Framework · Last verified

CIS Critical Security Controls

The CIS Critical Security Controls are CIS's prescriptive defense framework; v8.1 is current, organized as 18 Controls across three Implementation Groups. There is no CIS Controls certificate from the owner: CIS publishes the framework and sells a separate SecureSuite membership. Version 8.1, announced 25 June 2024, aligned the Controls with NIST CSF 2.0's new Govern function.

Class
Framework
Owner
The Center for Internet Security, Inc. (CIS)
Last verified

What it is

The owner presents the framework as "The 18 CIS Critical Security Controls" — eighteen numbered controls, from inventory of enterprise assets through penetration testing, each broken into Safeguards.

Version 8.1 is the current edition, announced in the owner's press release of 25 June 2024. The owner's v8.1 page describes it, verbatim, as "an iterative update to v8" whose changes include "the addition of the “Govern” security function introduced in the National Institute of Standards and Technology (NIST) Cybersecurity Framework".

Adoption is tiered by Implementation Group rather than by a pass/fail audit; the three IG definitions are carried verbatim in the levels section below.

Access runs through a registration form on the owner's learn.cisecurity.org domain — no payment was requested on the pages read for this record, but the owner's pages do not describe the download with the word "free" either, so neither claim is made here.

The owner maintains a page titled "Laws, Regulations, and Other Endorsements of the CIS Controls", which lists U.S. state instruments it presents as referencing the Controls — including Ohio SB 220, Connecticut PA 21-119 and Nevada SB 302. Those statute texts were not opened for this record, so this page carries the owner's list as the owner's own presentation, not as verified legal effect.

Who owns it

The Center for Internet Security, Inc. — its pages describe it as a "501(c)(3) nonprofit organization".

Implementation Groups

  • IG1 — The owner's definition, verbatim: "IG1 is defined as “essential cyber hygiene,” the foundational set of cyber defense Safeguards that every enterprise should apply to guard against the most common attacks."
  • IG2 — Defined by the owner only relative to IG1 on the page read for this record: "IG2 builds upon IG1".
  • IG3 — The owner's sentence: "IG3 is comprised of all the Controls and Safeguards."

Who asks for it

No assessment body exists in the owner's program: organisations self-apply the Controls. The separate paid offering, CIS SecureSuite, is a membership product — its page does not describe a certification.

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"CIS Critical Security Controls." Certifidex, FutureTechnologies. Last verified 7 September 2026. https://certifidex.com/frameworks/cis-controls

All frameworks & audits →