Frameworks

CIS Critical Security Controls v8.1

The prioritized to-do list of security — start where attacks actually happen.

Book a demo

The CIS Controls answer the practitioner's question every framework dodges: what should we do first? Eighteen controls, ordered by attack relevance, split into implementation groups so a ten-person startup and a bank both know their next move.

Implementation groups keep it honest

IG1 is essential cyber hygiene — 56 safeguards every organization needs, from asset inventory to MFA. IG2 layers on controls for teams managing sensitive data at scale; IG3 completes the set for mature, targeted enterprises. You adopt the group that matches your reality, then grow.

The perfect companion framework

CIS Controls are prescriptive where CSF is descriptive and audits are retrospective. Teams commonly run CIS as the engineering checklist while presenting posture through CSF and attesting through SOC 2 or ISO 27001 — three views of the same underlying work.

How Compriska helps

Compriska tracks safeguard implementation by group, evidences each one, and cross-maps CIS safeguards to every other framework you run — so hardening work done by engineering shows up instantly in audit readiness.

Frequently asked questions

Where should a small company start with CIS Controls?

IG1, without hesitation — its 56 safeguards are explicitly designed as the minimum standard of hygiene and block the commodity attacks that cause most breaches.

Other frameworks

Automate CIS Controls with Compriska

See how cross-mapped controls, continuous evidence, and AI workflows change the cost of compliance.

Book a demo