All Frameworks

Get Your MSP CIS Controls Aligned the Easy Way

CIS

The CIS Critical Security Controls (currently v8.1) are 18 prioritized control categories with 153 specific safeguards. Unlike abstract frameworks, CIS tells you exactly what to do, in what order. Three Implementation Groups (IG1, IG2, IG3) scale the safeguards to your organization size and risk profile.

  • CIS v8.1 readiness assessment in 30 minutes
  • All 153 safeguards mapped to UCS Practice Domains
  • Implementation Group selection (IG1 / IG2 / IG3)
  • CIS Benchmarks for Microsoft, Linux, AWS, Azure, GCP

Join 500+ MSPs CIS Controls-aligned through Cyber Verify.

Interactive demo

See CIS in action

No sales call — enter your email and explore Cyber Verify yourself, right now.

30-minute walkthrough. No prep required.

Prefer a guided walkthrough? Book a 30-min call.

Logo
Your Logo Here
Expertise
90.48%
Trust
100%
Security
46.88%
Resilience
76.19%
Transparency
100%

CIS

64.27%Complete
Inventory and Control of Enterprise Assets (Control 1)
IG1 · Foundational Cyber Hygiene
Go →
Secure Configuration of Enterprise Assets (Control 4)
IG1 · Foundational Cyber Hygiene
Go →
Access Control Management (Control 6)
IG1 · Foundational Cyber Hygiene
Go →
Audit Log Management (Control 8)
IG2 · Operational Maturity
Go →
Network Monitoring and Defense (Control 13)
IG2 · Operational Maturity
Go →
v8.1
Current version
18
Control categories
153
Specific safeguards
IG1 / IG2 / IG3
Implementation Groups

What are the CIS Controls?

The CIS Critical Security Controls (formerly known as the 'SANS Top 20' before CIS adopted them) are a prioritized set of cybersecurity safeguards published by the Center for Internet Security. The current version is v8.1 (released 2024), reorganizing v7's 20 controls into 18 categories with 153 specific safeguards.

Three Implementation Groups (IGs) scale the safeguards to organization size and risk:

  • IG1 (Essential Cyber Hygiene): 56 safeguards. The minimum baseline. Focused on data, software, and asset management foundations.
  • IG2: 130 safeguards (IG1 + 74 more). For organizations handling sensitive data with moderate threat exposure.
  • IG3: All 153 safeguards. For high-target organizations with sensitive data and elevated threat profiles.

Why CIS matters for MSPs

  • Most actionable framework. Where NIST CSF says 'maintain access control,' CIS Control 6 says 'establish, document, and maintain an account management process; uniquely assign authentication to each individual; remove accounts within X days of termination.' That specificity is gold for MSP operations.
  • Cyber insurance leverage. Carriers price CIS-mature MSPs and clients more favorably. Demonstrating IG1 implementation often unlocks 10–25% better rates.
  • Maps to everything. CIS publishes mappings to NIST CSF, ISO 27001, PCI DSS, HIPAA, and others. Implementing IG1 satisfies the baseline of most major frameworks.

Which clients reference CIS

  • US state and local governments (many state cybersecurity laws reference CIS)
  • Education sector (CIS partners with EDUCAUSE on K-12 and higher ed)
  • Critical infrastructure operators
  • Cyber insurance applicants
  • Any client whose RFP / SIG / questionnaire references 'CIS Controls' or 'CIS Top 20'

Where CIS applies

CIS is US-headquartered but globally adopted. CIS Controls are referenced in cybersecurity laws and policies across the US, EU, UK, Australia, Singapore, India, and other jurisdictions. CIS Benchmarks are the most-downloaded hardening guides on the internet.

How Cyber Verify accelerates CIS

  • All 153 v8.1 safeguards mapped to UCS Practice Domains and policy templates
  • Implementation Group selection guidance based on client risk profile
  • CIS Benchmark integration with major MSP configuration tools
  • CORTEX scoring tracks safeguard maturity (Implementation Group + maturity level)
  • Cyber insurance documentation generated to satisfy underwriter questionnaires

Why MSPs care about CIS

  • Most actionable cybersecurity guidance available — concrete controls, not abstract principles
  • IG1 maps closely to NIST CSF Tier 1, ISO 27001 baseline, and Cyber Essentials — overlap is huge
  • CIS Benchmarks provide hardening configurations for major OS and cloud platforms
  • Cyber insurance carriers explicitly map underwriting questions to CIS Controls
  • Free reference framework — no licensing cost beyond optional CIS Hardened Images
  • Strong signal of cybersecurity maturity in security-conscious procurement conversations
How Cyber Verify helps

The Cyber Verify path to CIS.

Select Implementation Group

IG1 (essential cyber hygiene, ~56 safeguards) for small orgs and most MSP starting points. IG2 (~130 safeguards) for orgs handling sensitive data. IG3 (all 153) for high-risk, high-target orgs. Cyber Verify's scoping interview lands you on the right IG in 30 minutes.

Establish asset inventory

CIS Controls 1 and 2 — Inventory of Enterprise Assets and Software — are foundational. Without them, every other control is partial. We help you build a defensible inventory using your existing RMM and discovery tools.

Implement IG1 safeguards

Roll out the 56 IG1 safeguards in priority order. Cyber Verify's templates map each safeguard to specific MSP control implementations and evidence requirements.

Apply CIS Benchmarks to systems

Use the appropriate CIS Benchmark for each platform (Windows Server, Linux, M365, AWS, Azure, GCP). Cyber Verify integrates with your configuration management tools to track Benchmark compliance.

Continuous monitoring + IG progression

Once IG1 is solid, progress to IG2 for sensitive-data clients. CORTEX scoring tracks safeguard implementation maturity continuously.

FAQ

Common questions about CIS

Is CIS a certification?

No — CIS Controls are guidance, not certifiable. There's no CIS audit. Some organizations use SOC 2 or ISO 27001 audits to evidence CIS Control implementation, since the controls map cleanly. CIS itself remains a free, prescriptive reference.

How does CIS relate to NIST CSF?

CIS Controls are more prescriptive ('do these specific things') while NIST CSF is more strategic ('manage these outcomes'). CIS publishes mappings between the two. Many MSPs use CIS as their tactical implementation playbook and NIST CSF as their strategic governance framework — they're complementary, not competing.

Cyber insurance leverage?

Yes — many cyber insurance underwriters explicitly map their security questionnaires to CIS Controls. Demonstrating IG1 implementation typically unlocks better rates. CIS publishes a Community Defense Model that shows cyber insurers how the controls map to defenses against the most common attack patterns.

Should we start with IG1 or jump to IG2?

Always start with IG1. It's the foundation — even sophisticated organizations frequently have gaps in IG1 safeguards (asset inventory, account management, secure configuration). Lock IG1 down across your entire client base, then progress sensitive-data clients to IG2.

Ready to get audit-ready on CIS?

Book a 30-minute demo call with our team to walk through your timeline and certification path.