18 Controls
The top layer bundles related protection objectives – from inventory to access control and data protection through to incident response and penetration testing.
CIS Controls v8.1 translate abstract compliance requirements into 18 concrete, impact-prioritised measures. We move you methodically to the level of essential cyber hygiene (IG1) and beyond.
The CIS Critical Security Controls (published by the Center for Internet Security, CIS) are a prioritised, vendor-neutral catalogue of security measures. Instead of asking "What does the standard require?", they answer the practical question "What protects us first and most effectively?". The current version 8.1 is structured into 18 Controls and 153 Safeguards (concrete individual measures).
The core is prioritisation across three Implementation Groups (IG1–IG3). IG1 defines essential cyber hygiene for smaller organisations with limited resources, while IG2 and IG3 address more mature and critical environments. This makes the CIS Controls not another compliance burden but a pragmatic implementation roadmap beneath ISO 27001, NIS2 and DORA.
Five building blocks that turn a catalogue into a robust roadmap.
The top layer bundles related protection objectives – from inventory to access control and data protection through to incident response and penetration testing.
Each Control breaks down into concrete, actionable and measurable individual measures (Safeguards). This granularity makes progress demonstrable.
Essential cyber hygiene: the subset of Safeguards every organisation should implement as a foundation. The pragmatic entry point.
IG2 for organisations with sensitive data and multiple departments; IG3 for mature or critical environments facing a high threat profile.
Version 8.1 adds the "Govern" security function in line with the NIST CSF 2.0, strengthening organisational oversight and steering.
v8.1 includes realigned mappings, notably to NIST CSF 2.0, along with refined asset classes for cleaner assignment of measures.
Why the CIS Controls are the fastest route to robust compliance.
NIS2 requires "appropriate and proportionate" technical measures but does not name them in detail. The CIS Controls provide exactly this concrete, prioritised measures layer as evidence.
Where ISO 27001 describes the management system and the "what", the CIS Controls deliver the operational "how". The Safeguards map directly onto the Annex A controls.
Whether digital operational resilience (DORA) or product security (Cyber Resilience Act): inventory, patch management and access control from IG1 form the shared technical foundation.
Via the bundled mapping, Safeguards implemented once serve as evidence for several frameworks at the same time – "implement once, prove many times".
From baseline assessment to demonstrable cyber hygiene – in four steps.
We assess your current state against the IG1 Safeguards and identify the most critical gaps – prioritised by risk and effort.
You receive an actionable roadmap: which Safeguards first, at what effort, with what impact and which ownership (RACI).
We support technical delivery – inventory, patch and vulnerability management, MFA, backup – and automate measurement.
Continuous reporting demonstrates your maturity and builds the bridge towards IG2/IG3 as well as ISO 27001 and NIS2.
Four questions on the load-bearing pillars of Implementation Group 1. Answer honestly with Yes, Partly or No.
1Do you maintain an up-to-date inventory of all hardware assets and authorised software (including cloud services)?
2Do you run centralised, continuous vulnerability and patch management with defined deadlines?
3Is multi-factor authentication (MFA) active for all relevant access, and is access control governed by least privilege?
4Do you take regular backups – and have you demonstrably tested recovery?
The self-check is an initial orientation and does not replace a full assessment of the 153 Safeguards.
Primary sources on the standard and matching VamiSec services.
The most important questions about the CIS Controls, answered briefly.
No. The CIS Controls are a vendor-neutral best-practice framework and not certifiable. However, they provide the prioritised measures layer that operationally underpins an ISO 27001 certification or a NIS2 attestation.
ISO 27001 describes a management system and the "what" of information security. The CIS Controls make the operational "how" concrete with prioritised, technical measures – the two complement each other ideally.
IG1 is the subset of Safeguards regarded as essential cyber hygiene. It is the pragmatic entry point for smaller organisations and already protects against the most common attack patterns.
Version 8.1 (June 2024) adds the "Govern" security function, refines asset classes and updates the mappings – notably the alignment with NIST CSF 2.0. The structure (18 Controls) and counting remain unchanged.
Yes. NIS2 requires appropriate technical measures without naming them in detail. The CIS Controls – IG1 in particular – provide exactly this concrete, prioritised and demonstrable measures layer.
We assess your maturity against CIS Controls v8.1, prioritise the most effective steps and support delivery through to robust evidence.