CIS Controls v8.1 assessments for consultants

Updated

A CIS Controls assessment measures a client against the CIS Critical Security Controls, a prioritized set of 18 Controls broken into 153 Safeguards in version 8.1. Because the Safeguards are concrete, such as maintaining an asset inventory or requiring MFA for remote access, they make a practical baseline for small and mid-sized clients. The first decision is the Implementation Group, which sets how many Safeguards are in scope.

Choosing the Implementation Group

Group Who it fits Scope
IG1 Small organizations with limited IT staff and mostly commodity threats Essential cyber hygiene; the minimum for every organization
IG2 Organizations with several departments, regulated or sensitive data, or a dedicated IT team IG1 plus Safeguards for more complex environments
IG3 Organizations handling highly sensitive data or facing targeted attacks All 153 Safeguards

Pick the group before collecting evidence. It decides what you request, and it keeps the client from being scored on Safeguards that were never meant for them.

What to request

CIS Safeguards reward system evidence over documents. Asset and software inventories, identity provider exports, vulnerability scan results, backup logs and endpoint coverage reports cover a large share of IG1. Policies still matter for Control 14 (security awareness training) and Control 17 (incident response management), but most Safeguards expect to see the practice operating.

From Safeguard results to a roadmap

Clients rarely fix everything at once. Group the gaps by Control, then order them by the Implementation Group they belong to: close IG1 gaps before starting IG2 work. That keeps the roadmap aligned with how CIS prioritizes the Safeguards and gives the client a sequence they can budget for.

How Control+s supports CIS assessments

  • Scope by Implementation Group, then by the enterprise assets, software, identities, data stores and service providers in the assessed environment.
  • Score each Safeguard from 0 to 5 with a rationale citing the evidence and the gaps that remain, with results rolled up by Control.
  • Share a CIS 18 Safeguard snapshot with the client through a password-protected, expiring link.
  • Reuse the evidence if the client later needs NIST CSF 2.0, ISO 27001 or SOC 2.
  • Reassess each cycle and show which Safeguards improved.

Frequently asked questions

How many Safeguards are in CIS Controls v8.1?

CIS Controls v8.1 has 18 Controls and 153 Safeguards. Minor updates v8.1.1 and v8.1.2 followed in August 2024 and March 2025. No version 9 has been released as of September 2026.

Which Implementation Group should a small client start with?

Most small and mid-sized organizations start with Implementation Group 1, which CIS describes as essential cyber hygiene. IG2 includes IG1 and adds Safeguards for organizations with more complex environments or sensitive data. IG3 includes both and targets organizations facing sophisticated attacks.

What changed in CIS Controls v8.1?

Version 8.1 aligned the Controls with NIST CSF 2.0, including a new Governance security function, and revised Safeguard descriptions, asset classes and the glossary. The 18 Controls kept the same overall structure.

How is Control+s different from CIS CSAT?

CIS CSAT is a free CIS tool for tracking CIS Controls implementation. Control+s is built for consultants assessing clients from evidence. Each Safeguard gets a score with a rationale citing the client's files, the same evidence can support other frameworks, and the result becomes a shareable view or a client report.

Sources

  1. CIS: CIS Critical Security Controls v8.1
  2. CIS: Implementation Groups
  3. CIS: CSAT, the CIS Controls Self Assessment Tool
  4. CIS: Mapping and compliance with the CIS Controls

Bring your next assessment to Control+s.

Start free with two frameworks and five evidence files. Use your own material to inspect the mapping, reasoning, and results, and see how Control+s fits your engagements.

Help shape the product around real consulting work. We welcome teams who want to build their assessment workflow with us.

Running a larger program? .