Most frameworks tell you what outcomes to achieve. The CIS Controls tell you what to do first, and the CIS Benchmarks tell you exactly which setting to change. That specificity is why they are the most practical starting point for organisations with more urgency than process maturity - and they are free.
Two things, often confused
- CIS Critical Security Controls - a prioritised set of safeguards covering what an organisation should do, ordered by impact. This is a security programme in outline.
- CIS Benchmarks - detailed, system-specific hardening configurations for operating systems, cloud platforms, databases, browsers and more. This is the "which setting" layer.
You use them together: the Controls tell you to harden systems; the Benchmarks tell you precisely how for each platform.
Implementation Groups - the prioritisation that makes it usable
The Controls are divided into three Implementation Groups so you are not asked to do everything at once:
- IG1 - essential cyber hygiene. The baseline every organisation should achieve, aimed at limited-resource organisations defending against untargeted attacks.
- IG2 - for organisations with more complexity and sensitive data, adding controls for a more capable adversary.
- IG3 - for organisations facing targeted attacks, where a breach would have severe consequences.
IG1 is the most useful concept in the whole framework. It gives a small team a defensible answer to "what should we do first?" that is not simply "everything".
What the Controls cover
The safeguards run in a deliberate order, starting with knowing what you have:
- Inventory of enterprise assets and of software
- Data protection and secure configuration
- Account and access management
- Continuous vulnerability management
- Audit log management
- Email, web, malware and data recovery defences
- Network infrastructure management and monitoring
- Security awareness and skills training
- Service provider management, application security, incident response and penetration testing
Note the ordering principle: inventory first. Every subsequent control assumes you know what exists.
Measure yourself against CIS - and reuse it
GRC Copilot assesses you against the CIS Controls and Benchmarks, and maps the same evidence into ISO 27001, the NCA ECC and whatever else you report against.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
Using the Benchmarks without breaking production
Benchmarks are thorough, which means applying one wholesale to a running system is a reliable way to break something. A workable approach:
- Choose a profile. Benchmarks typically offer a Level 1 profile (practical, low disruption) and Level 2 (defence in depth, higher impact). Start at Level 1.
- Assess before enforcing. Scan against the benchmark to see your current state.
- Test in non-production, then roll out progressively.
- Document deviations with justification - a deliberate, recorded exception is defensible; an undocumented gap is a finding.
- Bake it into images so new systems start hardened rather than being remediated later.
- Monitor for drift, because configuration decays.
Why they help with other frameworks
CIS is not certifiable, and no auditor issues a CIS certificate. Its value in a compliance programme is different: it gives you a concrete, defensible answer when a framework says "apply secure configuration". Pointing at "systems built to CIS Benchmark Level 1, with documented exceptions" is far stronger evidence than "we harden our systems".
Published mappings connect the Controls to ISO 27001, NIST CSF and others, so the work counts in several places at once.
Frequently asked questions
Can we be certified against CIS?
No. There is no CIS certification. It is a free, widely respected reference used to implement and evidence controls that other frameworks require.
Which Implementation Group should we target?
IG1 for essentially everyone as a floor. Move to IG2 or IG3 based on data sensitivity and threat exposure, not on ambition.
Do Benchmarks conflict with vendor guidance?
Occasionally. Where they do, follow the vendor for supportability and document the deviation with your reasoning.
Is this enough for ISO 27001 or SOC 2?
It covers technical controls strongly but not the management system - risk assessment, internal audit, management review. Use CIS for the technical layer within a broader framework.
Key takeaways
- Controls tell you what and in what order; Benchmarks tell you exactly how.
- IG1 is a defensible answer to "what first?" for a small team.
- Start at Benchmark Level 1, test first, and document deviations.
- Not certifiable - but excellent evidence for frameworks that are.