Compliance · Framework & benchmarks
The most practical starting point in security — a prioritized list, in order.
The CIS Critical Security Controls are a prioritized set of safeguards, ordered so the things that stop the most attacks come first. Paired with CIS Benchmarks — hardened configuration baselines for specific technologies — they're the most actionable framework available, and they're free.
18
Controls (v8)
IG1–IG3
Implementation groups
100+
Benchmark technologies
Two distinct things that get conflated: a prioritized control framework, and hardening baselines.
18 controls covering inventory, data protection, access, logging, and response — deliberately ordered by impact, so you can start at the top and work down.
IG1 is the basic cyber hygiene every organization should have. IG2 and IG3 add depth for organizations with more resources and more risk. It tells you what's realistic for your size.
Consensus hardening baselines for operating systems, cloud platforms, browsers, and databases — turning 'harden the server' into a specific, checkable configuration.
Anyone who needs to improve security fast and doesn't know where to start.
We do the readiness, build and run the controls, and support you through the audit — we are not the auditor, and we keep that separation deliberate.
We determine the right implementation group for your size and risk so you don't over-commit or under-protect.
We measure current coverage safeguard by safeguard and produce a prioritized roadmap in CIS's own order.
We apply CIS Benchmarks to your operating systems, cloud accounts, and databases — and handle the exceptions that break things.
We monitor for configuration drift so hardened stays hardened after the project ends.
We map CIS coverage to SOC 2, ISO 27001, and HIPAA so one body of work serves several obligations.
We report coverage over time, which is what turns security spend into a defensible story.
Right-size the target to your organization.
Score current safeguard coverage.
Work the prioritized list top-down.
Apply benchmarks and handle exceptions.
Watch for drift and report coverage.
Not in the way you can with ISO 27001. CIS is a framework and a set of benchmarks, not a certification scheme. You can be independently assessed against it, and CIS offers benchmark-conformance tooling, but there's no organizational CIS certificate. Its value is the prioritized roadmap.
They complement each other. NIST CSF is better for organizing and communicating a program at the executive level; CIS is better for telling engineers exactly what to do next, in order. Many organizations use CSF for structure and CIS for execution.
Not blindly — some settings break real applications. That's why benchmarks have profile levels and why exceptions must be documented rather than silently skipped. We test in staging, record deviations with justification, and keep the baseline defensible.
IG1, top-down. Asset and software inventory first — because every later control depends on knowing what you have. Teams that jump to the interesting controls first almost always find they can't apply them consistently.
Most of the work transfers. Once controls are mapped and evidenced, a second framework costs a fraction of the first.
Tell us where you are and who’s asking for it — we’ll come back with scope, gaps, and a realistic timeline.