18 controls. Three Implementation Groups. One mapping.
CIS Controls v8 is the most practical list in this catalog. Eighteen controls, each broken into safeguards, ordered so that the ones that stop the most common attacks come first. It is not a regulation and not a certification — it is a prioritized answer to the question every small security team actually asks, which is what to do next.
That practicality is also where it gets lost. The list is easy to agree with and easy to leave in a spreadsheet, reviewed annually, drifting quietly out of date. A safeguard that was true in March and false in September is not a safeguard; it is a note about March.
Who it applies to
Any organization, by choice. CIS is a non-profit and the Controls are free to adopt, which is why they show up as the de facto baseline for teams without a regulator telling them what to do, and as the crosswalk reference for teams who have several. Insurers and customers increasingly ask about them by name for the same reason: the list is specific enough to answer honestly.
Implementation Groups, not maturity levels
The three Implementation Groups are the most commonly misread part of the framework. They are not maturity tiers you graduate through by doing the same things better — they define which safeguards apply to you, and they are cumulative. IG1 is the set CIS describes as essential cyber hygiene: the floor for every organization, including the smallest. IG2 and IG3 add safeguards as the sensitivity of what you hold and the sophistication of who wants it go up. Choosing your group is a risk decision, and it is one you should be able to justify later — which means recording why, not just what.
What it asks, in operating terms
Read as an operating requirement rather than a checklist, the Controls reduce to a handful of standing asks — each answerable from live state, not from last quarter's spreadsheet.
| What CIS asks | Where it is answered |
|---|---|
| Pick an Implementation Group, and justify it | Risk management · the decision and its rationale, dated |
| Know your assets and software before defending them | Asset register · one record every framework reads |
| Show each safeguard is in place now, not in March | Control library · continuously monitored |
| Carry the safeguards you have not met honestly | Exceptions · owned, dated, re-reviewed on expiry |
| Reuse the same evidence for ISO 27001 and CSF | Shared control library · mapped once, cited by each |
What you'd actually look at
In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a safeguard file is made of:
- Implementation Group
- IG2 · rationale recorded
- Controls covered
- 18/18 · safeguards scoped to IG2
- Evidence freshness
- continuous · provenance tracked
- Open exceptions
- 2 · each with an owner and an expiry
- Export
- sealed · sha256:4f88...b1c7
Where teams usually start
With a demo walked through by TruSecure — your Implementation Group scoped against controls you already operate, a single safeguard opened to its evidence, the same evidence answering ISO 27001 and CSF without being collected twice. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
CIS Controls v8 is a set of 18 prioritized cybersecurity safeguards organized into three Implementation Groups scaled by organizational size and risk. TruSecure maps CIS safeguards into the same control library used across every other framework it supports.