CIS 18 · Version 8.1

A CIS 18 assessment scored safeguard by safeguard

We measure your environment against all 18 CIS Controls in v8.1, set the Implementation Group you should be working to, and show exactly which safeguards stand between you and it.

Book a CIS 18 assessmentSee a sample report
VersionCIS Controls v8.1
Maintained byCenter for Internet Security
Structure18 controls · 153 safeguards
Suited toAny organisation wanting a prioritised technical baseline
01 · The framework

The 18 controls

CIS 18 is a prioritised set of technical and operational safeguards. Version 8.1 adds a Govern security function and aligns the controls with NIST CSF 2.0.

01Inventory and control of enterprise assets
02Inventory and control of software assets
03Data protection
04Secure configuration of enterprise assets and software
05Account management
06Access control management
07Continuous vulnerability management
08Audit log management
09Email and web browser protections
10Malware defences
11Data recovery
12Network infrastructure management
13Network monitoring and defence
14Security awareness and skills training
15Service provider management
16Application software security
17Incident response management
18Penetration testing
02 · Implementation Groups

Implementation Groups

Safeguards are grouped into three cumulative Implementation Groups. We agree the right target with you before scoring.

IG156 safeguardsEssential cyber hygiene. The minimum every organisation should have in place.
IG2130 safeguardsIG1 plus safeguards for organisations with dedicated IT staff and sensitive data.
IG3153 safeguardsEvery safeguard, for organisations facing skilled, targeted attackers.
03 · How we assess

Evidence first, interviews second

Every rating is backed by evidence from your environment, so the result reflects what is running, not what the policy says. A baseline typically takes two weeks.

  1. 01ScopeAgree the target, the systems in scope and who we need to speak to.
  2. 02CollectInterviews, document review and live data from Pulse and Trace.
  3. 03ScoreRate every requirement against your target, with evidence for each rating.
  4. 04ReportA prioritised roadmap and a short board briefing.
04 · What you receive

A result you can act on

Findings map across frameworks, so work done for CIS 18 counts towards the others you hold.

✓Scored gap analysisStatus for every requirement against your target, backed by evidence.
✓Prioritised roadmapP1 to P3 work packages with owners, dates and exit criteria.
✓Board briefingA short summary of where you stand and the decisions needed.
✓Evidence kept currentResults live in Attest and update as your environment changes.
Often assessed together
NIST Cybersecurity Framework 2.0 ISO/IEC 27001:2022 SOC 2

Know where you stand against CIS 18 in two weeks

A baseline assessment with a prioritised roadmap and a board-ready summary.

Book a CIS 18 assessment