
CIS Controls, or CIS Critical Security Controls for Effective Cyber Defense, are the baseline for effective IT risk management. No matter the size or the industry, organizations around the world can implement CIS controls to build more secure software and systems.
Remote work and cloud computing are standard in most organizations. The same applies to third-party vendors, and all three introduce new levels of risk. Through CIS compliance, organizations can mitigate the risks they face and protect their competitive advantage.
According to What Directors Think 2026 by Diligent Institute and Corporate Board Member, 63% of directors have incorporated cyber events and data breaches into crisis preparedness exercises, yet only 28% view a large-scale cybersecurity breach as a top organizational risk and just 12% say strengthening cybersecurity and data privacy defenses is a priority for 2026. The findings come from an online survey of more than 200 U.S. public company directors conducted in fall 2025.
That gap makes a prioritized framework such as the CIS Controls useful for turning crisis awareness into funded, measurable security action.
This guide covers how to put the CIS Controls to work:
CIS Controls are a set of clear actions for organizations to strengthen cybersecurity. The aim of CIS Controls is to provide clear, focused actions which will have an impact on severe threats to IT systems.
There are 18 different CIS Controls, which consist of a range of actions to improve resilience to cyberattacks. Their straightforward, effective actions help mitigate the potential damage from known cyber threats.
CIS critical security controls are a separate program by the Center for Internet Security but are referenced throughout CIS Benchmarks. Whereas CIS Benchmarks focus on the cybersecurity baseline of a specific system or product, CIS Controls are guidelines for the entire IT system. Organizations use CIS Controls to guide IT governance decisions and risk management processes.
The Center for Internet Security describes the CIS Controls as "a general set of recommended practices for securing a wide range of systems and devices," while CIS Benchmarks are "guidelines for hardening specific operating systems, middleware, software applications, and network devices."
In practice, the Controls tell an organization what to do across the whole environment; the Benchmarks specify how to configure a particular operating system, cloud platform, application or network device. The two programs meet at CIS Control 4, Secure Configuration of Enterprise Assets and Software. Organizations satisfy that Control in large part by applying the relevant Benchmarks. CIS Benchmarks include more than 100 Benchmarks across 25-plus vendor product families and cover cloud platforms and services, containers, databases, desktop and server software, mobile devices, network devices and operating systems. Teams should prioritize Benchmarks for internet-facing and business-critical systems first.
CIS Controls improve cybersecurity and reduce the risk of cyberattacks. CIS Controls v8, or Version 8, updates the controls to focus on modern software and systems and the new risks that come with them.
The update addresses risks associated with these operating models. The goal of CIS Controls v8 is to prepare organizations to operate securely in a fully remote or hybrid capacity.
The current version is CIS Controls v8.1, released in June 2024. It retains the same 18 Controls and 153 Safeguards as v8 and made no changes to the Implementation Groups. V8.1 realigned its security-function mappings to match NIST Cybersecurity Framework 2.0. The mappings include the Govern function that NIST introduced in CSF 2.0. Organizations already working from v8 can therefore adopt v8.1 without restructuring their program, since the full v8.1 controls list keeps the same names and count.
CIS released CIS Controls v8 in May 2021. The v8 CIS controls reduced the Top 20 to the Top 18, which is one major difference in CIS Controls v7 vs. v8. Organizations migrating from v7 should remap existing work rather than assume that two security priorities disappeared. V8 also reordered the Controls. In v7, the controls were categorized based on the different activities an organization might undertake. The new v8 controls are intended to be more flexible. Organizations can apply the guidelines to their unique environment. Version 8.1 continues from that structure and refines mappings rather than reworking the Controls themselves.
The Center for Internet Security designed the v8 CIS Controls to be simple and easy to implement. They're relevant in various environments and provide a more straightforward route for organizations to achieve CIS compliance. They also have a new focus on third-party vendors and cloud computing.
Different industries have different compliance frameworks. These frameworks often overlap with CIS Controls, which is why organizations need to map their CIS Controls according to their industry. The CIS provides guidance on how their controls interact with popular industry frameworks, including GDPR and HIPAA.
CIS Controls map to the following industry frameworks.
Organizations that store, process or transmit payment-card data must meet applicable Payment Card Industry Data Security Standard (PCI DSS) requirements, many of which align with CIS Controls. By implementing CIS Controls, these organizations can also achieve compliance with certain PCI DSS requirements, including:
The NIST framework oversees technology compliance. CIS Controls complement NIST CSF and can provide prioritized implementation actions within broader NIST-aligned risk programs that address the Federal Information Security Modernization Act (FISMA). CIS published a mapping white paper covering CIS Controls v8.1 and its Safeguards against NIST CSF 2.0 in June 2024. Teams running both can trace each Safeguard to the corresponding CSF 2.0 function. The mapping covers the Govern function. This mapping helps teams reuse control evidence and identify governance responsibilities, so they do not have to operate the frameworks as separate programs.
The Health Insurance Portability and Accountability Act (HIPAA) creates a standard for protecting sensitive patient information. Its guidance contains many of the same requirements as the CIS Controls, since they both focus on mitigating the risk of breach and safeguarding data. CIS Controls also reach beyond HIPAA's requirements and can support a stronger cybersecurity program.
Since May 2018, organizations that handle the data of E.U. citizens must follow the General Data Protection Regulation (GDPR). CIS Controls can support organizations as they achieve GDPR compliance, since CIS guidelines also focus on data privacy.
CIS Controls are also used by organizations seeking ISO/IEC 27001 compliance. The International Organization for Standardization (ISO) created ISO/IEC 27001 to help with securing technologies. It focuses on many of the same cybersecurity standards as the CIS Controls, which is why CIS Controls are recognized as a benchmark for ISO compliance.
CIS Controls are prioritized to help organizations perform actions with the most positive impact. These different priorities are referred to as "implementation groups" for CIS Controls. Organizational cybersecurity requirements vary with size and complexity. Organizations decide which group they belong to, which helps them understand which CIS Controls to implement according to their risk profile and available resources.
Implementation groups prioritize risk management and planning according to organizational risks and resources. They help organizations take focused actions suitable to their cybersecurity needs.
Each group builds on the one before it, and each organization determines its own placement based on its risk profile and available resources. The official Safeguard counts from CIS Implementation Groups make the cumulative structure concrete:
| Implementation group | Safeguards added | Cumulative total | Typical profile |
|---|---|---|---|
| IG1 | 56 | 56 | "Essential cyber hygiene" for organizations with limited IT and cybersecurity expertise |
| IG2 | 74 | 130 | Organizations with dedicated security personnel and moderate complexity |
| IG3 | 23 | 153 | Enterprises facing regulatory oversight and sophisticated, targeted threats |
Implementation Groups sequence adoption of the same Controls. Organizations can fund an achievable baseline first, then expand implementation as risk, expertise and regulatory obligations increase.
IG1 provides a meaningful baseline. CIS defense research found in its Community Defense Model v2.0 that implementing the IG1 Safeguards alone defends against 77% of the ATT&CK (sub-)techniques used across the top five attack types the model evaluated: malware, ransomware, web application hacking, insider privilege and misuse and targeted intrusions. Implementing all 153 Safeguards raises that coverage to 91%. This makes IG1 a meaningful operating baseline while supporting progression to the complete set when risk warrants it.
The CIS Controls Self Assessment Tool (CSAT) allows organizations to track their compliance with every individual CIS control. This includes whether they've implemented that control and how effective that implementation is. Built-in workflows also allow IT teams to configure their CSAT based on their Implementation Group, which informs an overall compliance score.
With CSAT, organizations can document, implement, automate and report on their CIS activities. They can also produce reports at any time to provide assurances to the board and shareholders.
CIS offers several tools for different programs and budgets:
A practical sequence is to use CSAT to identify program-level Safeguard gaps, run CIS-CAT against the affected technologies and prioritize failed checks by asset exposure and business importance. Teams can then test customized Build Kit remediation in a controlled environment before deployment, document exceptions and rescan systems to confirm that the intended configuration changes were applied successfully.
Organizations use CIS Controls to mitigate the risk of cyberattacks. But IT teams must also manage IT and third-party risk across dispersed systems.
According to the Q4 Business Risk Index by Diligent Institute and Corporate Board Member, technology risk is now the connective tissue across the entire risk register, in the words of Kira Ciccarelli, Senior Manager of Research at Diligent Institute. CIS Controls give organizations a practical way to connect specific cybersecurity actions with that broader risk picture.
Incident response matters because even one cyberattack can result in irrevocable damage to an organization's reputation and bottom line. Control 17, Incident Response Management, is built around the assumption that an organization will be hit at some point.
Pairing the Controls with proven IT risk management practices keeps the framework connected to day-to-day decisions. CIS tools can identify configuration and Safeguard gaps, but their outputs often remain dispersed across separate systems. Organizations still need to consolidate findings, prioritize them by business impact and report whether remediation is reducing risk.
CIS tools assess an organization's status against the Controls and Benchmarks. Organizations must turn vulnerability-scanner findings into decisions that a risk committee or board can act on. Findings from cloud security tools and endpoint agents must also inform those decisions.
Diligent IT Risk Management addresses that challenge by unifying fragmented security data and translating technical findings into business context. It connects assets to vulnerabilities, applies automated risk scoring and control gap analysis and quantifies technical risks by business impact. Board-ready reporting then gives non-technical stakeholders a clearer view of priorities and remediation progress.
A shared asset record creates a repeatable workflow for comparing remediation priorities and showing how control performance changes from one reporting period to the next. Teams spend less time reconciling separate systems because scanner findings connect to the same assets as cloud security and endpoint findings. Those assets are tied to relevant controls and business impacts.
Growing companies can consolidate signals from multiple security tools and focus limited resources on the assets with the greatest business impact. Pre-IPO companies can establish consistent cyber governance and evidence processes for enterprise customers and public-market stakeholders. Large organizations can aggregate cyber risk across complex environments and give risk committees a consistent view of control performance.
For organizations mapping CIS Controls alongside PCI DSS, HIPAA, GDPR, ISO/IEC 27001 or NIST, Diligent IT Compliance supports cross-framework program management, continuous compliance monitoring, automated evidence collection and board-ready dashboards.
These products complement CSAT, CIS-CAT and CIS Benchmarks; they are not official CIS assessment tools. They carry technical outputs into enterprise risk and compliance reporting. Technical teams receive a shared view of priorities and progress, as do executives and boards.
No. CIS Controls are voluntary best practices rather than a regulation, and CIS guidance states that they do not replace regulatory, compliance or authorization schemes. Organizations often use their mappings to major frameworks as evidence of reasonable security, but implementing them does not guarantee regulatory compliance. A practical approach is to identify the requirements that apply to the organization first, then map relevant CIS Safeguards to those obligations and document any remaining compliance gaps separately.
Choose an Implementation Group by assessing available expertise, data sensitivity, regulatory exposure and likely threats. IG1 contains 56 Safeguards for essential cyber hygiene, IG2 reaches 130 cumulatively for organizations with dedicated security staff and IG3 includes all 153 for organizations facing sophisticated threats or regulatory oversight. Because each group builds on the one before it, organizations can begin with the group that reflects their current risk profile and resources, then expand implementation as complexity and obligations increase.
CIS Controls define organization-wide security priorities through 18 Controls and 153 Safeguards. CIS Benchmarks provide technology-specific hardening settings and connect to Control 4, Secure Configuration of Enterprise Assets and Software. Organizations can use the Controls to decide which security outcomes to prioritize, then apply relevant Benchmarks to configure specific operating systems, cloud platforms, applications and network devices. The CIS Benchmarks FAQ describes Level 2 profiles as defense in depth for environments where security is paramount.
Use them together. CIS Controls provide prioritized, prescriptive actions, while NIST CSF supplies a broader structure for governing and organizing cybersecurity risk. The official mapping white paper maps CIS Controls v8.1 directly to NIST CSF 2.0 and covers the Govern function. Teams can use that mapping to coordinate evidence, assign ownership and connect individual Safeguards to broader risk outcomes rather than maintaining two disconnected programs or duplicating the same assessment work.
CIS-CAT assesses configurations against CIS Benchmarks and reports a compliance score, while Build Kits support remediation of identified configuration gaps. CIS-CAT Lite covers select Benchmarks, and Pro Assessor supports 100-plus Benchmarks for SecureSuite members. CIS Build Kits provide Windows Group Policy Objects and Linux Bash scripts that teams should tailor and test before deployment, then rescan with CIS-CAT to confirm the changes applied.
Ready to connect CIS control gaps to business risk? Schedule a demo of Diligent IT Risk Management.