CIS Controls v8.1
153 Safeguards, and only 56 of them are yours to worry about.
The CIS Critical Security Controls are 18 Controls containing 153 Safeguards — prescriptive, prioritised and free. The reason this framework is the right first move for a small organisation is the Implementation Group: IG1 carves out 56 Safeguards as essential cyber hygiene, achievable by a team without a security specialist, and CIS says every enterprise should meet it. Sentinel is where you assess them, own them and keep the evidence they produce.
Self-service signup opens shortly — we will set you up in the meantime
| Control | Owner | Status | Evidence | Last tested |
|---|---|---|---|---|
| A.5.1Policies for information security | Priya Raman | Passed | Accepted | 28 Jul 2026 |
| A.5.18Access rights | Priya Raman | Passed | Accepted | 26 Jun 2026 |
| A.8.5Secure authentication | Priya Raman | Passed | Accepted | 14 Aug 2026 |
| A.8.13Information backup | Jordan Blake | Passed | Accepted | 18 Jun 2026 |
| A.8.2Privileged access rights | Priya Raman | Failed | Needs Review | 20 Aug 2026 |
| A.8.7Protection against malware | Jordan Blake | Tested | Accepted | 28 Aug 2026 |
| CC9.2Vendor and business partner risk management | Elena Kowalski | Failed | Accepted | 12 Aug 2026 |
| PR.AA-01Identities and credentials are managed | Unassigned | Not Tested | Missing | — |
- A.5.1Policies for information security
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 28 Jul 2026
- A.5.18Access rights
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 26 Jun 2026
- A.8.5Secure authentication
- Owner
- Priya Raman
- Status
- Passed
- Evidence
- Accepted
- Last tested
- 14 Aug 2026
- + 5 more in the workspace
Safeguards filtered to your Implementation Group, each with an owner and an evidence state.
Start here
The Implementation Group is the most useful idea in this framework.
Most control sets hand a ten-person company the same list they hand a bank, and the company reasonably concludes the whole thing is for somebody else. CIS instead defines three enterprise profiles and assigns every Safeguard to one, so a small organisation gets a defensible, finite scope on the first day.
Essential cyber hygiene
56Safeguards
CIS defines IG1 as the baseline of essential cyber hygiene and states that every enterprise should implement it, whatever its size. It is the closest thing to an agreed floor that exists in this field, and it is deliberately achievable by a team without a security specialist.
A small or medium organisation with limited IT and cybersecurity expertise, often one or two generalists, whose overriding concern is keeping the business running. Sensitivity of the data held is limited, and an outage matters more than espionage.
Managing higher complexity
74Safeguards · 130 cumulative
Adds 74 Safeguards on top of IG1, bringing the cumulative total to 130. The character of the work changes here: from configuring things correctly to running programmes — vulnerability management with cadence, log analysis, service provider assessment.
An organisation with people whose actual job is managing and protecting IT infrastructure, multiple departments with different risk tolerances, and sensitive client or company information that would cause real harm and reputational damage if lost.
Specialist and regulated
23Safeguards · 153 cumulative
The remaining 23 Safeguards, completing all 153. Penetration testing, application security programmes and network monitoring sophistication live largely here, which is why the Implementation Group model spares a smaller organisation from pretending otherwise.
An organisation employing security specialists in distinct disciplines — risk management, penetration testing, application security — with assets and data subject to regulatory oversight, where a successful attack could affect public wellbeing.
The groups are cumulative: 56, then 130, then all 153. An IG2 organisation implements the IG1 Safeguards as well, so the 74 and 23 figures are what each group adds rather than what it contains. Three Controls contribute no IG1 Safeguards at all — network monitoring and defence, application software security, and penetration testing — which is a deliberate statement about what a small team should not be attempting first.
IG1 is the only artefact described anywhere on this site that a two-person IT team can actually finish. That is not a criticism of the others. It is the reason to start here.
Structure
Eighteen Controls, ordered by what to do first.
Version 8 reorganised the set around activities rather than around who managed the device, which is what made it usable for organisations whose estate is laptops, cloud services and a virtual private network rather than a server room. The order is a priority order — and the first two Controls are the ones everything else silently depends on.
- 01
Inventory and Control of Enterprise Assets
The dependency for nearly everything else. You cannot patch, monitor or decommission what nobody listed.
- 5 SG
- 02
Inventory and Control of Software Assets
Authorised software, and a way of finding what is running that should not be.
- 7 SG
- 03
Data Protection
Data inventory, classification, retention, encryption and disposal. The largest control by Safeguard count, alongside application security.
- 14 SG
- 04
Secure Configuration of Enterprise Assets and Software
Hardened baselines for devices, servers, network gear and cloud services, plus session locking and default-credential removal.
- 12 SG
- 05
Account Management
Inventory of accounts, unique credentials, disabling dormant accounts, and separate administrative accounts.
- 6 SG
- 06
Access Control Management
Granting and revoking access, multi-factor authentication for remote and administrative access, and role-based access design.
- 8 SG
- 07
Continuous Vulnerability Management
A defined cadence for finding and remediating vulnerabilities, with automated patching where it exists.
- 7 SG
- 08
Audit Log Management
What is collected, whether clocks agree, how long logs are retained, and who reviews them.
- 12 SG
- 09
Email and Web Browser Protections
The two channels most incidents still arrive through. DNS filtering, attachment and URL controls, and supported clients only.
- 7 SG
- 10
Malware Defenses
Anti-malware deployed and updated, behaviour-based detection, and disabling autorun on removable media.
- 7 SG
- 11
Data Recovery
Automated backups, protected and isolated copies, and — the Safeguard most often missing — testing restoration.
- 5 SG
- 12
Network Infrastructure Management
Current network devices, secure architecture, encrypted administration, and documented network diagrams.
- 8 SG
- 13
Network Monitoring and Defense
Centralised alerting, intrusion detection, traffic flow logging and network segmentation. No IG1 Safeguards at all.
- 11 SG
- 14
Security Awareness and Skills Training
A programme with completion records, covering social engineering, authentication, data handling and incident reporting.
- 9 SG
- 15
Service Provider Management
An inventory of providers, classification by risk, security requirements in contracts, and monitoring and decommissioning.
- 7 SG
- 16
Application Software Security
Secure development practices, dependency management, vulnerability triage and code review. Relevant if you build software; no IG1 Safeguards.
- 14 SG
- 17
Incident Response Management
Named roles and contact details, a reporting process people know, defined thresholds, and post-incident review.
- 9 SG
- 18
Penetration Testing
Scoped, periodic testing with remediation tracking. Entirely IG2 and IG3 — no IG1 Safeguards.
- 5 SG
153 Safeguards across the 18 Controls. Version 8.1 keeps that structure and adds alignment with NIST CSF 2.0 — including the Govern function alongside Identify, Protect, Detect, Respond and Recover — together with revised asset classes and clarified descriptions. The Controls and the accompanying mappings are published free of charge by the Center for Internet Security.
Readiness path
Six steps, and the second one is the one people skip.
This framework is unusual in that the work is mostly technical rather than documentary, so progress is visible within weeks. The failure mode is different too: not a stalled audit, but a burst of activity that nobody recorded and nobody can now evidence.
- 01
Place yourself in an Implementation Group honestly
Read the three enterprise profiles and pick the one that describes you, not the one you aspire to. Most growing businesses are IG1, and a few are IG1 with a handful of IG2 Safeguards forced on them by a specific customer or a regulated data type.
- 02
Finish Controls 1 and 2 before anything else
Asset and software inventory is the prerequisite the rest quietly assumes. Every later Safeguard about patching, hardening, monitoring or decommissioning is unmeasurable until you know what exists — and this is the step people skip because it is dull.
- 03
Assess each Safeguard in your group
For each of the 56 IG1 Safeguards, record whether it is implemented, partly implemented or absent, and what evidence supports the answer. Partly implemented is a legitimate and very common answer; treat “yes, mostly” as a gap.
- 04
Sequence by dependency, not by number
The Controls are ordered by priority, but your own sequencing has to respect dependencies. Multi-factor authentication needs the account inventory. Log retention needs somewhere to retain logs. Restoration testing needs backups that already run.
- 05
Do the work, and keep the artefact each Safeguard produces
The configuration export, the scan result, the restore test, the training completion record. Each Safeguard leaves a trace, and that trace is what later answers a questionnaire, an insurance application or an ISO 27001 Annex A control.
- 06
Reassess, then decide whether to move up
Reassess on a cadence and after material change. Moving to IG2 is a deliberate decision driven by the data you now hold, the customers you now serve or the regulation you now fall under — not by having finished IG1.
Evidence
Every Safeguard leaves something behind. Keep it.
Nobody audits the CIS Controls, so the temptation is to do the work and move on. Six months later a customer questionnaire, an insurance application or an ISO 27001 gap analysis asks for proof, and the work is invisible. These are the artefacts worth capturing while they are in front of you.
- Asset inventory with owners and disposal recordsFoundational
- Controls 1 and 2. Every other Safeguard is measured against this list.
- Hardened configuration baselinesFoundational
- What the baseline is, and how a device is confirmed to match it.
- Account inventory, including administrative accountsFoundational
- Who holds privileged access, and which accounts are service accounts.
- Multi-factor authentication coverage recordFoundational
- Remote access, administrative access and externally exposed applications, stated by system.
- Access grant and revocation recordsRecurring
- A joiner or leaver, the request, and the date access actually changed.
- Vulnerability scan output and remediation ticketsRecurring
- The cadence, the findings, and what closed them — including accepted exceptions.
- Patch and update deployment reportsRecurring
- Coverage and age, per platform, rather than a claim that automatic updates are on.
- Log retention configuration and review notesRecurring
- What is collected, for how long, and evidence that someone looked.
- Backup restoration test resultsEvent-driven
- A restore that actually ran, with a date, a scope and a result.
- Incident records and post-incident reviewEvent-driven
- Control 17 expects a process people have used, not a plan they have filed.
- Service provider inventory and assessmentsRecurring
- Providers classified by risk, with the security terms that are genuinely in the contract.
- Awareness training completion recordsTime-bound
- By person and date. The item most likely to be out of date the day you need it.
- Penetration test report and remediation planTime-bound
- IG2 and IG3 only — and a report with no remediation tracking is an expensive PDF.
In Sentinel
A Safeguard list with names against it.
A downloaded spreadsheet of 153 rows is where this framework usually stops. What changes the outcome is the boring part: a filter to your Implementation Group, an owner per Safeguard, and an artefact attached the day the work is done.
Safeguards filtered to your group
Bring the Controls in as scope and work the 56, the 130 or all 153 — without deleting rows from a spreadsheet and losing them.
An owner per Safeguard
The person who will actually configure it, not the department. This is the difference between a plan and a list.
Evidence captured at the moment of work
Attach the scan output, the configuration export or the restore result while it exists, with a status and an expiry date.
Gaps as dated actions
Partly implemented becomes tracked work with a date, and the register stops flattering you.
Mapped into the other frameworks
The same Safeguard evidence answers ISO 27001 Annex A controls, SOC 2 common criteria and CSF 2.0 Subcategories. Collected once.
Straight into insurance readiness
The IG1 evidence set is close to what an underwriter asks for, so the renewal workspace draws on work you have already done.
- CIS Controls v8.1Available56 safeguards in the catalogue
Straight answers
Honest limitations.
The most practical framework of the four, and the one that will not satisfy procurement on its own.
No certificate exists
CIS does not certify organisations against the Controls. The commercial value is indirect — the evidence maps into ISO 27001, SOC 2, CSF 2.0 and insurance applications, which is where the credential actually comes from.
Thin on governance by design
There is no risk appetite statement, no management review, no internal audit programme. If you need to answer a board rather than harden a fleet, pair the Controls with NIST CSF 2.0.
An Implementation Group is not a risk assessment
IG1 is a sensible default, not a determination that your residual risk is acceptable. Unusual data or an unusual adversary can pull a specific IG3 Safeguard forward.
Some Safeguards assume tooling
Centralised logging, endpoint detection and automated patching cost money and someone’s attention. The framework is free; the implementation is not.
Questions
What people ask before they commit a quarter to this.
Which group, whether IG1 is sufficient, and how any of it converts into something a customer accepts.
Which Implementation Group are we?
Is IG1 actually enough?
Can we be certified against the CIS Controls?
How do the CIS Controls differ from the CIS Benchmarks?
Will working through IG1 help at our next cyber-insurance renewal?
What changed in v8.1, and does our v8 work still count?
Fifty-six Safeguards, an owner against each one.
Assess IG1 honestly and you will finish the afternoon with a finite list, a name beside every item, and a much better idea of which of the other frameworks is worth the money.
Self-service signup opens shortly — we will set you up in the meantime
- Published pricing — no quote-on-request tier
- No credit card required for the trial
- No automatic charge when a trial ends
- Tenant-isolated architecture, data stored in Canada
- Clear data-processing terms
- No compliance guarantee — human judgement still required