 is described by CIS as essential cyber hygiene, a baseline for organizations of all sizes.
- There is no official certification; organizations self-assess or use a third-party assessor.
What problem it solves
Broad frameworks tell you what outcomes to achieve but leave smaller teams asking where to begin. Mid-market IT teams often have a long list of possible security projects and limited time. The CIS Controls answer the “what first?” question by ordering safeguards around the attacks most organizations actually face, and by splitting them into groups sized to an organization’s resources.
The Controls also give a common language. Cyber insurers, auditors, MSPs and security providers often map their questions or services to them, so a buyer can compare coverage and spot gaps instead of reading each provider’s own terminology.
How it works
The Controls. The 18 Controls cover enterprise asset inventory, software inventory, data protection, secure configuration, account management, access control management, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, data recovery, network infrastructure management, network monitoring and defense, security awareness and skills training, service provider management, application software security, incident response management and penetration testing.
Safeguards. Each Control contains specific Safeguards, such as maintaining a software inventory or enforcing multi-factor authentication for remote access, which are concrete enough to check.
Implementation Groups. Safeguards are assigned to IG1, IG2 or IG3. An organization picks its target group by risk profile and resources, then works through the Safeguards in that group.
Assessment. Organizations score their implementation, often with CIS’s free assessment tool or a GRC platform, and track progress over time. Outside assessors can verify. Results feed a vulnerability management program, an IT asset management (ITAM) effort, security awareness training (SAT) and periodic penetration testing.
Mappings. CIS publishes mappings to other frameworks, so work on the Controls can support programs built on frameworks such as the NIST CSF or ISO/IEC 27001.
Implementation Groups
The groups are cumulative: IG2 includes everything in IG1, and IG3 includes all Safeguards. Which group fits is your decision; CIS gives guidance, not a mandate.
| Group | Who it is aimed at | What’s required to reach it | Typical evidence |
|---|---|---|---|
| IG1 | Organizations of every size; small and mid-sized organizations with limited IT and security expertise often start here | Implement the IG1 Safeguards (CIS describes these as essential cyber hygiene); self-assessed or third-party assessed | Self-assessment scores, asset and software inventories, MFA and backup evidence |
| IG2 | Organizations with sensitive client or company data, multiple departments or dedicated IT staff | IG1 plus additional IG2 Safeguards; self-assessed or third-party assessed | Assessment report, vulnerability management records, log review and configuration standards |
| IG3 | Organizations with dedicated security specialists whose systems and data face regulatory scrutiny and more sophisticated attacks | All Safeguards, including the most advanced ones; often third-party assessed | Independent assessment, penetration test reports, detailed program documentation |
When it matters for buyers
- When building a security baseline with a small team. IG1 gives a defined starting list.
- When completing cyber insurance applications. Many questions line up with IG1 Safeguards such as MFA, backups and endpoint protection; see cyber insurance.
- When choosing an MSP or managed security provider. Ask which Safeguards the service covers and which stay with you.
- When a customer asks what framework you follow. The CIS Controls are widely recognized, especially for mid-market organizations.
Our governance, risk and compliance and vulnerability management overviews cover services that assess and implement the Controls.
Questions to ask vendors
- Which CIS Safeguards does your service implement or monitor, and which remain our responsibility?
- Can you map your service to a specific Implementation Group, and show the mapping?
- Do you harden systems using CIS Benchmarks or another configuration standard?
- What reporting will show our progress against the Controls over time?
- If you assess us, will you use CIS’s own tools or your own method, and can we keep the results?
- How do your own internal controls compare with the Controls you recommend to us?
How it differs from the NIST Cybersecurity Framework
The NIST Cybersecurity Framework (NIST CSF) describes cybersecurity outcomes at a high level, organized into functions such as Govern, Identify, Protect, Detect, Respond and Recover, and leaves the choice of specific controls to you. The CIS Controls are more prescriptive: a specific, prioritized list of safeguards. Many organizations use both, with the CSF to structure the program and report to leadership, and the CIS Controls as the practical checklist. Neither is a certifiable standard in the way ISO/IEC 27001 is.
The CIS Controls are also different from CIS Benchmarks, which are detailed secure-configuration guides for specific products. Benchmarks are one way to implement the secure configuration Control.
