A prioritised set of 18 technical security controls with three Implementation Groups. Not certifiable, but among the most practical starting points available.
The CIS Critical Security Controls are a prioritised set of 18 technical and procedural safeguards published by the Center for Internet Security. They are ordered deliberately, so that working through them in sequence delivers risk reduction faster than tackling controls at random.
What makes them useful is the Implementation Group model. Controls are grouped into IG1, IG2 and IG3, scaled to organisational complexity, resources and threat exposure. IG1 is described as essential cyber hygiene for organisations with limited security expertise protecting against common, non-targeted attacks. IG2 and IG3 add depth for organisations with greater exposure.
That scaling is the point. Most Australian small and mid-sized organisations sit comfortably at IG1, and IG1 fully implemented is a materially better security position than IG3 half-attempted.
There is no CIS Controls certification. No certificate exists and nobody can issue you one. What the controls provide is a practical, evidence-based implementation path — which is why they work well as the technical layer beneath a certifiable framework rather than as an alternative to one.
Where nobody is demanding a particular certificate but the security posture genuinely needs work. This is where CIS Controls are most valuable and most under-used.
The prioritised ordering means early work delivers disproportionate risk reduction, which makes it easier to demonstrate progress to a board or an investor.
CIS Controls map into ISO 27001, NIST CSF and the Essential Eight, so the technical work is not wasted when a formal obligation later arrives.
The controls are more prescriptive than ISO Annex A, which some teams find considerably easier to act on.
IG1, IG2 or IG3, based on organisational complexity, security expertise and threat exposure. Choosing honestly matters — IG1 fully implemented beats IG3 half-attempted every time.
Against evidence rather than intent. The controls are specific enough that assessment is relatively unambiguous, which is one of their strengths.
Enterprise asset inventory and software inventory are the first two controls for good reason: no other control is reliable if you do not know what you have. Most organisations find this step harder and more revealing than expected.
The ordering reflects real-world attack data, so working sequentially delivers risk reduction faster than tackling controls in whatever order is convenient.
Inventories drift, configurations decay. The controls assume ongoing maintenance rather than one-time implementation.
Into ISO 27001, NIST CSF or the Essential Eight, where the same technical work supports a formal obligation.
Soveriq assesses against the Implementation Group that genuinely fits your organisation, builds the remediation roadmap in the controls' own priority order, and starts with the asset and software inventories because everything downstream depends on them.
Where a formal obligation exists, we map the technical work outward so it also serves ISO 27001, NIST CSF or Essential Eight requirements rather than being done twice.
Being direct about what this is. There is no CIS Controls certificate and we will not imply otherwise. For an organisation with no contractual framework obligation, this is often the most cost-effective place to start — real risk reduction without the overhead of a certification programme. We would rather tell you that than sell you a certificate you do not need.
Modules 03 and 04 do not apply in the certification sense, because there is no certification audit. Where the work supports an ISO 27001 or other certification, those modules apply to that programme.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day.
No. There is no certification scheme. If a provider offers you CIS Controls certification, that tells you something useful about the provider. What you can do is assess against them, implement them and evidence them — which is where the value is.
For an Australian organisation with government or defence obligations, the Essential Eight is what contracts name, so start there. CIS Controls are broader — 18 controls against 8 strategies — and cover ground the Essential Eight does not, including asset inventory, data protection and incident response. Many organisations use both.
IG1 for organisations with limited security expertise protecting against common attacks; IG2 and IG3 as complexity and threat exposure increase. Most Australian SMEs sit at IG1, and IG1 fully implemented is a meaningfully better position than IG3 partially attempted.
Well. ISO 27001 is the management system; CIS Controls are technical controls that can populate it. Using CIS to drive technical implementation while ISO 27001 provides governance is a coherent and common combination.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope