Skip to content
CIS Controls v8

CIS Controls v8 Checklist

The 18 CIS Critical Security Controls with Implementation Group (IG) mapping. Start with IG1 (56 safeguards) for essential cyber hygiene. Progress saved in your browser.

IG1 — Essential

56 safeguards. All organisations

IG2 — Enterprise

130 safeguards. Dedicated IT staff

IG3 — Mature

153 safeguards. Sophisticated threats

0%0/18 controls implemented
Asset Inventory & Configuration: 0/5
Access Control & Monitoring: 0/3
Browser, Email & Malware Defenses: 0/2
Data Recovery & Network Management: 0/3
Security Awareness & Service Providers: 0/2
Application Security & Incident Response: 0/3

Frequently Asked Questions

What are CIS Controls v8?

A prioritised set of 18 safeguards (formerly "controls") published by the Center for Internet Security, designed as a practical, evidence-based baseline for cyber defense.

What are CIS Implementation Groups (IG1/IG2/IG3)?

They tier the roughly 153 individual safeguards by organisational risk and resource profile — IG1 is essential cyber hygiene for any organisation, IG2 adds safeguards for organisations with more resources or risk, and IG3 covers the full set for high-risk organisations.

Where should a small organisation start with CIS Controls?

IG1 — it's designed as the minimum standard of care against the most common attacks and doesn't require dedicated security staff to implement.

Is CIS Controls v8 the same as CIS Controls v7?

No — v8 (2021) consolidated the prior 20 controls into 18, restructured them around activities rather than who manages the devices (reflecting cloud and remote work), and renumbered safeguards accordingly.