Skip to main content
FRAMEWORK

18 controls. Three Implementation Groups. One mapping.

CIS Controls v8 is the most practical list in this catalog. Eighteen controls, each broken into safeguards, ordered so that the ones that stop the most common attacks come first. It is not a regulation and not a certification — it is a prioritized answer to the question every small security team actually asks, which is what to do next.

That practicality is also where it gets lost. The list is easy to agree with and easy to leave in a spreadsheet, reviewed annually, drifting quietly out of date. A safeguard that was true in March and false in September is not a safeguard; it is a note about March.

Who it applies to

Any organization, by choice. CIS is a non-profit and the Controls are free to adopt, which is why they show up as the de facto baseline for teams without a regulator telling them what to do, and as the crosswalk reference for teams who have several. Insurers and customers increasingly ask about them by name for the same reason: the list is specific enough to answer honestly.

Implementation Groups, not maturity levels

The three Implementation Groups are the most commonly misread part of the framework. They are not maturity tiers you graduate through by doing the same things better — they define which safeguards apply to you, and they are cumulative. IG1 is the set CIS describes as essential cyber hygiene: the floor for every organization, including the smallest. IG2 and IG3 add safeguards as the sensitivity of what you hold and the sophistication of who wants it go up. Choosing your group is a risk decision, and it is one you should be able to justify later — which means recording why, not just what.

What it asks, in operating terms

Read as an operating requirement rather than a checklist, the Controls reduce to a handful of standing asks — each answerable from live state, not from last quarter's spreadsheet.

CIS Controls requirements · how TruSecure answers them
What CIS asksWhere it is answered
Pick an Implementation Group, and justify itRisk management · the decision and its rationale, dated
Know your assets and software before defending themAsset register · one record every framework reads
Show each safeguard is in place now, not in MarchControl library · continuously monitored
Carry the safeguards you have not met honestlyExceptions · owned, dated, re-reviewed on expiry
Reuse the same evidence for ISO 27001 and CSFShared control library · mapped once, cited by each

What you'd actually look at

In the dashboard, every figure opens on click to the control, the evidence and the person behind it. This excerpt is what a safeguard file is made of:

CIS Controls file · excerptSample data
Implementation Group
IG2 · rationale recorded
Controls covered
18/18 · safeguards scoped to IG2
Evidence freshness
continuous · provenance tracked
Open exceptions
2 · each with an owner and an expiry
Export
sealed · sha256:4f88...b1c7

Where teams usually start

With a demo walked through by TruSecure — your Implementation Group scoped against controls you already operate, a single safeguard opened to its evidence, the same evidence answering ISO 27001 and CSF without being collected twice. Onboarding then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.

Compliance roadmap

Typical timeline: 3–6 months to full compliance readiness

  1. 1Weeks 1–4

    Assessment

    Gap analysis against CIS Controls v8, risk review, remediation plan.

  2. 2Weeks 5–12

    Implementation

    Controls deployed, policies written, evidence flowing.

  3. 3Weeks 13–16

    Audit prep

    Gaps closed, evidence package assembled for the authority.

  4. 4Weeks 17–24

    Steady state

    Continuous evidence, reports on demand, drift alerts.

With TruSecure: 3× faster to audit-ready. AI does the evidence work; your team keeps the decisions.

Map once, comply everywhere

unified commitments

One control model

Each control exists exactly once. Every obligation cites it — a gap shows up once, as one remediation item, not six findings in six programs.

  1. Regulations

    NIS2 · DORA · GDPR · EU AI Act

  2. Frameworks

    ISO 27001 · SOC 2 · NIST · CMMC · CIS

  3. Contracts

    Customer security requirements

  4. Internal policy

    Your own security standards

When the law moves, the model moves. A new transposition or a revised annex lands as a reviewable proposal against the controls it cites — not as a gap-analysis project you commission separately.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.

The short answer

CIS Controls v8 is a set of 18 prioritized cybersecurity safeguards organized into three Implementation Groups scaled by organizational size and risk. TruSecure maps CIS safeguards into the same control library used across every other framework it supports.