The 18 CIS Critical Security Controls v8 address over 90% of the most common attack vectors. We guide you through the complete implementation — from gap analysis and Implementation Group prioritization to technical integration into your existing security architecture.
Our clients trust our expertise in digital transformation, compliance, and risk management
30 Minutes • Non-binding • Immediately available
Or contact us directly:










Since version 8, the CIS framework includes 18 controls instead of the previous 20. Controls were consolidated and new topics like Data Protection and Service Provider Management were added. Start with Implementation Group 1 (56 safeguards) for the greatest security gain.
Years of Experience
Employees
Projects
Our structured approach follows the three Implementation Groups and ensures each phase delivers measurable security improvements.
Assessment: Gap analysis of all 18 controls against your current state
Prioritization: Classification by Implementation Group and business risk
Implementation: Technical deployment with per-control validation
Integration: Connection to existing SIEM, IAM, and ITSM systems
Monitoring: KPI-based effectiveness measurement and maturity tracking
"The professional implementation of the Top 20 CIS Controls by ADVISORI has fundamentally strengthened our cybersecurity posture. The structured approach and practical implementation have achieved measurable improvements across all critical security areas."

Head of Information Security, Cyber Security
Expertise & Experience:
10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security
We offer you tailored solutions for your digital transformation
Comprehensive evaluation of your current security posture against the Top 20 CIS Critical Security Controls.
Development of a strategic roadmap for the phased implementation of the Top 20 Controls.
Hands-on technical implementation of prioritized CIS Controls in your IT environment.
Establishment of a sustainable monitoring and improvement system for the Top 20 Controls.
Choose the area that fits your requirements
Which of the 18 CIS Controls matter most to your organization? We analyze your specific threat landscape and prioritize security measures based on business criticality. The result: maximum protection with optimal resource allocation — from IG1 essential cyber hygiene to full IG3 coverage.
How mature is your CIS Controls implementation? Our structured assessment evaluates all 18 controls across Implementation Groups IG1 through IG3, identifies gaps, and delivers a prioritized roadmap so you can measurably reduce cyber risk.
CIS Controls v
8 (currently v8.1, released June 2024) comprises
18 prioritized security measures with
153 safeguards in total. They were developed by the Center for Internet Security based on real-world attack data. The
18 controls replace the former
20 controls from version
7 — through consolidation and addition of new areas like Data Protection (Control 3) and Service Provider Management (Control 15). The controls are organized into three Implementation Groups (IG1, IG2, IG3) that enable phased implementation based on organization size and risk profile.
In version 8, the framework was consolidated from
20 to
18 controls. The former controls for email and browser protection were integrated into other controls, and new topics were added: Data Protection (Control 3), Service Provider Management (Control 15), and Application Software Security (Control 16). Additionally, v
8 introduced the concept of safeguards —
153 specific individual measures replacing the former sub-controls. The Implementation Groups (IG 1 with 56, IG 2 with 74, IG 3 with
23 safeguards) replace the old Basic/Foundational/Organizational categorization.
Implementation Group
1 (IG1) comprises
56 safeguards and suits organizations without a dedicated security team. According to CIS, it addresses over 90% of the most common attacks and can be implemented in three to six months. Implementation Group
2 (IG2) adds
74 additional safeguards for organizations with their own IT security team and more complex infrastructure. Implementation Group
3 (IG3) adds the remaining
23 safeguards and targets organizations with a SOC team and high maturity level. ADVISORI recommends always starting with IG 1 and increasing maturity step by step.
Duration depends on the chosen Implementation Group and your current maturity level. IG 1 (
56 safeguards) can be implemented in three to six months for most organizations. For IG2, plan an additional six to twelve months; for IG3, another six months. ADVISORI begins with a gap analysis that maps your current state against all
18 controls within two to three weeks. This produces a prioritized roadmap that addresses quick wins first, delivering the greatest security improvement with the least effort.
CIS Controls v
8 can be mapped directly to other frameworks. Approximately 80% of ISO 27001 Annex A measures are covered by the CIS Controls. For NIS2, the controls provide a practical implementation guide for the required risk management measures. In the context of DORA, they particularly support ICT risk management and incident response requirements. ADVISORI creates a compliance mapping with every implementation showing which regulatory requirements are covered by which CIS safeguards.
Costs vary by scope, organization size, and target Implementation Group. An initial gap analysis for all
18 controls typically starts in the low five-figure range. Full IG 1 implementation for a mid-sized company generally falls between EUR 50,
000 and 150,
000 — including consulting, tool integration, and training. Return on investment materializes through reduced cyber insurance premiums (15§30% reduction), shorter audit cycles, and avoided incident costs.
Technical requirements depend on the Implementation Group. For IG1, existing tools often suffice: Active Directory for access management, group policies for configuration hardening, and existing monitoring tools. From IG 2 onward, specialized solutions are recommended such as SIEM systems (e.g., Microsoft Sentinel, Splunk), vulnerability scanners (Tenable, Qualys), and PAM solutions (BeyondTrust, CyberArk). ADVISORI integrates the controls into your existing tool landscape and avoids unnecessary new acquisitions.
Discover how we support companies in their digital transformation
Klöckner & Co
Digital Transformation in Steel Trading

Siemens
Smart Manufacturing Solutions for Maximum Value Creation

Festo
Intelligent Networking for Future-Proof Production Systems

Bosch
AI Process Optimization for Improved Production Efficiency

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.
Our clients trust our expertise in digital transformation, compliance, and risk management
Schedule a strategic consultation with our experts now
30 Minutes • Non-binding • Immediately available
Direct hotline for decision-makers
Strategic inquiries via email
For complex inquiries or if you want to provide specific information in advance