CIS Controls Implementation: All 18 Controls v8
The 18 CIS Critical Security Controls v8 address over 90% of the most common attack vectors. We guide you through the complete implementation — from gap analysis and Implementation Group prioritization to technical integration into your existing security architecture.
- ✓Implementation of all 18 CIS Controls v8 with 153 safeguards
- ✓Prioritization by Implementation Groups (IG1, IG2, IG3)
- ✓Measurable risk reduction through structured deployment
- ✓Mapping to ISO 27001, NIS2, and DORA requirements
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
- Your strategic goals and objectives
- Desired business outcomes and ROI
- Steps already taken
Or contact us directly:
Certifications, Partners and more...










What are CIS Controls v8 and why do they matter?
Why ADVISORI for CIS Controls?
- ISO 27001-certified consultants with CIS implementation experience
- Proven methodology for all three Implementation Groups
- Industry-specific adaptation (financial services, insurance, manufacturing)
- Seamless mapping to regulatory requirements (NIS2, DORA, BAIT)
Important: CIS Controls v8 has 18 controls (not 20)
Since version 8, the CIS framework includes 18 controls instead of the previous 20. Controls were consolidated and new topics like Data Protection and Service Provider Management were added. Start with Implementation Group 1 (56 safeguards) for the greatest security gain.
ADVISORI in Numbers
11+
Years of Experience
120+
Employees
520+
Projects
Our structured approach follows the three Implementation Groups and ensures each phase delivers measurable security improvements.
Our Approach:
Assessment: Gap analysis of all 18 controls against your current state
Prioritization: Classification by Implementation Group and business risk
Implementation: Technical deployment with per-control validation
Integration: Connection to existing SIEM, IAM, and ITSM systems
Monitoring: KPI-based effectiveness measurement and maturity tracking

Sarah Richter
Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
Our Services
We offer you tailored solutions for your digital transformation
Top 20 CIS Controls Assessment
Comprehensive evaluation of your current security posture against the Top 20 CIS Critical Security Controls.
- Detailed gap analysis of all Top 20 CIS Controls
- Assessment according to Implementation Groups (IG1, IG2, IG3)
- Risk priority matrix and business impact assessment
- Tailored implementation roadmap
Strategic Implementation Planning
Development of a strategic roadmap for the phased implementation of the Top 20 Controls.
- Prioritization according to Implementation Groups and business criticality
- Resource planning and budget optimization
- Change management and stakeholder alignment
- Timeline development with milestone definition
Technical Implementation
Hands-on technical implementation of prioritized CIS Controls in your IT environment.
- Technical implementation according to best practices
- Integration with existing security tools and systems
- Automation and orchestration of controls
- Testing and validation of implemented measures
Monitoring & Continuous Improvement
Establishment of a sustainable monitoring and improvement system for the Top 20 Controls.
- Development of KPIs and measurement criteria for each control
- Automated monitoring and alerting systems
- Regular effectiveness analyses and optimization
- Compliance reporting and audit documentation
Looking for a complete overview of all our services?
View Complete Service OverviewOur Areas of Expertise
Our expertise in managing regulatory compliance and transformation, including DORA.
Wir steuern Ihre regulatorischen Transformationsprojekte erfolgreich – von der Konzeption bis zur nachhaltigen Implementierung.
Frequently Asked Questions about CIS Controls Implementation: All 18 Controls v8
What are the CIS Controls v8 and how many controls are there?
CIS Controls v8 (currently v8.1, released June 2024) comprises 18 prioritized security measures with 153 safeguards in total. They were developed by the Center for Internet Security based on real-world attack data. The 18 controls replace the former 20 controls from version 7 — through consolidation and addition of new areas like Data Protection (Control 3) and Service Provider Management (Control 15). The controls are organized into three Implementation Groups (IG1, IG2, IG3) that enable phased implementation based on organization size and risk profile.
What changed between CIS Controls v7 (20 controls) and v8 (18 controls)?
In version 8, the framework was consolidated from 20 to 18 controls. The former controls for email and browser protection were integrated into other controls, and new topics were added: Data Protection (Control 3), Service Provider Management (Control 15), and Application Software Security (Control 16). Additionally, v8 introduced the concept of safeguards — 153 specific individual measures replacing the former sub-controls. The Implementation Groups (IG1 with 56, IG2 with 74, IG3 with 23 safeguards) replace the old Basic/Foundational/Organizational categorization.
What are the three Implementation Groups and which one fits our organization?
Implementation Group 1 (IG1) comprises 56 safeguards and suits organizations without a dedicated security team. According to CIS, it addresses over 90% of the most common attacks and can be implemented in three to six months. Implementation Group 2 (IG2) adds 74 additional safeguards for organizations with their own IT security team and more complex infrastructure. Implementation Group 3 (IG3) adds the remaining 23 safeguards and targets organizations with a SOC team and high maturity level. ADVISORI recommends always starting with IG1 and increasing maturity step by step.
How long does CIS Controls v8 implementation take?
Duration depends on the chosen Implementation Group and your current maturity level. IG1 (56 safeguards) can be implemented in three to six months for most organizations. For IG2, plan an additional six to twelve months; for IG3, another six months. ADVISORI begins with a gap analysis that maps your current state against all 18 controls within two to three weeks. This produces a prioritized roadmap that addresses quick wins first, delivering the greatest security improvement with the least effort.
How do CIS Controls map to ISO 27001, NIS2, and DORA?
CIS Controls v8 can be mapped directly to other frameworks. Approximately 80% of ISO 27001 Annex A measures are covered by the CIS Controls. For NIS2, the controls provide a practical implementation guide for the required risk management measures. In the context of DORA, they particularly support ICT risk management and incident response requirements. ADVISORI creates a compliance mapping with every implementation showing which regulatory requirements are covered by which CIS safeguards.
What does CIS Controls implementation cost?
Costs vary by scope, organization size, and target Implementation Group. An initial gap analysis for all 18 controls typically starts in the low five-figure range. Full IG1 implementation for a mid-sized company generally falls between EUR 50,000 and 150,000 — including consulting, tool integration, and training. Return on investment materializes through reduced cyber insurance premiums (15§30% reduction), shorter audit cycles, and avoided incident costs.
What tools and technologies are needed for CIS Controls implementation?
Technical requirements depend on the Implementation Group. For IG1, existing tools often suffice: Active Directory for access management, group policies for configuration hardening, and existing monitoring tools. From IG2 onward, specialized solutions are recommended such as SIEM systems (e.g., Microsoft Sentinel, Splunk), vulnerability scanners (Tenable, Qualys), and PAM solutions (BeyondTrust, CyberArk). ADVISORI integrates the controls into your existing tool landscape and avoids unnecessary new acquisitions.
Let's
Work Together!
Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Your strategic success starts here
Our clients trust our expertise in digital transformation, compliance, and risk management
Ready for the next step?
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
For optimal preparation of your strategy session:
Prefer direct contact?
Direct hotline for decision-makers
Strategic inquiries via email
Detailed Project Inquiry
For complex inquiries or if you want to provide specific information in advance