Skip to main content
The state of ai impact assessment
Category: Security Frameworks

CIS Critical Security Controls

Also known as: CIS Controls, Critical Security Controls, CSC, CIS CSC
Simply put

The CIS Critical Security Controls are a set of 18 prioritized, community-developed cybersecurity best practices that organizations can adopt to strengthen their defenses against common cyber attacks. They are voluntary recommendations rather than a law, focusing on specific security activities rather than on particular roles or types of devices. Organizations use them to help focus their security efforts on measures that offer the most value.

Formal definition

The CIS Critical Security Controls (formerly the Critical Security Controls, abbreviated CSC) are a framework of 18 prioritized safeguards developed and maintained by the Center for Internet Security (CIS) with input from a community of cybersecurity practitioners. They constitute a voluntary set of cyber defense best practices—not a binding regulation—and are not a certification scheme in themselves, though they may be referenced contractually or mapped to other frameworks. The Controls prioritize defensive activities over roles and device ownership, and are periodically revised (the current major revision is CIS Controls v8); practitioners should verify the specific control content and version against the current authoritative source at cisecurity.org. Application to a given organization's risk profile requires professional judgment and, where the Controls are invoked by law or agreement, review against those specific obligations.

Why it matters

Organizations face a broad and shifting landscape of cyber threats, and security teams often struggle to decide where to focus limited resources. The CIS Critical Security Controls address this by offering a prioritized set of 18 community-developed safeguards, drawing on the knowledge of cybersecurity practitioners to help organizations concentrate their efforts on the measures that offer the most value. Rather than presenting an undifferentiated checklist, the Controls emphasize prioritization, which can be particularly useful for organizations building or maturing a security program.

Because the CIS Controls are a voluntary best-practice framework rather than a binding regulation, adopting them does not by itself satisfy any legal obligation. Their value lies in improving an organization's overall security posture and in providing a structured, recognized reference point that can be mapped to other frameworks or invoked contractually. Where the Controls are referenced in an agreement or incorporated by another obligation, they may take on practical force through that instrument rather than as law in their own right.

The Controls are periodically revised—the current major revision is CIS Controls v8—so their specific content changes over time. Practitioners relying on them should confirm which version applies to their circumstances and verify the specific safeguards against the current authoritative source, since application to a given organization's risk profile requires professional judgment.

Who it's relevant to

Information security teams and CISOs
Security professionals responsible for building or maturing a defense program can use the prioritized structure of the CIS Controls to focus resources on the measures identified as offering the most value. Because the framework emphasizes activities over roles and device ownership, it can help teams translate broad security goals into specific defensive actions. Teams should verify the current version and safeguard content against the authoritative source before relying on it.
Compliance and GRC professionals
Governance, risk, and compliance staff may encounter the CIS Controls as a reference point that can be mapped to other cybersecurity frameworks or invoked through contracts. It is important to keep in mind that the Controls are a voluntary best-practice framework and not a regulation or a certification scheme; adopting them does not by itself satisfy a legal obligation unless they are incorporated by agreement or by another requirement.
Auditors and assessors
Those evaluating an organization's security posture may use the CIS Controls as a structured benchmark against which practices can be assessed. Because the Controls are periodically revised, assessors should confirm which version an organization has adopted and should distinguish an assessment against these voluntary safeguards from a formal certification, which the Controls do not themselves provide.
Organizations seeking to strengthen cyber defenses
Enterprises of varying sizes and sectors that want to improve their overall security posture against common cyber attacks may adopt the CIS Controls as a prioritized starting point. Application to a specific organization's risk profile requires professional judgment, and where the Controls are invoked by law or agreement, they should be reviewed against those particular obligations.

Inside CIS Controls

Prioritized Set of Safeguards
The CIS Critical Security Controls are a curated, ordered set of defensive actions intended to mitigate the most common and impactful cyberattacks. They are structured to help organizations focus on high-value activities rather than attempting to address every possible risk at once.
Controls and Safeguards Structure
The framework is organized into a set of top-level Controls, each of which is broken down into more granular Safeguards (sometimes historically referred to as sub-controls) that describe specific actions an organization can take.
Implementation Groups (IGs)
The Controls are commonly grouped into implementation tiers that allow organizations to scope their adoption according to size, resources, and risk profile, so that smaller or less resource-rich organizations can start with a foundational subset. Practitioners should verify the current tier definitions against the latest official CIS publication.
Voluntary, Non-Regulatory Nature
The Controls are a voluntary best-practice framework published by the Center for Internet Security. They are not a law or regulation and carry no independent legal force unless an organization adopts them contractually or a regulator or standard references them.
Mapping to Other Frameworks
The Controls are frequently cross-referenced or mapped to other standards and frameworks so organizations can align their control activities. Any specific mappings should be confirmed against current authoritative CIS materials, as they are periodically updated.

Common questions

Answers to the questions practitioners most commonly ask about CIS Controls.

Are the CIS Critical Security Controls a legal requirement that organizations must comply with?
No. The CIS Critical Security Controls are a voluntary, prescriptive set of cybersecurity best practices maintained by the Center for Internet Security, not a law or regulation. They carry no legal force in themselves. They may, however, become effectively binding in specific circumstances—for example, when a contract, a sector regulator, or an organization's own policy references them, or where they are cited as evidence of reasonable security practices. Any binding effect derives from that external instrument, not from the Controls as such. Readers should confirm whether a particular obligation applies to their circumstances against the relevant contract or legal source.
Is implementing the CIS Controls the same as achieving a formal certification?
No. The CIS Critical Security Controls are an implementation framework, not a certification scheme. Adopting them is a matter of implementing and operating the recommended safeguards; there is no accredited pass/fail certificate issued for the Controls in the way certification is awarded against certain formal standards. An organization may assess or attest to its alignment with the Controls, and third parties may review that alignment, but that is distinct from the audited, accredited certification associated with some other schemes. Treat 'implementing the Controls' and 'being certified' as separate concepts.
How do the Implementation Groups help an organization decide which safeguards to prioritize?
The CIS Controls organize safeguards into Implementation Groups intended to reflect differing organizational size, resources, and risk exposure, so that an organization can start with a foundational tier and expand as maturity and risk warrant. In practice, selecting an Implementation Group is a risk-based decision that should account for the sensitivity of data handled, threat exposure, and available resources. The grouping is guidance for prioritization rather than a rigid mandate, and organizations generally tailor the safeguards to their own environment. Verify the current group definitions and safeguard mappings against the latest published version, as these are periodically revised.
How can the CIS Controls be mapped to regulatory or other framework obligations we already face?
The Center for Internet Security has historically published mappings between the Controls and various other frameworks and regulatory expectations to help organizations avoid duplicative effort. Such mappings can support an integrated control set, but they are aids to interpretation rather than authoritative statements of legal compliance—satisfying a mapped safeguard does not automatically discharge a distinct legal obligation, which must be assessed against the governing text itself. Because both the Controls and the referenced instruments are periodically amended, confirm that any mapping reflects current versions before relying on it, and apply professional judgment to your specific facts.
What does it take to operate the CIS Controls on an ongoing basis rather than as a one-time exercise?
The Controls are generally intended to be operated continuously, not implemented once and left static. Sustained use typically involves maintaining accurate asset and software inventories, keeping configurations and access current, monitoring for changes, and periodically reassessing which safeguards apply as the environment and threat landscape evolve. Organizations often assign ownership for each safeguard and integrate the Controls into existing security operations and governance processes. The specific cadence and depth of these activities depend on organizational risk, size, and resources, and should be defined in internal policy.
How should an organization measure its progress against the CIS Controls?
Progress is commonly gauged through self-assessment or third-party review of which safeguards are implemented and how effectively they operate, and the Center for Internet Security has provided tooling and self-assessment resources to support this. Such measurement is an assessment activity—an evaluation of current state against the framework—and should be distinguished from a formal audit conducted to a defined attestation standard. Results are most useful when tied to defined implementation targets and reviewed over time. Because the framework and its supporting tools change between versions, confirm you are assessing against the current release.

Common misconceptions

Implementing the CIS Controls makes an organization legally compliant with data protection or security regulations.
The CIS Controls are a voluntary framework, not a regulation. Adopting them may support compliance efforts and demonstrate diligence, but it does not by itself satisfy legal obligations under regimes such as the GDPR, HIPAA, or other jurisdiction-specific laws. Legal compliance must be assessed against the applicable statute or regulation directly.
There is a formal CIS Controls 'certification' that organizations can obtain, similar to ISO/IEC 27001 certification.
The CIS Controls are a set of recommended safeguards rather than a formal certification scheme in the way ISO/IEC 27001 operates through accredited certification bodies. Organizations can assess and report on their alignment with the Controls, but readers should verify the availability and nature of any assessment or attestation offerings against current official CIS sources rather than assuming an equivalent certification exists.
Every organization must implement all of the Controls in full to benefit from the framework.
The framework is designed to be scoped through Implementation Groups so organizations can adopt safeguards proportionate to their size, resources, and risk. Full implementation of every Safeguard is generally not expected of all organizations, and a phased, risk-based approach is anticipated by the framework's structure.

Best practices

Begin by determining the appropriate Implementation Group for your organization based on size, resources, and risk profile, rather than attempting to adopt every Safeguard at once.
Treat the Controls as one input to a broader compliance and security program, and separately verify obligations under any applicable laws or regulations that govern your jurisdiction and sector.
Distinguish between demonstrating alignment with the Controls and achieving formal certification under a standard such as ISO/IEC 27001, and document which you are actually pursuing.
Where you rely on mappings between the CIS Controls and other frameworks, confirm those mappings against the current official CIS publications, since they are periodically revised.
Prioritize the foundational safeguards first as an ordered baseline, then expand coverage as maturity and resources allow.
Verify that you are working from the latest published version of the Controls, as the framework is periodically updated and prior versions may be superseded.
Promotional banner for the Penetration Report Template Kit