Skip to main content
Category: Compliance Frameworks & Standards

CIS Controls v8.1

Also known as: CIS Controls, CIS Critical Security Controls Version 8.1, Critical Security Controls v8.1, CIS CSC v8.1
Simply put

CIS Controls v8.1 is a prioritized set of recommended cybersecurity best practices that organizations can use as a foundation for building a security program. It is an iterative update to version 8 that refines alignment with other industry standards and frameworks. The controls are intended to help organizations move from limited visibility toward a more defensible, well-governed security posture.

Formal definition

CIS Controls v8.1, published by the Center for Internet Security, is an iterative revision of CIS Controls v8 consisting of 18 controls intended to serve as a basis for an information security program. The v8.1 update includes revised alignment to evolving industry standards and frameworks, updated asset classes, and refined CIS mappings; it retains the Implementation Group model that tiers controls by organizational maturity and resources. The controls can be mapped to other frameworks (for example via the CIS Controls Navigator) to fit within a broader security program. In a virtual or fractional CISO engagement, the CIS Controls are typically used as a prioritization and gap-assessment reference to guide governance and program development, rather than as a certification standard; adopting them supports readiness and does not by itself guarantee compliance with any specific regulation, and realized value depends on organizational maturity, scope, and stakeholder cooperation.

Why it matters

Many organizations, particularly those without a mature security program, struggle with knowing where to begin. CIS Controls v8.1 addresses this by offering a prioritized set of best practices, helping organizations move from limited visibility toward a more defensible, well-governed cybersecurity posture. Rather than presenting an undifferentiated list of every possible safeguard, the controls are structured to guide organizations toward the actions that provide meaningful risk reduction first, which is especially valuable when resources are constrained.

For security leaders, the framework's value lies in its role as a common reference point that can be mapped to other standards and frameworks. Because the 18 controls are intended to serve as the basis for an information security program, they give executives and boards a coherent way to discuss security investments and gaps in terms of program maturity rather than isolated technical tasks. This reframes security as a governance and business risk function, not a purely technical checklist.

It is important to be clear about what the CIS Controls do not do. Adopting them supports readiness and helps structure a program, but doing so does not by itself guarantee compliance with any specific regulation, nor does it constitute a certification. The realized value of the controls depends heavily on organizational maturity, the scope of adoption, and the cooperation of stakeholders who must implement and sustain them over time.

Who it's relevant to

Organizations building an early-stage security program
For organizations moving from limited visibility toward a more defensible posture, the prioritized structure and Implementation Group model provide a starting point that reflects available resources and maturity. The framework helps focus initial effort where it matters most, though the value depends on stakeholders actually implementing and sustaining the chosen safeguards.
Virtual and fractional CISOs
In a vCISO or fractional CISO engagement, the CIS Controls are commonly used as a prioritization and gap-assessment reference to guide governance and program development. The engagement provides strategy and direction on applying the controls; it generally does not include hands-on operational implementation unless explicitly contracted, and accountability for decisions remains with the client organization.
Executives and boards
Because the 18 controls are intended to serve as the basis for an information security program, they give leadership a structured way to discuss security posture and gaps as a matter of governance and business risk. Leaders should understand that adopting the controls supports readiness but does not by itself guarantee regulatory compliance or certification.
Teams working across multiple frameworks
Organizations that must align with several standards can use tools such as the CIS Controls Navigator to map the controls to other frameworks, fitting them within a broader security program. This mapping supports coherence across compliance efforts, though it does not replace the specific requirements of any individual regulation or standard.

Inside CIS Controls

Prioritized Safeguards
CIS Controls v8.1 organizes security actions into a set of controls, each broken down into specific safeguards (formerly called sub-controls) that describe discrete, actionable measures an organization can implement.
Implementation Groups (IGs)
The framework tiers safeguards across Implementation Groups that reflect differing levels of organizational resources, risk, and maturity, allowing organizations to scope adoption to their capacity rather than applying every safeguard uniformly.
Asset and Data Focus
Many controls emphasize inventory and control of enterprise assets, software assets, and data, reflecting the principle that organizations cannot protect what they have not identified.
Governance and Process Elements
Beyond technical measures, the controls address process-oriented areas such as account management, access control management, and security awareness, positioning security as a governance function and not solely a technical one.
Mapping to Other Frameworks
CIS Controls are commonly mapped to other frameworks and standards to help organizations align their control efforts with broader compliance or governance programs. The specifics of any mapping should be verified against current CIS documentation rather than assumed.

Common questions

Answers to the questions practitioners most commonly ask about CIS Controls.

Does implementing the CIS Controls v8.1 make an organization compliant or certified?
No. The CIS Controls are a prioritized set of safeguards intended to improve security posture; they are not a certification scheme, and implementing them does not by itself confer compliance with frameworks or regulations such as ISO 27001, SOC 2, HIPAA, or PCI DSS. In many engagements they are used to support readiness and to map toward those other frameworks, but adopting the Controls should not be conflated with achieving or asserting certification. A virtual CISO can help align a program to the Controls, though accountability for compliance decisions typically remains with the client organization.
Is following the CIS Controls a purely technical exercise handled by the IT or security team?
Not entirely. While many safeguards are technical, the Controls also depend on governance, prioritization, resourcing, and business risk decisions that sit above day-to-day operations. Treating them as a checklist for technical staff often overlooks the leadership and program-level work needed to sequence, sustain, and measure them. A virtual CISO typically advises on strategy, prioritization, and governance around the Controls rather than performing hands-on tool administration or operational implementation, which usually falls outside a vCISO's scope unless explicitly contracted.
How does an organization decide where to start with the CIS Controls?
Many organizations begin by assessing their current maturity against the Controls and prioritizing based on risk, resources, and existing gaps. The Controls are organized to help with sequencing, and the value of any prioritization depends heavily on organizational maturity, stakeholder cooperation, and a clearly defined scope. A virtual CISO can facilitate this assessment and recommend a sequence, but effective progress typically requires access to the right stakeholders and reliable information about the current environment.
Who is responsible for actually implementing the safeguards once they are prioritized?
Implementation responsibility generally rests with the client organization's internal teams or contracted operational providers, not with the virtual CISO. A vCISO typically directs, advises, and helps track progress, while hands-on tasks such as configuring tools, monitoring, or remediation are usually carried out by others. Clarifying this division at the outset of an engagement helps avoid the common mistake of assuming the advisory role includes operational execution.
How can progress against the CIS Controls be measured over time?
Progress is often tracked by reassessing implementation status of individual safeguards and monitoring how the program matures against defined objectives. The quality of measurement depends on consistent data, defined scope, and ongoing client cooperation. A virtual CISO can help establish metrics and reporting suitable for executive and board-level communication, framing progress in terms of business risk rather than technical activity alone.
Can the CIS Controls be used alongside other frameworks an organization already follows?
Yes. The Controls are frequently used in conjunction with broader frameworks and can be mapped to them to support alignment and readiness efforts. This mapping is a common area where advisory input adds value, though it does not guarantee compliance or certification outcomes for any mapped framework. How the Controls integrate with existing frameworks may vary by organization, and the effort involved depends on organizational maturity and the clarity of the engagement scope.

Common misconceptions

Implementing CIS Controls v8.1 makes an organization compliant or certified against regulations and standards.
CIS Controls can support readiness and align with elements of frameworks or regulations, but implementing them does not by itself constitute compliance or certification. Formal compliance and certification depend on separate assessment processes and requirements defined by the relevant standard or regulator.
A virtual CISO engaged to help with CIS Controls will operationally implement and run all the safeguards.
A vCISO typically provides strategy, governance, prioritization, and program guidance around adopting the controls. Hands-on operational tasks such as tool administration, monitoring, or remediation execution are generally out of scope unless explicitly contracted, and often require the client's internal team or other providers.
Every organization should implement all CIS Controls safeguards in full.
The framework's Implementation Groups exist precisely because appropriate scope varies by organizational size, resources, and risk. Attempting to apply every safeguard regardless of maturity is often impractical, and value depends on scoping the effort realistically.

Best practices

Begin by scoping adoption to the appropriate Implementation Group based on your organization's resources, risk profile, and maturity rather than defaulting to full implementation.
Prioritize foundational safeguards such as asset, software, and data inventory early, since later controls often depend on knowing what must be protected.
Treat the controls as a governance and business risk exercise with executive stakeholders involved, not solely as a technical checklist owned by IT.
Clarify in any vCISO or advisory engagement which activities are strategy and direction versus hands-on operational implementation, and confirm who is responsible for execution.
If pursuing alignment with other frameworks or regulations, verify current mappings against official CIS documentation and treat control adoption as support for readiness rather than a guarantee of compliance or certification.
Reassess control implementation periodically as organizational maturity, assets, and risk change, and confirm that accountability for security decisions remains clearly assigned within the client organization.