Back to Frameworks
Frameworks

CIS Critical Controls

Framework Name

CIS Critical Security Controls (CIS Controls), Version 8.1

Type

Voluntary

Region / Jurisdiction

Global (originated in the US)

Enforcing Body / Certifying Party

Center for Internet Security (CIS), a nonprofit organization. There is no certifying body and no formal certification, organizations self-assess using CIS's own assessment tools

Penalty / Consequence of Non-Compliance

No direct penalty, and nothing to be certified against. The practical consequence is indirect: it's widely used as a benchmark for "reasonable security practice" in cyber insurance underwriting and vendor risk reviews

What It Is & Why It Matters

The CIS Controls are a prioritized, highly practical list of 18 controls and 153 specific safeguards, organized into three Implementation Groups so an organization can start with the basics and scale up as its resources and risk profile grow. Where NIST CSF describes broad outcomes an organization should achieve, CIS Controls go a level more specific: they tell you the actual, concrete actions to take, deliberately designed to be simple enough for IT teams to implement without much interpretation.

It matters because it started from a genuinely different place than most frameworks on this list: it began as a grassroots effort, originally the "SANS Top 20," built directly from real attack data to identify which defenses actually stop the most common, damaging attacks. That practical, no-nonsense origin is still its main appeal today. For smaller organizations or teams without a dedicated security function, CIS Controls is often the first framework they adopt, precisely because it reads like a to-do list rather than an abstract set of principles.

Who Needs It

  • You want a straightforward, practical starting point for a security program, especially with limited security staff or budget
  • You need a benchmark of "reasonable security practice" for a cyber insurance application or vendor questionnaire
  • You are building toward a more formal framework like CMMC Level 2 or NIST CSF and want a concrete foundation to start from
  • You prefer specific, actionable steps over broad outcome statements when building a security roadmap
Book A Demo