Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

CIS Controls: Your complete guide to the top 18

August 21, 2026
•
16 min read
Risk professionals discussing the top 18 CIS controls

In this article

  • Intro
  • What are CIS Controls?
  • CIS Controls v8 and v8.1
  • CIS Controls list
  • CIS Controls mapping by industry framework
  • CIS Controls implementation groups
  • CIS Controls assessment
  • Successfully manage IT risk with CIS Controls
  • How Diligent supports CIS Controls implementation
  • Frequently asked questions about CIS Controls
Jessica Donohue

Jessica Donohue

Senior Specialist

CIS Controls, or CIS Critical Security Controls for Effective Cyber Defense, are the baseline for effective IT risk management. No matter the size or the industry, organizations around the world can implement CIS controls to build more secure software and systems.

Remote work and cloud computing are standard in most organizations. The same applies to third-party vendors, and all three introduce new levels of risk. Through CIS compliance, organizations can mitigate the risks they face and protect their competitive advantage.

According to What Directors Think 2026 by Diligent Institute and Corporate Board Member, 63% of directors have incorporated cyber events and data breaches into crisis preparedness exercises, yet only 28% view a large-scale cybersecurity breach as a top organizational risk and just 12% say strengthening cybersecurity and data privacy defenses is a priority for 2026. The findings come from an online survey of more than 200 U.S. public company directors conducted in fall 2025.

That gap makes a prioritized framework such as the CIS Controls useful for turning crisis awareness into funded, measurable security action.

This guide covers how to put the CIS Controls to work:

  • What the CIS Controls are and how they differ from CIS Benchmarks
  • What changed in v8 and v8.1, and what it means for teams migrating from v7
  • All 18 Controls and how they map to PCI DSS, NIST, HIPAA, GDPR and ISO/IEC 27001
  • How Implementation Groups sequence adoption by risk profile and resources
  • Which CIS assessment and remediation tools to use, and in what order

What are CIS Controls?

CIS Controls are a set of clear actions for organizations to strengthen cybersecurity. The aim of CIS Controls is to provide clear, focused actions which will have an impact on severe threats to IT systems.

There are 18 different CIS Controls, which consist of a range of actions to improve resilience to cyberattacks. Their straightforward, effective actions help mitigate the potential damage from known cyber threats.

CIS critical security controls are a separate program by the Center for Internet Security but are referenced throughout CIS Benchmarks. Whereas CIS Benchmarks focus on the cybersecurity baseline of a specific system or product, CIS Controls are guidelines for the entire IT system. Organizations use CIS Controls to guide IT governance decisions and risk management processes.

The Center for Internet Security describes the CIS Controls as "a general set of recommended practices for securing a wide range of systems and devices," while CIS Benchmarks are "guidelines for hardening specific operating systems, middleware, software applications, and network devices."

In practice, the Controls tell an organization what to do across the whole environment; the Benchmarks specify how to configure a particular operating system, cloud platform, application or network device. The two programs meet at CIS Control 4, Secure Configuration of Enterprise Assets and Software. Organizations satisfy that Control in large part by applying the relevant Benchmarks. CIS Benchmarks include more than 100 Benchmarks across 25-plus vendor product families and cover cloud platforms and services, containers, databases, desktop and server software, mobile devices, network devices and operating systems. Teams should prioritize Benchmarks for internet-facing and business-critical systems first.

CIS Controls v8 and v8.1

CIS Controls improve cybersecurity and reduce the risk of cyberattacks. CIS Controls v8, or Version 8, updates the controls to focus on modern software and systems and the new risks that come with them.

The update addresses risks associated with these operating models. The goal of CIS Controls v8 is to prepare organizations to operate securely in a fully remote or hybrid capacity.

The current version is CIS Controls v8.1, released in June 2024. It retains the same 18 Controls and 153 Safeguards as v8 and made no changes to the Implementation Groups. V8.1 realigned its security-function mappings to match NIST Cybersecurity Framework 2.0. The mappings include the Govern function that NIST introduced in CSF 2.0. Organizations already working from v8 can therefore adopt v8.1 without restructuring their program, since the full v8.1 controls list keeps the same names and count.

CIS Controls v7 vs. v8

CIS released CIS Controls v8 in May 2021. The v8 CIS controls reduced the Top 20 to the Top 18, which is one major difference in CIS Controls v7 vs. v8. Organizations migrating from v7 should remap existing work rather than assume that two security priorities disappeared. V8 also reordered the Controls. In v7, the controls were categorized based on the different activities an organization might undertake. The new v8 controls are intended to be more flexible. Organizations can apply the guidelines to their unique environment. Version 8.1 continues from that structure and refines mappings rather than reworking the Controls themselves.

CIS Controls list

The Center for Internet Security designed the v8 CIS Controls to be simple and easy to implement. They're relevant in various environments and provide a more straightforward route for organizations to achieve CIS compliance. They also have a new focus on third-party vendors and cloud computing.

  1. Inventory and Control of Enterprise Assets: Understanding all the devices on your network can reduce your organization's risk. This includes device tracking and management that prevents unauthorized access to the organization's network.
  2. Inventory and Control of Software Assets: Knowing which systems your organization uses matters. Inventorying your software assets and implementing proper IT governance and management are necessary steps toward preventing unauthorized software from being installed on the network.
  3. Data Protection: Identify the data your organization processes and stores, then develop procedures for secure processing, handling and disposing of that data.
  4. Secure Configuration of Enterprise Assets and Software: Develop and manage hardware and software configurations to mitigate vulnerable settings across the organization's IT systems.
  5. Account Management: These controls ensure only authorized users can access company systems. These controls require processes that assign and manage credentials.
  6. Access Control Management: With credentials in place, organizations also need procedures that grant the right level of access to user, service and administrator-level accounts.
  7. Continuous Vulnerability Management: To improve cybersecurity, organizations should take a proactive approach to identify and fix vulnerabilities in the IT system. This requires an always-on approach to monitoring vulnerabilities and mitigating potential risks.
  8. Audit Log Management: Proactively detect and respond to cybersecurity incidents by performing internal audits of event logs.
  9. Email and Web Browser Protections: Strengthen email and browser systems against cyber threats.
  10. Malware Defenses: Ensure rapid response to malware attack and proactively limit the likelihood of installation and spread.
  11. Data Recovery: Implement processes to recover and periodically back up essential data and information.
  12. Network Infrastructure Management: Mitigate the risk of cyberattacks by ensuring your network infrastructure is secure. Ensure routers, firewalls and other devices on your network are properly configured to filter out suspicious activity.
  13. Network Monitoring and Defense: Set up a system that will alert you to both attempted and successful breaches. This includes ongoing network intrusion detection and security team audits to ensure all safeguards are in place.
  14. Security Awareness and Skills Training: Identify and develop the skills and knowledge the organization needs to apply cybersecurity best practices.
  15. Service Provider Management: Many organizations work with multiple third-party service providers. Doing so securely means configuring security processes that reduce the risk of attack via third-party access.
  16. Application Software Security: Identify and fix vulnerabilities in software the organization uses, then implement application controls to protect the network further.
  17. Incident Response Management: Develop and embed incident response processes across the organization to restore the IT system after serious cybersecurity incidents.
  18. Penetration Testing: Simulate a cyberattack to test the cybersecurity strengths of the organization.

CIS Controls mapping by industry framework

Different industries have different compliance frameworks. These frameworks often overlap with CIS Controls, which is why organizations need to map their CIS Controls according to their industry. The CIS provides guidance on how their controls interact with popular industry frameworks, including GDPR and HIPAA.

CIS Controls map to the following industry frameworks.

PCI DSS

Organizations that store, process or transmit payment-card data must meet applicable Payment Card Industry Data Security Standard (PCI DSS) requirements, many of which align with CIS Controls. By implementing CIS Controls, these organizations can also achieve compliance with certain PCI DSS requirements, including:

  • Firewall and Router Configuration
  • Patch Management
  • Change Control
  • Access Control

NIST and FISMA

The NIST framework oversees technology compliance. CIS Controls complement NIST CSF and can provide prioritized implementation actions within broader NIST-aligned risk programs that address the Federal Information Security Modernization Act (FISMA). CIS published a mapping white paper covering CIS Controls v8.1 and its Safeguards against NIST CSF 2.0 in June 2024. Teams running both can trace each Safeguard to the corresponding CSF 2.0 function. The mapping covers the Govern function. This mapping helps teams reuse control evidence and identify governance responsibilities, so they do not have to operate the frameworks as separate programs.

HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) creates a standard for protecting sensitive patient information. Its guidance contains many of the same requirements as the CIS Controls, since they both focus on mitigating the risk of breach and safeguarding data. CIS Controls also reach beyond HIPAA's requirements and can support a stronger cybersecurity program.

GDPR

Since May 2018, organizations that handle the data of E.U. citizens must follow the General Data Protection Regulation (GDPR). CIS Controls can support organizations as they achieve GDPR compliance, since CIS guidelines also focus on data privacy.

ISO/IEC 27001

CIS Controls are also used by organizations seeking ISO/IEC 27001 compliance. The International Organization for Standardization (ISO) created ISO/IEC 27001 to help with securing technologies. It focuses on many of the same cybersecurity standards as the CIS Controls, which is why CIS Controls are recognized as a benchmark for ISO compliance.

Understand CIS compliance

Learn how CIS Benchmarks and Controls support a structured cybersecurity compliance program.

CIS Controls implementation groups

CIS Controls are prioritized to help organizations perform actions with the most positive impact. These different priorities are referred to as "implementation groups" for CIS Controls. Organizational cybersecurity requirements vary with size and complexity. Organizations decide which group they belong to, which helps them understand which CIS Controls to implement according to their risk profile and available resources.

Implementation groups prioritize risk management and planning according to organizational risks and resources. They help organizations take focused actions suitable to their cybersecurity needs.

  1. Implementation group 1: smaller organizations with limited resources to allocate to cybersecurity. Data sensitivity may be low, and organizations will likely use off-the-shelf software and IT systems.
  2. Implementation group 2: larger organizations with multiple departments and more complex IT systems. There may be the need for cybersecurity compliance, and the organizations will likely be using enterprise-level IT systems and products.
  3. Implementation group 3: complex organizations with requirements for cybersecurity compliance. There may be cybersecurity specialists within the organization, with complex IT governance and risk management responsibilities. CIS Controls will help to reduce the risk of targeted cyber threats.

Each group builds on the one before it, and each organization determines its own placement based on its risk profile and available resources. The official Safeguard counts from CIS Implementation Groups make the cumulative structure concrete:

Implementation groupSafeguards addedCumulative totalTypical profile
IG15656"Essential cyber hygiene" for organizations with limited IT and cybersecurity expertise
IG274130Organizations with dedicated security personnel and moderate complexity
IG323153Enterprises facing regulatory oversight and sophisticated, targeted threats

Implementation Groups sequence adoption of the same Controls. Organizations can fund an achievable baseline first, then expand implementation as risk, expertise and regulatory obligations increase.

IG1 provides a meaningful baseline. CIS defense research found in its Community Defense Model v2.0 that implementing the IG1 Safeguards alone defends against 77% of the ATT&CK (sub-)techniques used across the top five attack types the model evaluated: malware, ransomware, web application hacking, insider privilege and misuse and targeted intrusions. Implementing all 153 Safeguards raises that coverage to 91%. This makes IG1 a meaningful operating baseline while supporting progression to the complete set when risk warrants it.

CIS Controls assessment

The CIS Controls Self Assessment Tool (CSAT) allows organizations to track their compliance with every individual CIS control. This includes whether they've implemented that control and how effective that implementation is. Built-in workflows also allow IT teams to configure their CSAT based on their Implementation Group, which informs an overall compliance score.

With CSAT, organizations can document, implement, automate and report on their CIS activities. They can also produce reports at any time to provide assurances to the board and shareholders.

CIS offers several tools for different programs and budgets:

  • CIS-Hosted CSAT is the free, web-based version of the self-assessment tool, available to any organization for non-commercial use. It tracks Controls implementation down to the individual Safeguard, cross-maps to NIST SP 800-53 and PCI DSS and supports anonymous comparison against industry peers.
  • CIS CSAT Pro is the on-premises version available through CIS SecureSuite membership. CIS also notes that its functions are now part of the CIS SecureSuite Platform alongside the CIS-CAT Pro Dashboard.
  • CIS-CAT Lite shifts the focus from Controls to configurations. The free version of CIS-CAT tools runs unlimited scans against select CIS Benchmarks and returns a compliance score.
  • CIS-CAT Pro Assessor, for SecureSuite members, automates assessment against 100-plus CIS Benchmarks. It maps its findings back to CIS Controls and Implementation Groups, so a failed configuration check can be read as a Safeguard gap rather than an isolated setting.
  • CIS Build Kits handle remediation rather than assessment. CIS Build Kit guidance describes them as resources that automate remediation of systems to the Benchmarks, delivered as Group Policy Objects for Windows and Bash shell scripts for Linux. Not every Benchmark setting can be applied through a Build Kit, and CIS advises modifying the templates to fit organizational policy before deployment.

A practical sequence is to use CSAT to identify program-level Safeguard gaps, run CIS-CAT against the affected technologies and prioritize failed checks by asset exposure and business importance. Teams can then test customized Build Kit remediation in a controlled environment before deployment, document exceptions and rescan systems to confirm that the intended configuration changes were applied successfully.

Successfully manage IT risk with CIS Controls

Organizations use CIS Controls to mitigate the risk of cyberattacks. But IT teams must also manage IT and third-party risk across dispersed systems.

According to the Q4 Business Risk Index by Diligent Institute and Corporate Board Member, technology risk is now the connective tissue across the entire risk register, in the words of Kira Ciccarelli, Senior Manager of Research at Diligent Institute. CIS Controls give organizations a practical way to connect specific cybersecurity actions with that broader risk picture.

Incident response matters because even one cyberattack can result in irrevocable damage to an organization's reputation and bottom line. Control 17, Incident Response Management, is built around the assumption that an organization will be hit at some point.

Pairing the Controls with proven IT risk management practices keeps the framework connected to day-to-day decisions. CIS tools can identify configuration and Safeguard gaps, but their outputs often remain dispersed across separate systems. Organizations still need to consolidate findings, prioritize them by business impact and report whether remediation is reducing risk.

How Diligent supports CIS Controls implementation

CIS tools assess an organization's status against the Controls and Benchmarks. Organizations must turn vulnerability-scanner findings into decisions that a risk committee or board can act on. Findings from cloud security tools and endpoint agents must also inform those decisions.

Diligent IT Risk Management addresses that challenge by unifying fragmented security data and translating technical findings into business context. It connects assets to vulnerabilities, applies automated risk scoring and control gap analysis and quantifies technical risks by business impact. Board-ready reporting then gives non-technical stakeholders a clearer view of priorities and remediation progress.

A shared asset record creates a repeatable workflow for comparing remediation priorities and showing how control performance changes from one reporting period to the next. Teams spend less time reconciling separate systems because scanner findings connect to the same assets as cloud security and endpoint findings. Those assets are tied to relevant controls and business impacts.

Growing companies can consolidate signals from multiple security tools and focus limited resources on the assets with the greatest business impact. Pre-IPO companies can establish consistent cyber governance and evidence processes for enterprise customers and public-market stakeholders. Large organizations can aggregate cyber risk across complex environments and give risk committees a consistent view of control performance.

For organizations mapping CIS Controls alongside PCI DSS, HIPAA, GDPR, ISO/IEC 27001 or NIST, Diligent IT Compliance supports cross-framework program management, continuous compliance monitoring, automated evidence collection and board-ready dashboards.

These products complement CSAT, CIS-CAT and CIS Benchmarks; they are not official CIS assessment tools. They carry technical outputs into enterprise risk and compliance reporting. Technical teams receive a shared view of priorities and progress, as do executives and boards.

Frequently asked questions about CIS Controls

Are CIS Controls mandatory?

No. CIS Controls are voluntary best practices rather than a regulation, and CIS guidance states that they do not replace regulatory, compliance or authorization schemes. Organizations often use their mappings to major frameworks as evidence of reasonable security, but implementing them does not guarantee regulatory compliance. A practical approach is to identify the requirements that apply to the organization first, then map relevant CIS Safeguards to those obligations and document any remaining compliance gaps separately.

How should an organization choose a CIS Implementation Group?

Choose an Implementation Group by assessing available expertise, data sensitivity, regulatory exposure and likely threats. IG1 contains 56 Safeguards for essential cyber hygiene, IG2 reaches 130 cumulatively for organizations with dedicated security staff and IG3 includes all 153 for organizations facing sophisticated threats or regulatory oversight. Because each group builds on the one before it, organizations can begin with the group that reflects their current risk profile and resources, then expand implementation as complexity and obligations increase.

What is the difference between CIS Controls and CIS Benchmarks?

CIS Controls define organization-wide security priorities through 18 Controls and 153 Safeguards. CIS Benchmarks provide technology-specific hardening settings and connect to Control 4, Secure Configuration of Enterprise Assets and Software. Organizations can use the Controls to decide which security outcomes to prioritize, then apply relevant Benchmarks to configure specific operating systems, cloud platforms, applications and network devices. The CIS Benchmarks FAQ describes Level 2 profiles as defense in depth for environments where security is paramount.

Should an organization use CIS Controls or NIST CSF?

Use them together. CIS Controls provide prioritized, prescriptive actions, while NIST CSF supplies a broader structure for governing and organizing cybersecurity risk. The official mapping white paper maps CIS Controls v8.1 directly to NIST CSF 2.0 and covers the Govern function. Teams can use that mapping to coordinate evidence, assign ownership and connect individual Safeguards to broader risk outcomes rather than maintaining two disconnected programs or duplicating the same assessment work.

What do CIS-CAT and CIS Build Kits do?

CIS-CAT assesses configurations against CIS Benchmarks and reports a compliance score, while Build Kits support remediation of identified configuration gaps. CIS-CAT Lite covers select Benchmarks, and Pro Assessor supports 100-plus Benchmarks for SecureSuite members. CIS Build Kits provide Windows Group Policy Objects and Linux Bash scripts that teams should tailor and test before deployment, then rescan with CIS-CAT to confirm the changes applied.

Ready to connect CIS control gaps to business risk? Schedule a demo of Diligent IT Risk Management.