CIS Controls v8.1

153 Safeguards, and only 56 of them are yours to worry about.

The CIS Critical Security Controls are 18 Controls containing 153 Safeguards — prescriptive, prioritised and free. The reason this framework is the right first move for a small organisation is the Implementation Group: IG1 carves out 56 Safeguards as essential cyber hygiene, achievable by a team without a security specialist, and CIS says every enterprise should meet it. Sentinel is where you assess them, own them and keep the evidence they produce.

Self-service signup opens shortly — we will set you up in the meantime

ControlsSentinel interface, reproduced
Control LibraryFramework ReadinessTest ScheduleTest HistoryFindings
Operating
18
Needs evidence
6
Not implemented
2
Owners assigned
24/26
  • A.5.1Policies for information security
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    28 Jul 2026
  • A.5.18Access rights
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    26 Jun 2026
  • A.8.5Secure authentication
    Owner
    Priya Raman
    Status
    Passed
    Evidence
    Accepted
    Last tested
    14 Aug 2026
  • + 5 more in the workspace

Safeguards filtered to your Implementation Group, each with an owner and an evidence state.

Start here

The Implementation Group is the most useful idea in this framework.

Most control sets hand a ten-person company the same list they hand a bank, and the company reasonably concludes the whole thing is for somebody else. CIS instead defines three enterprise profiles and assigns every Safeguard to one, so a small organisation gets a defensible, finite scope on the first day.

IG1Start here

Essential cyber hygiene

56Safeguards

CIS defines IG1 as the baseline of essential cyber hygiene and states that every enterprise should implement it, whatever its size. It is the closest thing to an agreed floor that exists in this field, and it is deliberately achievable by a team without a security specialist.

A small or medium organisation with limited IT and cybersecurity expertise, often one or two generalists, whose overriding concern is keeping the business running. Sensitivity of the data held is limited, and an outage matters more than espionage.

IG2Adds to IG1

Managing higher complexity

74Safeguards · 130 cumulative

Adds 74 Safeguards on top of IG1, bringing the cumulative total to 130. The character of the work changes here: from configuring things correctly to running programmes — vulnerability management with cadence, log analysis, service provider assessment.

An organisation with people whose actual job is managing and protecting IT infrastructure, multiple departments with different risk tolerances, and sensitive client or company information that would cause real harm and reputational damage if lost.

IG3Adds to IG2

Specialist and regulated

23Safeguards · 153 cumulative

The remaining 23 Safeguards, completing all 153. Penetration testing, application security programmes and network monitoring sophistication live largely here, which is why the Implementation Group model spares a smaller organisation from pretending otherwise.

An organisation employing security specialists in distinct disciplines — risk management, penetration testing, application security — with assets and data subject to regulatory oversight, where a successful attack could affect public wellbeing.

The groups are cumulative: 56, then 130, then all 153. An IG2 organisation implements the IG1 Safeguards as well, so the 74 and 23 figures are what each group adds rather than what it contains. Three Controls contribute no IG1 Safeguards at all — network monitoring and defence, application software security, and penetration testing — which is a deliberate statement about what a small team should not be attempting first.

IG1 is the only artefact described anywhere on this site that a two-person IT team can actually finish. That is not a criticism of the others. It is the reason to start here.

Structure

Eighteen Controls, ordered by what to do first.

Version 8 reorganised the set around activities rather than around who managed the device, which is what made it usable for organisations whose estate is laptops, cloud services and a virtual private network rather than a server room. The order is a priority order — and the first two Controls are the ones everything else silently depends on.

01

Inventory and Control of Enterprise Assets

The dependency for nearly everything else. You cannot patch, monitor or decommission what nobody listed.

5 SG
02

Inventory and Control of Software Assets

Authorised software, and a way of finding what is running that should not be.

7 SG
03

Data Protection

Data inventory, classification, retention, encryption and disposal. The largest control by Safeguard count, alongside application security.

14 SG
04

Secure Configuration of Enterprise Assets and Software

Hardened baselines for devices, servers, network gear and cloud services, plus session locking and default-credential removal.

12 SG
05

Account Management

Inventory of accounts, unique credentials, disabling dormant accounts, and separate administrative accounts.

6 SG
06

Access Control Management

Granting and revoking access, multi-factor authentication for remote and administrative access, and role-based access design.

8 SG
07

Continuous Vulnerability Management

A defined cadence for finding and remediating vulnerabilities, with automated patching where it exists.

7 SG
08

Audit Log Management

What is collected, whether clocks agree, how long logs are retained, and who reviews them.

12 SG
09

Email and Web Browser Protections

The two channels most incidents still arrive through. DNS filtering, attachment and URL controls, and supported clients only.

7 SG
10

Malware Defenses

Anti-malware deployed and updated, behaviour-based detection, and disabling autorun on removable media.

7 SG
11

Data Recovery

Automated backups, protected and isolated copies, and — the Safeguard most often missing — testing restoration.

5 SG
12

Network Infrastructure Management

Current network devices, secure architecture, encrypted administration, and documented network diagrams.

8 SG
13

Network Monitoring and Defense

Centralised alerting, intrusion detection, traffic flow logging and network segmentation. No IG1 Safeguards at all.

11 SG
14

Security Awareness and Skills Training

A programme with completion records, covering social engineering, authentication, data handling and incident reporting.

9 SG
15

Service Provider Management

An inventory of providers, classification by risk, security requirements in contracts, and monitoring and decommissioning.

7 SG
16

Application Software Security

Secure development practices, dependency management, vulnerability triage and code review. Relevant if you build software; no IG1 Safeguards.

14 SG
17

Incident Response Management

Named roles and contact details, a reporting process people know, defined thresholds, and post-incident review.

9 SG
18

Penetration Testing

Scoped, periodic testing with remediation tracking. Entirely IG2 and IG3 — no IG1 Safeguards.

5 SG

153 Safeguards across the 18 Controls. Version 8.1 keeps that structure and adds alignment with NIST CSF 2.0 — including the Govern function alongside Identify, Protect, Detect, Respond and Recover — together with revised asset classes and clarified descriptions. The Controls and the accompanying mappings are published free of charge by the Center for Internet Security.

Readiness path

Six steps, and the second one is the one people skip.

This framework is unusual in that the work is mostly technical rather than documentary, so progress is visible within weeks. The failure mode is different too: not a stalled audit, but a burst of activity that nobody recorded and nobody can now evidence.

  1. 01

    Place yourself in an Implementation Group honestly

    Read the three enterprise profiles and pick the one that describes you, not the one you aspire to. Most growing businesses are IG1, and a few are IG1 with a handful of IG2 Safeguards forced on them by a specific customer or a regulated data type.

  2. 02

    Finish Controls 1 and 2 before anything else

    Asset and software inventory is the prerequisite the rest quietly assumes. Every later Safeguard about patching, hardening, monitoring or decommissioning is unmeasurable until you know what exists — and this is the step people skip because it is dull.

  3. 03

    Assess each Safeguard in your group

    For each of the 56 IG1 Safeguards, record whether it is implemented, partly implemented or absent, and what evidence supports the answer. Partly implemented is a legitimate and very common answer; treat “yes, mostly” as a gap.

  4. 04

    Sequence by dependency, not by number

    The Controls are ordered by priority, but your own sequencing has to respect dependencies. Multi-factor authentication needs the account inventory. Log retention needs somewhere to retain logs. Restoration testing needs backups that already run.

  5. 05

    Do the work, and keep the artefact each Safeguard produces

    The configuration export, the scan result, the restore test, the training completion record. Each Safeguard leaves a trace, and that trace is what later answers a questionnaire, an insurance application or an ISO 27001 Annex A control.

  6. 06

    Reassess, then decide whether to move up

    Reassess on a cadence and after material change. Moving to IG2 is a deliberate decision driven by the data you now hold, the customers you now serve or the regulation you now fall under — not by having finished IG1.

Evidence

Every Safeguard leaves something behind. Keep it.

Nobody audits the CIS Controls, so the temptation is to do the work and move on. Six months later a customer questionnaire, an insurance application or an ISO 27001 gap analysis asks for proof, and the work is invisible. These are the artefacts worth capturing while they are in front of you.

Asset inventory with owners and disposal recordsFoundational
Controls 1 and 2. Every other Safeguard is measured against this list.
Hardened configuration baselinesFoundational
What the baseline is, and how a device is confirmed to match it.
Account inventory, including administrative accountsFoundational
Who holds privileged access, and which accounts are service accounts.
Multi-factor authentication coverage recordFoundational
Remote access, administrative access and externally exposed applications, stated by system.
Access grant and revocation recordsRecurring
A joiner or leaver, the request, and the date access actually changed.
Vulnerability scan output and remediation ticketsRecurring
The cadence, the findings, and what closed them — including accepted exceptions.
Patch and update deployment reportsRecurring
Coverage and age, per platform, rather than a claim that automatic updates are on.
Log retention configuration and review notesRecurring
What is collected, for how long, and evidence that someone looked.
Backup restoration test resultsEvent-driven
A restore that actually ran, with a date, a scope and a result.
Incident records and post-incident reviewEvent-driven
Control 17 expects a process people have used, not a plan they have filed.
Service provider inventory and assessmentsRecurring
Providers classified by risk, with the security terms that are genuinely in the contract.
Awareness training completion recordsTime-bound
By person and date. The item most likely to be out of date the day you need it.
Penetration test report and remediation planTime-bound
IG2 and IG3 only — and a report with no remediation tracking is an expensive PDF.

In Sentinel

A Safeguard list with names against it.

A downloaded spreadsheet of 153 rows is where this framework usually stops. What changes the outcome is the boring part: a filter to your Implementation Group, an owner per Safeguard, and an artefact attached the day the work is done.

  • Safeguards filtered to your group

    Bring the Controls in as scope and work the 56, the 130 or all 153 — without deleting rows from a spreadsheet and losing them.

  • An owner per Safeguard

    The person who will actually configure it, not the department. This is the difference between a plan and a list.

  • Evidence captured at the moment of work

    Attach the scan output, the configuration export or the restore result while it exists, with a status and an expiry date.

  • Gaps as dated actions

    Partly implemented becomes tracked work with a date, and the register stops flattering you.

  • Mapped into the other frameworks

    The same Safeguard evidence answers ISO 27001 Annex A controls, SOC 2 common criteria and CSF 2.0 Subcategories. Collected once.

  • Straight into insurance readiness

    The IG1 evidence set is close to what an underwriter asks for, so the renewal workspace draws on work you have already done.

  • CIS Controls v8.1Available
    56 safeguards in the catalogue

Straight answers

Honest limitations.

The most practical framework of the four, and the one that will not satisfy procurement on its own.

  • No certificate exists

    CIS does not certify organisations against the Controls. The commercial value is indirect — the evidence maps into ISO 27001, SOC 2, CSF 2.0 and insurance applications, which is where the credential actually comes from.

  • Thin on governance by design

    There is no risk appetite statement, no management review, no internal audit programme. If you need to answer a board rather than harden a fleet, pair the Controls with NIST CSF 2.0.

  • An Implementation Group is not a risk assessment

    IG1 is a sensible default, not a determination that your residual risk is acceptable. Unusual data or an unusual adversary can pull a specific IG3 Safeguard forward.

  • Some Safeguards assume tooling

    Centralised logging, endpoint detection and automated patching cost money and someone’s attention. The framework is free; the implementation is not.

Questions

What people ask before they commit a quarter to this.

Which group, whether IG1 is sufficient, and how any of it converts into something a customer accepts.

Which Implementation Group are we?
Read the three enterprise profiles rather than counting your staff. If your IT and security work is done by generalists, the data you hold would be embarrassing rather than dangerous to lose, and your worst realistic day is an outage or a ransomware event, you are IG1 — and CIS is explicit that IG1 is the baseline every enterprise should meet regardless of size. If you have people whose actual job title is infrastructure or security, several business units with different risk tolerances, and client data whose loss would cause real harm, you are IG2. IG3 assumes specialists in distinct disciplines and regulatory oversight of the data itself. The groups are cumulative, so an IG2 organisation implements all 130 Safeguards rather than only the 74 that IG2 adds.
Is IG1 actually enough?
It is enough to be meaningfully harder to attack than you are today, and it is far more than most small organisations currently have. It is not a statement that your residual risk is acceptable — that depends on what you hold and who wants it. Two honest cautions. First, 56 Safeguards is not 56 afternoons: the data protection and configuration Safeguards contain real projects. Second, an Implementation Group is a starting profile rather than a risk assessment, so if you hold something unusually sensitive, specific IG2 or IG3 Safeguards may be necessary long before you have finished IG1.
Can we be certified against the CIS Controls?
No. The Center for Internet Security publishes the Controls free of charge and operates no certification scheme for organisations implementing them, so there is no certificate and no accredited body. Third parties will assess you and write a report, and that can be useful internally, but it is not a credential procurement recognises. Where the Controls earn their keep commercially is indirect: the evidence they generate maps cleanly onto ISO 27001 Annex A, the SOC 2 common criteria, NIST CSF 2.0 Subcategories and most insurance applications.
How do the CIS Controls differ from the CIS Benchmarks?
They are separate publications that get conflated constantly. The Controls are the actions — 18 Controls and 153 Safeguards describing what to do. The Benchmarks are configuration guidance for specific technologies: consensus-developed hardening settings for a particular operating system, browser, database or cloud service, with recommended values and rationale. In practice the Controls tell you that secure configuration baselines must exist, and the Benchmarks are where you get the baseline for the platform in front of you.
Will working through IG1 help at our next cyber-insurance renewal?
It is the closest map on this site to what underwriters actually ask. Application forms and renewal questionnaires concentrate on multi-factor authentication coverage for remote and administrative access, backups that are isolated and restore-tested, endpoint protection, patching cadence, email filtering, privileged account handling and whether an incident response plan exists and has been exercised — all of which are IG1 or early IG2 Safeguards. Having the evidence organised also shortens the submission, because the answers stop being assembled from memory. What it cannot do is determine an underwriting outcome.
What changed in v8.1, and does our v8 work still count?
Yes, it still counts — v8.1 is an update rather than a rewrite, and it keeps the 18 Controls and the Implementation Group structure. The substantive additions are alignment with NIST CSF 2.0, including the Govern function alongside Identify, Protect, Detect, Respond and Recover, revised asset classes, and clarified descriptions and glossary entries. If you assessed against v8, the practical work is confirming your mapping and picking up the clarifications, not starting again. The larger break was v8 itself, which reorganised the Controls by activity rather than by who managed the device.

Fifty-six Safeguards, an owner against each one.

Assess IG1 honestly and you will finish the afternoon with a finite list, a name beside every item, and a much better idea of which of the other frameworks is worth the money.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required