Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
CIS Controls v8

CIS Controls v8: the prioritized safeguards, measured from evidence

Map the eighteen CIS Controls and their safeguards to automated checks and structured evidence, pick your Implementation Group, and show your current coverage from what your systems actually report rather than a self-assessment.

What is CIS Controls v8?

The CIS Critical Security Controls, published by the Center for Internet Security, are a prioritized set of safeguards against the most common cyber attacks, developed and updated by a community of practitioners. Version 8, released in May 2021 and refined as version 8.1 in 2024, organizes the safeguards by activity rather than by who manages the device, which suits cloud and hybrid environments. It has eighteen controls, from inventory and control of enterprise and software assets, data protection, secure configuration, account and access management, vulnerability management, audit log management and malware defenses through to incident response, penetration testing and service provider management, with 153 safeguards in all. The safeguards are grouped into three Implementation Groups: IG1, the 56 essential safeguards every organization should have; IG2, for organizations with more resources and sensitivity; and IG3, for those facing sophisticated adversaries. There is no certificate; the controls are a baseline that insurers, regulators and customers recognize, and CIS publishes mappings to NIST CSF, ISO 27001, PCI DSS and others.

In one paragraph

The CIS Critical Security Controls are the Center for Internet Security's prioritized set of safeguards against the most common attacks. Version 8, released in 2021 and refined in version 8.1 in 2024, has eighteen controls and 153 safeguards grouped into three Implementation Groups, so that a small company can start with the 56 essential safeguards of IG1 and grow to IG2 and IG3. There is no certification; the controls are widely used as a security baseline, referenced by insurers and regulators, and mapped by CIS to NIST CSF, ISO 27001 and others.

Who it's for

Companies that want a practical security baseline before or alongside a certification, and anyone whose insurer, customer or regulator references the CIS Controls.

With Viglyn

How Viglyn runs CIS Controls v8

  • All 153 safeguards mapped to controls in the library, with the Implementation Group you choose as the scope
  • Asset inventory, configuration, account, access, vulnerability, logging and endpoint safeguards checked automatically in your cloud, identity, device and code systems
  • Coverage scored from evidence by control and by Implementation Group, with each gap linked to its owner
  • Policy and process safeguards carried by structured evidence requests with a full audit trail
  • The CIS mappings applied, so the same evidence counts toward NIST CSF, ISO 27001, SOC 2 and PCI DSS
Straight answers

The CIS Controls v8 questions that decide it

Which Implementation Group should we choose?

IG1 if you are starting out or have a small team; it is the floor every organization should reach and most of its 56 safeguards are checked automatically in Viglyn. IG2 when you hold sensitive data or face regulatory pressure; IG3 when you are a likely target of sophisticated attacks. Our practitioners pick the group with you against your actual exposure.

How long does CIS Controls take?

A first IG1 coverage score takes days once your systems are connected, because most IG1 safeguards are technical. Closing the gaps depends on what they are; the inventory and configuration safeguards are usually the first wins.

How much does CIS Controls v8 cost with Viglyn?

CIS Controls counts as one of the frameworks included in your plan, from $2,699 a year with implementation by our practitioners included. There is no auditor fee because there is no audit.

FAQ

More CIS Controls v8 questions

Are the CIS Controls a certification?
No. They are a baseline you measure yourself against, and the measurement is what buyers, insurers and regulators ask for. Viglyn produces that measurement from evidence rather than from a questionnaire, which is the difference between claiming coverage and showing it.
What changed in version 8.1?
Version 8.1, released in 2024, aligned the controls with NIST CSF 2.0's Govern function, clarified asset classes and safeguard descriptions, and refined the mappings. The eighteen controls and the Implementation Groups are unchanged.
How do the CIS Controls relate to CIS Benchmarks?
The Controls are the organizational safeguards; the Benchmarks are the detailed secure-configuration guides for specific platforms, such as AWS, Azure, Windows or Kubernetes. The secure configuration safeguards point to the Benchmarks, and Viglyn's configuration checks are built on them.

See CIS Controls v8 run on your stack

A 30-minute walkthrough with your systems and your framework. No commitment.