Skip to content
Framework · Center for Internet Security v8.1

CIS Controls

The pragmatic, prioritized cybersecurity controls developed by a global community of practitioners. Implementation Group tiers (IG1, IG2, IG3) let smaller organizations start where they are.

153 Talarity controls mapped
Who it's for: Any organization wanting a defensible technical baseline. Often used alongside NIST CSF for tactical depth.
Talarity coverage

Mapped, monitored, and audit-ready.

Every CIS Controls control has a place in Talarity — with cross-mapping, automated evidence, and continuous validation.

153
Talarity controls mapped

Talarity's pre-built control library covering CIS Controls, with linked evidence, owners, and testing schedules.

Cross-maps to
NIST CSFISO 27001PCI DSSHIPAA

Answer once, prove everywhere. Talarity's mapping engine reuses your evidence across every framework you run.

Automated evidence
  • Asset inventory (hardware and software)
  • Vulnerability scan and patching cadence
  • Account and access management logs
  • Audit log review records
  • Penetration test reports and remediation

Your CIS Controls dashboard

Every completed CIS Controls assessment updates this automatically — where you stand now, how that has changed, and which areas need work.

Click to enlarge
The Talarity dashboard for a completed CIS Controls v8.1 assessment: the latest score, the trend across previous assessments, and a breakdown by control area
Common pain points

What gets easier with Talarity.

Pain

CIS Implementation Groups (IG1, IG2, IG3) are a great organizing principle — but mapping your current state against them by hand is a multi-day exercise.

Talarity

Talarity ships CIS v8.1 with pre-tagged IG levels. Filter to IG1 if you're starting; layer IG2 and IG3 as you mature.

Pain

Safeguard-level scoring requires evidence that's contextualized to your environment.

Talarity

Each safeguard has a structured evidence prompt — what to upload, what to attest to, what to link from automated systems. No guessing.

Pain

CIS RAM (Risk Assessment Method) is a separate workflow you'd otherwise spreadsheet.

Talarity

CIS RAM is built in as an asset-valuation risk model. Run it alongside your CIS Controls assessment; both share the same data.

Pain

Cross-mapping CIS to your other frameworks (NIST CSF, ISO 27001) is painful when done manually.

Talarity

Built-in mappings to NIST CSF, ISO 27001, PCI DSS, and HIPAA. Implement a CIS safeguard once; satisfy the related requirements in every framework.

CIS Controls — common questions

What are CIS Implementation Groups?
Implementation Groups prioritise the Safeguards by organisational profile. IG1 defines essential cyber hygiene — the baseline every organisation should meet. IG2 adds Safeguards for organisations managing more sensitive data and greater operational complexity. IG3 covers organisations facing targeted attacks and holding data whose loss carries severe consequences. Each group is cumulative, so IG2 includes all of IG1.
How do the CIS Controls relate to NIST CSF and ISO 27001?
The CIS Controls are a prioritised set of defensive actions, whereas NIST CSF is an outcome-based framework and ISO 27001 certifies a management system. They are complements rather than alternatives: teams frequently use CIS to decide what to implement first and CSF or ISO to structure governance and reporting. CIS publishes mappings to both, so one implemented Safeguard can be evidenced against several frameworks.
What changed in CIS Controls v8.1?
v8.1 was an update to v8 rather than a restructuring. It refined Safeguard descriptions and asset class definitions, added a governance security function to align more explicitly with the Govern function introduced in NIST CSF 2.0, and improved the supporting mappings. Organisations already implementing v8 do not need to rebuild their programme.
Is CIS a certification?
No. There is no CIS Controls certificate. It is a prioritised implementation guide, and its value is in sequencing — it answers what to do first when everything appears urgent. Evidence of implemented Safeguards is still what customers, insurers and auditors ask for, and that evidence maps onto the frameworks that do certify.

Working with CIS Controls

Step-by-step walkthroughs from the Talarity library.

Ready to ship CIS Controls?

Start a 7-day trial and run this framework end-to-end on your own evidence — then buy online in-app when you're ready.