What are the CIS Controls?
The CIS Critical Security Controls (formerly known as the 'SANS Top 20' before CIS adopted them) are a prioritized set of cybersecurity safeguards published by the Center for Internet Security. The current version is v8.1 (released 2024), reorganizing v7's 20 controls into 18 categories with 153 specific safeguards.
Three Implementation Groups (IGs) scale the safeguards to organization size and risk:
- IG1 (Essential Cyber Hygiene): 56 safeguards. The minimum baseline. Focused on data, software, and asset management foundations.
- IG2: 130 safeguards (IG1 + 74 more). For organizations handling sensitive data with moderate threat exposure.
- IG3: All 153 safeguards. For high-target organizations with sensitive data and elevated threat profiles.
Why CIS matters for MSPs
- Most actionable framework. Where NIST CSF says 'maintain access control,' CIS Control 6 says 'establish, document, and maintain an account management process; uniquely assign authentication to each individual; remove accounts within X days of termination.' That specificity is gold for MSP operations.
- Cyber insurance leverage. Carriers price CIS-mature MSPs and clients more favorably. Demonstrating IG1 implementation often unlocks 10–25% better rates.
- Maps to everything. CIS publishes mappings to NIST CSF, ISO 27001, PCI DSS, HIPAA, and others. Implementing IG1 satisfies the baseline of most major frameworks.
Which clients reference CIS
- US state and local governments (many state cybersecurity laws reference CIS)
- Education sector (CIS partners with EDUCAUSE on K-12 and higher ed)
- Critical infrastructure operators
- Cyber insurance applicants
- Any client whose RFP / SIG / questionnaire references 'CIS Controls' or 'CIS Top 20'
Where CIS applies
CIS is US-headquartered but globally adopted. CIS Controls are referenced in cybersecurity laws and policies across the US, EU, UK, Australia, Singapore, India, and other jurisdictions. CIS Benchmarks are the most-downloaded hardening guides on the internet.
How Cyber Verify accelerates CIS
- All 153 v8.1 safeguards mapped to UCS Practice Domains and policy templates
- Implementation Group selection guidance based on client risk profile
- CIS Benchmark integration with major MSP configuration tools
- CORTEX scoring tracks safeguard maturity (Implementation Group + maturity level)
- Cyber insurance documentation generated to satisfy underwriter questionnaires