.png)
.png)

CIS Critical Controls
Framework Name
CIS Critical Security Controls (CIS Controls), Version 8.1
Type
Voluntary
Region / Jurisdiction
Global (originated in the US)
Enforcing Body / Certifying Party
Center for Internet Security (CIS), a nonprofit organization. There is no certifying body and no formal certification, organizations self-assess using CIS's own assessment tools
Penalty / Consequence of Non-Compliance
No direct penalty, and nothing to be certified against. The practical consequence is indirect: it's widely used as a benchmark for "reasonable security practice" in cyber insurance underwriting and vendor risk reviews
What It Is & Why It Matters
The CIS Controls are a prioritized, highly practical list of 18 controls and 153 specific safeguards, organized into three Implementation Groups so an organization can start with the basics and scale up as its resources and risk profile grow. Where NIST CSF describes broad outcomes an organization should achieve, CIS Controls go a level more specific: they tell you the actual, concrete actions to take, deliberately designed to be simple enough for IT teams to implement without much interpretation.
It matters because it started from a genuinely different place than most frameworks on this list: it began as a grassroots effort, originally the "SANS Top 20," built directly from real attack data to identify which defenses actually stop the most common, damaging attacks. That practical, no-nonsense origin is still its main appeal today. For smaller organizations or teams without a dedicated security function, CIS Controls is often the first framework they adopt, precisely because it reads like a to-do list rather than an abstract set of principles.
Who Needs It
- You want a straightforward, practical starting point for a security program, especially with limited security staff or budget
- You need a benchmark of "reasonable security practice" for a cyber insurance application or vendor questionnaire
- You are building toward a more formal framework like CMMC Level 2 or NIST CSF and want a concrete foundation to start from
- You prefer specific, actionable steps over broad outcome statements when building a security roadmap