Skip to main content
—
Framework library
Framework module · cis-controls-v8-1

CIS Critical Security Controls

A prioritized, prescriptive set of defensive actions organized into three implementation groups — the practical starting list when a team has no framework yet.

v8.1 · Center for Internet Security · published 2024-06-25

Standing today
Directory entry

00Answer

from the registry record
What is CIS Critical Security Controls?
A prioritized, prescriptive set of defensive actions organized into three implementation groups — the practical starting list when a team has no framework yet.
Who does CIS Critical Security Controls apply to?
CIS Critical Security Controls applies to all sectors, global, per Center for Internet Security.
What is the current version of CIS Critical Security Controls?
The current edition is v8.1, issued by Center for Internet Security and published 2024-06-25. Source: https://www.cisecurity.org/controls/v8-1.
What does an assessment under CIS Critical Security Controls require?
153 control units are on record (Safeguards in CIS Controls v8.1 across 18 Controls, as published by CIS.), organized into 3 control families: Implementation Group 1, Implementation Group 2, Implementation Group 3.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

CIS Critical Security Controls is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

CIS publishes the Controls under stated noncommercial terms. Commercial software ingestion, adaptation, or distribution requires the applicable CIS approval or license; confirm rights before embedding safeguard text.

02Registry record

checked 2026-08-30
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
153Safeguards in CIS Controls v8.1 across 18 Controls, as published by CIS.
Control families
Implementation Group 1 · Implementation Group 2 · Implementation Group 3
Applies to
all sectors · global
Verification
Primary — the issuing body's own page was read and states this version. checked 2026-08-30

03Version ledger

2 editions
v8Supersededdate not published
v8.1Current edition · supersedes v82024-06-25

05Change history

06Related frameworks

scored from registry facts
  1. ASD Essential EightMaturity Model (November 2023)

    Also applies to all sectors · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.

  2. ISO/IEC 270012022 (Amd 1:2024)

    Also applies to all sectors · The international certifiable standard for an information security management system. Amendment 1:2024 added climate-change considerations to clauses 4.1 and 4.2. The 2013-edition certificate-transition deadline was 2025-10-31; no legitimate 2013-certified organization remains.

  3. Also applies to all sectors · The controls catalog underlying ISO/IEC 27001 Annex A — a genuinely separate, currently published standard, not a duplicate of 27001. Buyers who ask for '27001 evidence' routinely cite 27002 control numbers.

  4. Also applies to all sectors · Cloud-specific information security guidance for both cloud customers and providers, extending ISO/IEC 27002 with shared-responsibility and cloud-control guidance. It is guidance, not a standalone certification or a claim about ControlFrame's cloud environment.

CIS Critical Security Controls | ControlFrame