CIS Controls — Critical Security Controls

A prioritised set of 18 technical security controls with three Implementation Groups. Not certifiable, but among the most practical starting points available.

Center for Internet Security (CIS). Not a certification scheme.

What it is

The CIS Critical Security Controls are a prioritised set of 18 technical and procedural safeguards published by the Center for Internet Security. They are ordered deliberately, so that working through them in sequence delivers risk reduction faster than tackling controls at random.

What makes them useful is the Implementation Group model. Controls are grouped into IG1, IG2 and IG3, scaled to organisational complexity, resources and threat exposure. IG1 is described as essential cyber hygiene for organisations with limited security expertise protecting against common, non-targeted attacks. IG2 and IG3 add depth for organisations with greater exposure.

That scaling is the point. Most Australian small and mid-sized organisations sit comfortably at IG1, and IG1 fully implemented is a materially better security position than IG3 half-attempted.

There is no CIS Controls certification. No certificate exists and nobody can issue you one. What the controls provide is a practical, evidence-based implementation path — which is why they work well as the technical layer beneath a certifiable framework rather than as an alternative to one.

Who it's for

Organisations with no specific framework obligation

Where nobody is demanding a particular certificate but the security posture genuinely needs work. This is where CIS Controls are most valuable and most under-used.

Organisations at the start of a security programme

The prioritised ordering means early work delivers disproportionate risk reduction, which makes it easier to demonstrate progress to a board or an investor.

Organisations working toward a certifiable framework

CIS Controls map into ISO 27001, NIST CSF and the Essential Eight, so the technical work is not wasted when a formal obligation later arrives.

Technical teams wanting specificity

The controls are more prescriptive than ISO Annex A, which some teams find considerably easier to act on.

Why implement it

  • Prioritisation reflects real attack data. The ordering is derived from how compromises actually happen, so sequential implementation reduces risk faster than an arbitrary order.
  • Implementation Groups make it proportionate. A small organisation is not held to enterprise expectations, which makes the framework genuinely usable rather than aspirational.
  • It is specific. The controls tell you what to do at a level of detail management system standards deliberately avoid, which suits technical teams.
  • It maps outward. The same technical work supports ISO 27001, NIST CSF and Essential Eight obligations rather than being a parallel effort.
  • No certification overhead. For organisations that need better security rather than a certificate, this is the cheapest credible route to real improvement.

How implementation works

1. Determine your Implementation Group

IG1, IG2 or IG3, based on organisational complexity, security expertise and threat exposure. Choosing honestly matters — IG1 fully implemented beats IG3 half-attempted every time.

2. Assess against the applicable controls

Against evidence rather than intent. The controls are specific enough that assessment is relatively unambiguous, which is one of their strengths.

3. Start with the inventories

Enterprise asset inventory and software inventory are the first two controls for good reason: no other control is reliable if you do not know what you have. Most organisations find this step harder and more revealing than expected.

4. Work through in priority order

The ordering reflects real-world attack data, so working sequentially delivers risk reduction faster than tackling controls in whatever order is convenient.

5. Sustain

Inventories drift, configurations decay. The controls assume ongoing maintenance rather than one-time implementation.

6. Map outward

Into ISO 27001, NIST CSF or the Essential Eight, where the same technical work supports a formal obligation.

How Soveriq helps

Soveriq assesses against the Implementation Group that genuinely fits your organisation, builds the remediation roadmap in the controls' own priority order, and starts with the asset and software inventories because everything downstream depends on them.

Where a formal obligation exists, we map the technical work outward so it also serves ISO 27001, NIST CSF or Essential Eight requirements rather than being done twice.

Being direct about what this is. There is no CIS Controls certificate and we will not imply otherwise. For an organisation with no contractual framework obligation, this is often the most cost-effective place to start — real risk reduction without the overhead of a certification programme. We would rather tell you that than sell you a certificate you do not need.

What the engagement looks like

  • Module 01 — Gap analysis against your Implementation Group, with a prioritised remediation roadmap.
  • Module 02 — Build. Control implementation, starting with asset and software inventory because nothing else is reliable without them.
  • Module 05 — Continuous compliance, keeping inventories and configurations current.

Modules 03 and 04 do not apply in the certification sense, because there is no certification audit. Where the work supports an ISO 27001 or other certification, those modules apply to that programme.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.

Common questions

Can we be certified against the CIS Controls?

No. There is no certification scheme. If a provider offers you CIS Controls certification, that tells you something useful about the provider. What you can do is assess against them, implement them and evidence them — which is where the value is.

CIS Controls or Essential Eight?

For an Australian organisation with government or defence obligations, the Essential Eight is what contracts name, so start there. CIS Controls are broader — 18 controls against 8 strategies — and cover ground the Essential Eight does not, including asset inventory, data protection and incident response. Many organisations use both.

Which Implementation Group applies to us?

IG1 for organisations with limited security expertise protecting against common attacks; IG2 and IG3 as complexity and threat exposure increase. Most Australian SMEs sit at IG1, and IG1 fully implemented is a meaningfully better position than IG3 partially attempted.

Where does it fit alongside ISO 27001?

Well. ISO 27001 is the management system; CIS Controls are technical controls that can populate it. Using CIS to drive technical implementation while ISO 27001 provides governance is a coherent and common combination.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope