What CIS Controls v8.1 are
CIS describes the Controls as a recommended set of concrete defensive actions intended to reduce the most common attacks against systems and networks. The catalogue is prescriptive and prioritized, but it does not replace risk analysis. CIS explicitly states that it is not a one-size-fits-all solution: an enterprise still has to determine what is critical to it and which threat scenarios could interrupt its operations.[3]
Version 8.1 did not introduce Implementation Groups; they first appeared in v7.1. The 8.1 update preserved continuity with v8 and focused on context, consistency, and coexistence with other frameworks.[1]
Status: CIS Controls are voluntary guidance. CIS does not certify organizations as "CIS Controls compliant". Accreditation of companies that provide implementation or assessment services is a separate matter described in CIS documentation.[3]
CIS Controls and CIS Benchmarks are not interchangeable terms
| Element | Purpose | Example |
|---|---|---|
| CIS Control | Structures an area of the security program. | Control 4: Secure Configuration of Enterprise Assets and Software. |
| CIS Safeguard | Describes a single assessable action within a Control. | Establish and maintain a secure configuration process. |
| Implementation Group | Prioritizes Safeguards according to risk profile and organizational capability. | IG1 as a starting point for essential cyber hygiene. |
| CIS Benchmark | Provides configuration recommendations for a specific product or platform. | A benchmark for Windows 11, AWS Foundations, or Kubernetes. |
Controls describe which capabilities should exist; Benchmarks go down to technical configuration. A Benchmark can support Control 4, but it does not by itself prove that the entire Control has been implemented. The official catalogue includes more than 100 Benchmarks covering over 25 vendor product families. PDF documents are available without charge, while usage, especially commercial usage, is subject to CIS terms.[4][5]
IG1, IG2 and IG3: choosing the scope
IG1 - 56 Safeguards
CIS calls IG1 essential cyber hygiene and recommends that every enterprise start with this set. The typical profile described by CIS includes limited specialist expertise, low tolerance for downtime, and a primary need to protect employee and financial data. This is a supporting profile, not a formal company-size threshold.[2]
IG2 - 130 Safeguards in total
IG2 includes IG1 plus 74 additional Safeguards. It is appropriate for organizations whose services and data require greater assurance and where the consequences of an incident go beyond short operational disruption. It requires more formalized processes and stronger capabilities.
IG3 - 153 Safeguards
IG3 contains the full catalogue: IG1, IG2 and 23 additional Safeguards. It is designed for environments with high-value data or services that may be targeted by sophisticated adversaries. It does not automatically mean that every system in the organization must use identical configurations.
Decision questions
- Which data and processes are critical, and how much downtime is acceptable?
- Could disclosure, alteration, or loss of data seriously harm customers, the organization, or the public interest?
- Could an adversary intentionally target the organization?
- Which skills and operational capacity to maintain safeguards are actually available?
- Do contracts or laws impose more detailed requirements?
The result can be mixed: IG1 as an organizational baseline, supplemented by selected IG2 or IG3 Safeguards for critical systems. The rationale, scope, and exceptions should be documented.
The 18 controls in version 8.1
Numbering makes identification easier, but it is not a simple implementation sequence. Dependencies matter more: without a reliable asset inventory it is difficult to assess configurations, vulnerabilities, logging, or backups.
- Inventory and Control of Enterprise Assets - inventory and control of endpoints, virtual assets, cloud resources, and IoT devices.
- Inventory and Control of Software Assets - inventory of authorized software and detection of unauthorized or unsupported components.
- Data Protection - identification, handling, retention, and protection of data.
- Secure Configuration of Enterprise Assets and Software - secure configuration baselines and management of deviations.
- Account Management - lifecycle of user, administrator, and service accounts.
- Access Control Management - granting, reviewing, and revoking access according to business need.
- Continuous Vulnerability Management - continuous discovery, assessment, and remediation of vulnerabilities.
- Audit Log Management - collection, review, protection, and retention of logs required for detection and incident analysis.
- Email and Web Browser Protections - reducing risks associated with email and browsers.
- Malware Defenses - prevention, detection, and control of malicious software.
- Data Recovery - backups, protection of recovery data, and restoration testing.
- Network Infrastructure Management - secure maintenance of network devices and services.
- Network Monitoring and Defense - network visibility and defensive actions.
- Security Awareness and Skills Training - knowledge and skills tailored to roles.
- Service Provider Management - requirements, oversight, and termination of provider relationships.
- Application Software Security - security of the lifecycle of software developed, hosted, or acquired by the organization.
- Incident Response Management - roles, plans, communication, exercises, and improvement of incident response.
- Penetration Testing - testing resilience by controlled identification and exploitation of weaknesses.
Full descriptions and the assignment of Safeguards to Implementation Groups should be taken from the current CIS document or spreadsheet, not from outdated summaries found online.[6]
Applying CIS Benchmarks safely
Most Benchmarks contain Level 1 and Level 2 profiles, and some also contain STIG profiles. Level 1 is intended to reduce attack surface while preserving broad usability. Level 2 is usually more restrictive and may require additional testing. Not every Benchmark has the same structure, number of settings, or profiles. CIS recommends testing configurations before production deployment.[4]
- Choose the Benchmark that exactly matches the product, release, and system role.
- Select a baseline profile and document settings that are not applicable.
- Test compatibility, performance, availability, and rollback capability.
- Deploy in stages, starting with a representative group.
- Monitor configuration drift and changes in both the Benchmark and the product.
- Retain evidence: test results, profile version, date, scope, and approved exceptions.
An automated scan result is technical evidence for a particular time and scope. It does not prove that the organization correctly manages exceptions, risk, or business continuity.
Assessing an implementation: coverage is not effectiveness
The CIS Controls Assessment Specification (CAS) describes inputs, operations, measures, and metrics used to verify whether a Safeguard has been implemented. CIS distinguishes implementation from assessing how well a Safeguard performs. CAS focuses primarily on the former; maturity and effectiveness require broader testing.[7]
For every Safeguard it is useful to maintain a record of status, asset scope, owner, evidence, verification date, exceptions, remediation plan, and reassessment date. A status of "not applicable" requires justification. A percentage score without disclosure of critical gaps can mislead management.
CSAT supports self-assessment, while CIS-CAT tools assess technical configuration against supported Benchmarks. These are different tasks: one concerns the Controls program and the other concerns specific settings.[8]
Relationship with NIST CSF and ISO/IEC 27001
NIST CSF 2.0 describes high-level cybersecurity risk-management outcomes in the Govern, Identify, Protect, Detect, Respond, and Recover functions. It does not prescribe a single way to achieve them. CIS Controls provide more operational actions, so the two approaches can be combined. NIST publishes CIS Controls 8.1 mappings as informative references, while making clear that mappings are not proof of equivalence or endorsement.[9][10]
ISO/IEC 27001:2022 contains requirements for an information security management system and can form the basis of certification. ISO/IEC 27002:2022 provides guidance on information security controls; ISO/IEC 27002 itself is not a basis for organizational certification. Mapping Safeguards to ISO controls can help organize evidence, but it does not replace risk assessment, the Statement of Applicability, or the management-system requirements of ISO/IEC 27001.[11][12]
CIS Controls, the Polish Cybersecurity Act and NIS2
CIS Controls are neither Polish nor EU law. They do not create a presumption of compliance with the Polish Act on the National Cybersecurity System and do not release essential or important entities from their statutory duties. Since 3 April 2026, the amended KSC implementing NIS2 has been in force; entities within its scope must assess the current legal criteria and deadlines rather than determine their status from a selected framework.[13]
CIS can serve as a supporting catalogue of actions and evidence for risk-management measures such as asset management, incident response, continuity, supplier security, vulnerability management, and access control. NIS2 requires an all-hazards approach and measures proportionate to risk. A crosswalk can show common topics; it does not prove that every legal condition has been satisfied.[14]
A practical implementation process
- Define scope. Identify services, data, locations, cloud services, SaaS, mobile devices, IoT, and OT.
- Build a reliable inventory. Agree on data sources for assets, software, accounts, and suppliers.
- Choose a starting point. Adopt IG1 and add Safeguards required by risk or regulation.
- Assess the current state. For each Safeguard, record scope, evidence, gaps, and dependencies.
- Prioritize. First remove gaps that prevent control of other areas, such as an unreliable inventory.
- Assign responsibility. Every element should have a business owner and an implementation owner.
- Implement and test. Use pilots, change control, restoration tests, and incident exercises.
- Measure and improve. Periodically reassess coverage, effectiveness, exceptions, and drift.
There is no credible universal cost or implementation time for IG1, IG2, or IG3. They depend on scope, starting maturity, architecture, exceptions, evidence requirements, and the service model. The schedule should result from a gap assessment, not from a generic table of months.
The most common mistakes
- choosing an Implementation Group solely from headcount or budget;
- treating the purchase of a SIEM, EDR, or scanner as implementation of an entire Safeguard;
- applying a Benchmark without compatibility testing and rollback planning;
- reporting a compliance percentage without disclosing scope and critical exceptions;
- omitting cloud services, SaaS, technical accounts, suppliers, or OT/IoT devices;
- treating a mapping to ISO, NIST, or KSC as proof of compliance;
- performing a one-time assessment without change monitoring and reassessment.
Frequently asked questions
- Are CIS Controls v8.1 free?
- CIS allows organizations to use the Controls to improve their own security. Use by a vendor, consultant, or within a product or service for customers is subject to separate terms and may require membership or authorization. Always verify the current CIS terms.[3]
- Does CIS issue an organizational compliance certificate?
- No. An organization can conduct a self-assessment or independent assessment and issue a scoped evidence-based report, but it should not be described as a CIS Controls certificate.
- Is IG1 only for small companies?
- No. CIS recommends IG1 as a starting point for every enterprise. Organizational profiles help determine additional Safeguards, but there is no formal employee threshold.
- Does completing IG1 mean compliance with NIS2 or KSC?
- No. IG1 can support some technical and organizational measures, but it does not automatically cover all legal duties, scope rules, governance, reporting, and supervisory requirements.
- Does every CIS Benchmark have Level 1 and Level 2?
- Many Benchmarks contain multiple profiles, but the structure depends on the product. Read the specific Benchmark and use the version that matches the deployed environment.
- Does a CIS-CAT result prove implementation of CIS Controls?
- No. It demonstrates compliance of selected technical settings with a supported Benchmark for a specific scope and time. The Controls program also includes processes, people, data, suppliers, and activities that a configuration scan does not assess.
- Where should implementation begin?
- Start by identifying critical services and data and by building reliable inventories of assets, software, accounts, and suppliers. Then assess IG1 and add Safeguards required by risk.
- How often should the assessment be updated?
- There is no single interval for the whole program. Frequency should reflect the requirement of the individual Safeguard, environmental change, risk, and significant changes. Benchmarks should also be reassessed after product, configuration, or guidance changes.
Need consulting in this area?
A free 30-60 minute consultation. No obligations. We discuss needs, scale and a high-level timeline.
Related content
Other competence areas
- IT security audit
- Vulnerability scanning
- Penetration testing
- Device and system hardening
- Email security audit
- KRI compliance audit
- KSC and NIS2 audit
- GDPR compliance audit
- Information security policy
- ISMS - information security management system
- Security awareness - onsite and online
- SOC 24/7 - monitoring and response
Compliance and regulation
Bibliography and sources
Sources checked as of 29 August 2026. Benchmark versions and licensing terms should be verified before each use.
- [1] guidelineCenter for Internet Security (2024). CIS Critical Security Controls v8.1. Released 24 June 2024. · cisecurity.org/controls/v8-1
- [2] guidelineCenter for Internet Security (2024). Implementation Groups. · cisecurity.org/controls/implementation-groups
- [3] guidelineCenter for Internet Security (2024). CIS Critical Security Controls FAQ. · cisecurity.org/controls/cis-controls-faq
- [4] guidelineCenter for Internet Security (2024). CIS Benchmarks FAQ. · cisecurity.org/cis-benchmarks/cis-benchmarks-faq
- [5] regulationCenter for Internet Security (2024). Terms and Conditions. Terms of use for CIS material. · cisecurity.org/terms-and-conditions-table-of-contents
- [6] guidelineCenter for Internet Security (2024). The 18 CIS Critical Security Controls. · cisecurity.org/controls/cis-controls-list
- [7] guidelineCenter for Internet Security (2024). CIS Controls Assessment Specification for Controls v8.1. · cisecurity.org/controls/cis-controls-assessment-specification
- [8] guidelineCenter for Internet Security (2024). Controls Self-Assessment Tool (CSAT). · csat.cisecurity.org
- [9] standardNIST (2024). Cybersecurity Framework 2.0, NIST CSWP 29. DOI: 10.6028/NIST.CSWP.29. · doi.org/10.6028/NIST.CSWP.29
- [10] guidelineNIST (2024). CSF 2.0 Informative References. · nist.gov/cyberframework/informative-references
- [11] standardISO/IEC (2022). ISO/IEC 27001:2022 - Information security management systems - Requirements. · iso.org/standard/27001
- [12] standardISO/IEC (2022). ISO/IEC 27002:2022 - Information security controls. · iso.org/standard/75652.html
- [13] regulationParliament of the Republic of Poland (2026). Act of 23 January 2026 amending the Act on the National Cybersecurity System and certain other acts. Journal of Laws 2026 item 252. · ELI
- [14] regulationEuropean Parliament and Council of the EU (2022). Directive (EU) 2022/2555 (NIS2), in particular Article 21. · EUR-Lex