⚡ Every Mutex Systems product starts at £0 — create an account and go live today. See pricing →
grComply Compliance Frameworks Security Awareness Training TiLedger FlowChat Pricing Partners Resources About Reviews Contact Sign in to grComply Sign in to TiLedger Sign in to FlowChat
grComply framework · Cybersecurity baseline

CIS Controls v8, from IG1 to IG3.

CIS Controls v8 is the Center for Internet Security's prioritised set of 18 cybersecurity Safeguards, organised into three Implementation Groups — IG1 essential hygiene through IG3 advanced — that most organisations use as a practical technical baseline underneath a broader framework like ISO 27001 or SOC 2. grComply seeds the full 18-Control structure grouped by Implementation Group, with continuous vulnerability scanning feeding CIS-07 directly and the training module closing CIS-14 with a real completion record.

3 Implementation Groups · 18 Controls — CIS-07 vulnerability management runs on grComply's own scanning.
Back to all frameworks WhatsApp us
3Implementation Groups
18Controls
CIS-07Runs on live scanning
StructuralSeed depth

What is CIS Controls v8? CIS Controls v8 is a prioritised, practical set of 18 cybersecurity Safeguards published by the Center for Internet Security, organised into three Implementation Groups by organisational maturity — IG1 (essential hygiene), IG2 (intermediate), and IG3 (advanced). It's frequently used as the technical baseline underneath a governance framework like ISO 27001 rather than as a standalone compliance target.

Why it's different

How grComply benefits your CIS Controls v8 programme

Implementation Groups as your rollout plan

IG1 essential hygiene through IG3 advanced, tracked domain-by-domain so a maturity roadmap is visible, not just a flat 18-item checklist.

Continuous Vulnerability Management (CIS-07) is literally automated

grComply's own external and internal scanning IS the evidence source for CIS-07, CVE-enriched, not a manually uploaded quarterly scan.

Account & Access controls map straight to evidence

CIS-05/06 account-lifecycle controls attach to the same evidence types — procedure docs, IAM exports — grComply already models.

Security Awareness (CIS-14) closes with the training module

Course completion becomes the evidence CIS-14 needs automatically, with the same compliance-mapping gate every course carries.

One CIS Safeguard, many frameworks

CIS is frequently the technical baseline underneath ISO 27001 or SOC 2; cross-mapping credits both from one piece of evidence.

Penetration Testing (CIS-18) evidence stays with the audit trail

Findings and remediation sit in the same register auditors already review, not a separate pentest report nobody cross-references.

Structure

3 Implementation Groups, 18 Controls, real Safeguard structure

Seeded exactly as CIS publishes it — IG1 essential hygiene, IG2 intermediate, IG3 advanced — with Safeguards underneath each Control.

IG1 — Essential cyber hygiene

Controls 1–6: Inventory and Control of Enterprise Assets, Inventory and Control of Software Assets, Data Protection, Secure Configuration, Account Management, and Access Control Management — the baseline every organisation should have regardless of size.

IG2 — Intermediate

Controls 7–12: Continuous Vulnerability Management (CIS-07, fed by grComply's own scanning), Audit Log Management, Email and Web Browser Protections, Malware Defenses, Data Recovery, and Network Infrastructure Management.

IG3 — Advanced

Controls 13–18: Network Monitoring and Defense, Security Awareness and Skills Training (CIS-14, closed by the training module), Service Provider Management, Application Software Security, Incident Response Management, and Penetration Testing.

Evidence, mapped

Evidence grComply already models for CIS Controls v8

Real evidence-requirement examples from the seeded control library — the same evidence types every other framework in grComply uses, not a bespoke process for this one.

ControlEvidence typeExample
CIS-01 — Asset inventoryInventory documentAsset inventory export or CMDB screenshot
CIS-05 — Account managementProcedure documentAccount lifecycle / joiner-mover-leaver procedure
CIS-07 — Vulnerability managementVulnerability scan reportScan summary by severity, generated from grComply's own scanning pipeline
CIS-14 — Security awarenessTraining attestationSecurity awareness completion attestation from the training module
CIS-17 — Incident responseProcedure documentIncident response plan

Why this matters: CIS Controls v8 is usually adopted as the practical technical layer underneath a governance-heavy standard — grComply's cross-framework mapping means a CIS-07 vulnerability-management control can credit an ISO 27001 A.8.8 control simultaneously, so implementing CIS doesn't mean re-evidencing the ISMS on top.

Product screens

CIS Controls v8, in the live workspace

The same grComply workspace shown across the platform — control browser, mapping, evidence, and AI assist apply identically to CIS Controls v8.

FAQ

CIS Controls v8 in grComply

What is CIS Controls v8?

CIS Controls v8 is the Center for Internet Security's prioritised set of 18 cybersecurity Safeguards, organised into three Implementation Groups by organisational maturity — a practical technical baseline widely used underneath a broader governance framework.

Does grComply support all three Implementation Groups?

Yes — IG1 essential hygiene, IG2 intermediate, and IG3 advanced are seeded as the domain layer, with all 18 Controls underneath in their correct group.

How does CIS-07 vulnerability management work in grComply?

grComply's own external (agentless) and internal (agent-based) scanning generates CVE-enriched findings that serve as the evidence for CIS-07 directly — not a manually uploaded third-party scan report.

Can Security Awareness Training (CIS-14) evidence come from the training module?

Yes — the training module's compliance-mapped courses can map directly to CIS-14, producing a real completion attestation rather than a sign-in sheet.

Is CIS Controls v8 a certifiable standard like ISO 27001?

No — CIS Controls is a prioritised technical baseline, not a certification scheme. Most organisations use it internally or as evidence within a broader audit like SOC 2 or ISO 27001.

Can CIS-18 penetration testing evidence sit alongside a formal audit?

Yes — penetration test results and remediation status stay in the same findings register auditors already review for other frameworks, rather than living in a separate report.

Which Implementation Group should we target first?

Most organisations start with IG1 (essential hygiene) and expand to IG2/IG3 as maturity grows; grComply tracks completion per Implementation Group so the roadmap is visible, not just an 18-item flat list.

Does CIS Controls cross-map to ISO 27001 or NIST CSF?

Yes — cross-framework mapping lets a single implemented Safeguard credit an equivalent ISO 27001 Annex A control or NIST CSF Subcategory. See the full catalog on the Compliance Frameworks page.

See CIS Controls v8 mapped into your control library

Powered by Mutex Systems. Back to Compliance Frameworks → · grComply overview → · Security Awareness Training →

Get in touch

Talk to us about CIS Controls v8

Tell us where your CIS Controls v8 programme stands today, and we'll route it to the right product specialist.

  • A product specialist replies personally — not a bot
  • No obligation after the first conversation
  • WhatsApp support also available 24/7

By submitting, you agree to be contacted about your enquiry. We respect your privacy.

Prefer to talk it through?

Book a meeting directly

Pick a time that works for you — 30 minutes with a product specialist, no sales script.

Ready to bring CIS Controls v8 into one control library?

We respond within one working day — or reach us instantly on WhatsApp.

WhatsApp us