Book an Appointment
GRC · Risk Management

CIS Critical Security Controls Prioritised cyber hygiene that works

CIS Controls v8.1 translate abstract compliance requirements into 18 concrete, impact-prioritised measures. We move you methodically to the level of essential cyber hygiene (IG1) and beyond.

v8.1 (2024)Current version, released 25 June 2024
18 / 153Controls and Safeguards (measures)
Not certifiableVendor-neutral best-practice framework
Foundation for NIS2Prioritised measures layer under ISO 27001 & NIS2

What the CIS Controls deliver

The CIS Critical Security Controls (published by the Center for Internet Security, CIS) are a prioritised, vendor-neutral catalogue of security measures. Instead of asking "What does the standard require?", they answer the practical question "What protects us first and most effectively?". The current version 8.1 is structured into 18 Controls and 153 Safeguards (concrete individual measures).

The core is prioritisation across three Implementation Groups (IG1–IG3). IG1 defines essential cyber hygiene for smaller organisations with limited resources, while IG2 and IG3 address more mature and critical environments. This makes the CIS Controls not another compliance burden but a pragmatic implementation roadmap beneath ISO 27001, NIS2 and DORA.

The structure of CIS Controls v8.1

Five building blocks that turn a catalogue into a robust roadmap.

01

18 Controls

The top layer bundles related protection objectives – from inventory to access control and data protection through to incident response and penetration testing.

02

153 Safeguards

Each Control breaks down into concrete, actionable and measurable individual measures (Safeguards). This granularity makes progress demonstrable.

03

Implementation Group 1 (IG1)

Essential cyber hygiene: the subset of Safeguards every organisation should implement as a foundation. The pragmatic entry point.

04

Implementation Groups 2 & 3

IG2 for organisations with sensitive data and multiple departments; IG3 for mature or critical environments facing a high threat profile.

05

Governance function (new in v8.1)

Version 8.1 adds the "Govern" security function in line with the NIST CSF 2.0, strengthening organisational oversight and steering.

06

Updated mapping

v8.1 includes realigned mappings, notably to NIST CSF 2.0, along with refined asset classes for cleaner assignment of measures.

The bridge to your obligations

Why the CIS Controls are the fastest route to robust compliance.

NIS2 & national IT security law

NIS2 requires "appropriate and proportionate" technical measures but does not name them in detail. The CIS Controls provide exactly this concrete, prioritised measures layer as evidence.

ISO/IEC 27001

Where ISO 27001 describes the management system and the "what", the CIS Controls deliver the operational "how". The Safeguards map directly onto the Annex A controls.

DORA & CRA

Whether digital operational resilience (DORA) or product security (Cyber Resilience Act): inventory, patch management and access control from IG1 form the shared technical foundation.

NIST CSF 2.0, PCI DSS & GDPR

Via the bundled mapping, Safeguards implemented once serve as evidence for several frameworks at the same time – "implement once, prove many times".

How we proceed

From baseline assessment to demonstrable cyber hygiene – in four steps.

01

1 · Gap assessment against IG1

We assess your current state against the IG1 Safeguards and identify the most critical gaps – prioritised by risk and effort.

02

2 · Prioritised roadmap

You receive an actionable roadmap: which Safeguards first, at what effort, with what impact and which ownership (RACI).

03

3 · Implementation & automation

We support technical delivery – inventory, patch and vulnerability management, MFA, backup – and automate measurement.

04

4 · Evidence & maturity growth

Continuous reporting demonstrates your maturity and builds the bridge towards IG2/IG3 as well as ISO 27001 and NIS2.

Self-check: Do you reach IG1 (essential cyber hygiene)?

Four questions on the load-bearing pillars of Implementation Group 1. Answer honestly with Yes, Partly or No.

1Do you maintain an up-to-date inventory of all hardware assets and authorised software (including cloud services)?

2Do you run centralised, continuous vulnerability and patch management with defined deadlines?

3Is multi-factor authentication (MFA) active for all relevant access, and is access control governed by least privilege?

4Do you take regular backups – and have you demonstrably tested recovery?

The self-check is an initial orientation and does not replace a full assessment of the 153 Safeguards.

Frequently asked questions

The most important questions about the CIS Controls, answered briefly.

Can you get certified against the CIS Controls?

No. The CIS Controls are a vendor-neutral best-practice framework and not certifiable. However, they provide the prioritised measures layer that operationally underpins an ISO 27001 certification or a NIS2 attestation.

What is the difference between the CIS Controls and ISO 27001?

ISO 27001 describes a management system and the "what" of information security. The CIS Controls make the operational "how" concrete with prioritised, technical measures – the two complement each other ideally.

What does Implementation Group 1 (IG1) mean?

IG1 is the subset of Safeguards regarded as essential cyber hygiene. It is the pragmatic entry point for smaller organisations and already protects against the most common attack patterns.

What is new in version 8.1 compared with v8?

Version 8.1 (June 2024) adds the "Govern" security function, refines asset classes and updates the mappings – notably the alignment with NIST CSF 2.0. The structure (18 Controls) and counting remain unchanged.

Do the CIS Controls help with NIS2 implementation?

Yes. NIS2 requires appropriate technical measures without naming them in detail. The CIS Controls – IG1 in particular – provide exactly this concrete, prioritised and demonstrable measures layer.

Bring your cyber hygiene to a demonstrable level

We assess your maturity against CIS Controls v8.1, prioritise the most effective steps and support delivery through to robust evidence.