CIS Critical Security Controls: The Complete Guide

By Rodrigo Lamadrid 15 July, 2026
CIS Critical Security Controls

The CIS Critical Security Controls are a prioritized, 18-control blueprint for cyber defense, maintained by a nonprofit and free for any organization to use.

They started as a grassroots effort in 2008 to study real-world attacks and turn that knowledge into a practical to-do list for defenders. They’ve since become one of the most widely adopted starting points in security, especially for teams that don’t know where to begin.

In this article, we’ll explain what the CIS Controls actually are, how their Implementation Groups work, how they compare to other frameworks, and how you can start implementing them without drowning in scope using Mindsec.

What Is CIS Security?

CIS Security refers to the work of the Center for Internet Security (CIS), the nonprofit that publishes the Controls along with CIS Benchmarks, hardened images, and other free security resources.

The 18 Controls themselves began life in 2008 as the SANS Top 20 Critical Security Controls, a grassroots effort by security practitioners frustrated with vague, compliance-driven guidance that never told anyone what to actually do first.

CIS took over stewardship in 2015. SANS still sits on the Controls’ editorial board today, a rare example of a framework surviving a change of ownership without losing its original practical focus.

The framework moved from 20 controls to 18 with version 8, being renamed the CIS Critical Security Controls along the way and shifting from a device-centric structure to an activity-centric one. This, since fixed devices and network boundaries matter far less in a cloud-first, hybrid, remote-work world than they used to.

The current release, version 8.1, arrived June 2024, adding formal alignment to NIST CSF 2.0, including a new “Govern” function that treats policy and process as first-class parts of the framework.

The 18 CIS Critical Security Controls

Version 8.1 organizes the Controls into 18 domains containing 153 individual Safeguards. Each one has a specific, measurable action rather than a vague goal.

The 18 controls run from foundational hygiene (i.e. Knowing what hardware and software you actually have), through more advanced areas like application security, incident response, and penetration testing.

A Safeguard (formerly called a Sub-Control before version 8), is deliberately narrow. It describes one concrete action so two organizations implementing the same Safeguard end up doing recognizably the same thing.

  • Inventory and Control of Enterprise Assets and Software. You can’t protect what you don’t know exists.
  • Data Protection, Secure Configuration, and Account and Access Control Management. The core hygiene controls most breaches trace back to.
  • Continuous Vulnerability Management and Audit Log Management. Finding weaknesses and keeping a forensic record before and after an incident.
  • Email and Web Browser Protections, Malware Defenses, and Network Infrastructure and Monitoring. The day-to-day attack surface most organizations actually face.
  • Security Awareness Training, Service Provider Management, and Application Software Security, part of the CIS Critical Security Controls. The people and third-party risks that technical controls alone can’t close.
  • Incident Response Management and Penetration Testing. Preparing for the incident that eventually happens, and proving your other 17 controls actually hold up.

None of this is meant to be tackled all at once. That’s exactly what Implementation Groups are for.

Implementation Groups: Where to Start

The most useful idea in the CIS security framework isn’t a control. It’s the Implementation Group: a self-assessed tier that tells you which Safeguards to apply first.

IG1 covers 56 Safeguards: essential cyber hygiene aimed at small organizations with limited security staff. These focus on stopping the common, non-targeted attacks that make up the bulk of real-world incidents.

IG2 adds Safeguards for organizations with more complex environments and dedicated IT staff. IG3 adds the remaining Safeguards for organizations facing sophisticated, targeted threats, handling highly sensitive data, or protecting critical infrastructure.

IG3 includes all 153 Safeguards across all 18 CIS Critical Security Controls. You don’t choose a group based on your actual risk profile, size, and available resources.

A small business that jumps straight to IG3 without the IG1 foundations in place usually ends up with expensive, sophisticated controls sitting on top of basic gaps. Like unpatched software or shared admin passwords that undermine everything built above them.

CIS Security Controls vs. Other Frameworks

The Controls are designed for what CIS calls “peaceful coexistence” with other frameworks (including NIST CSF, ISO 27001, and PCI DSS), rather than competing with them.

NIST CSF and ISO 27001 describe what a mature security program should cover at a governance level. The CIS Controls tell you specifically how, with concrete, testable Safeguards ranked by defensive value.

A common pattern is to use the CIS Controls as the practical, prioritized to-do list. Then map that work back to NIST CSF or ISO 27001 to satisfy a compliance requirement or client questionnaire. The mappings of v8.1 make that translation straightforward.

Organizations that already run NIST CSF or ISO 27001 often find they’ve unknowingly satisfied a large share of IG1 and IG2 already, since the underlying security activities overlap heavily even when the documentation and language differ.

Getting CIS Protection Right in Practice

Effective CIS protection isn’t about implementing all 18 CIS Critical Security Controls on day one. It’s about implementing IG1 completely before moving on to IG2 and so on. 

A realistic starting sequence: inventory your assets and software, fix access control and secure configuration basics. Then, layer in vulnerability management and log collection before touching anything in IG2 or IG3.

Supply chain risk deserves special attention here. Control 15, Service Provider Management, exists because your security is only as strong as the vendors who touch your sensitive data or manage critical systems on your behalf.

To tackle this specific control, Mindsec has a Third-Party Risk Management Tool to keep track of all your vendors, suppliers, their security programs, the sensitive data you share with each other, and the potential vulnerabilities from the relationship.

Third Party Risk Management Tool

 

CIS Critical Security Controls

Most organizations underestimate how long full IG1 implementation actually takes. Inventory and asset management sound simple, but often surface unmanaged cloud accounts, forgotten legacy systems, and other systemic mishaps.

Work With a CIS Security Company Like Mindsec

Many organizations bring in a CIS security company (i.e. A consultancy, an MSSP, or a compliance automation platform like Mindsec) to help them translate the Controls into an actionable plan.

What that partner should bring isn’t just familiarity with the 153 Safeguards behind the CIS Critical Security Controls. It’s the ability to map your existing tools and processes against them; flag genuine gaps, and keep the evidence organized for when a client, auditor, or cyber insurer asks for proof.

Mindsec is a compliance automation platform that helps organizations document, monitor, and evidence the CIS security controls they’ve implemented from the full Controls catalog.

We have support for ISO 27001, NIST CSF, SOC 2, and a dozen of additional frameworks, along with cross-mapping technology that supports multiple certifications at once with the same pieces of evidence.

Book a 15-minute demo to see how Mindsec turns the CIS Controls into an easy, audit-ready program.

Frequently Asked Questions

Is CIS Security the Same as Internet CIS?

Yes. The organization behind the Controls is officially called the Center for Internet Security, often shortened in casual searches to just “internet CIS” or simply “CIS.” 

They’re the same nonprofit, and the Controls themselves are completely free to download and use.

Are the CIS Security Controls Mandatory?

No, not on their own. They are voluntary best practices rather than a legal or regulatory requirement, though some contracts, cyber insurance policies, and state or sector rules do reference them as an expected baseline.

How Do I Choose an Implementation Group?

Start with your risk profile: a small business with limited IT staff almost always starts at IG1. Organizations handling highly sensitive data, facing sophisticated threats, or running critical infrastructure typically need IG2 or IG3 instead.

Rodrigo Lamadrid

Mindsec staff

Why Stall? Book A Call

Want to comply with CIS and other regulations? Book a call with our team and learn how we streamline this for you.

See Mindsec In Action