Structured implementation of all 18 CIS Controls v8 with 153 safeguards for measurable cybersecurity

CIS Controls Implementation: All 18 Controls v8

The 18 CIS Critical Security Controls v8 address over 90% of the most common attack vectors. We guide you through the complete implementation — from gap analysis and Implementation Group prioritization to technical integration into your existing security architecture.

  • Implementation of all 18 CIS Controls v8 with 153 safeguards
  • Prioritization by Implementation Groups (IG1, IG2, IG3)
  • Measurable risk reduction through structured deployment
  • Mapping to ISO 27001, NIS2, and DORA requirements

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

  • Your strategic goals and objectives
  • Desired business outcomes and ROI
  • Steps already taken

Or contact us directly:

Certifications, Partners and more...

ISO 9001 CertifiedISO 27001 CertifiedISO 14001 CertifiedBeyondTrust PartnerBVMW Bundesverband MitgliedMitigant PartnerGoogle PartnerTop 100 InnovatorMicrosoft AzureAmazon Web Services

What are CIS Controls v8 and why do they matter?

Why ADVISORI for CIS Controls?

  • ISO 27001-certified consultants with CIS implementation experience
  • Proven methodology for all three Implementation Groups
  • Industry-specific adaptation (financial services, insurance, manufacturing)
  • Seamless mapping to regulatory requirements (NIS2, DORA, BAIT)

Important: CIS Controls v8 has 18 controls (not 20)

Since version 8, the CIS framework includes 18 controls instead of the previous 20. Controls were consolidated and new topics like Data Protection and Service Provider Management were added. Start with Implementation Group 1 (56 safeguards) for the greatest security gain.

ADVISORI in Numbers

11+

Years of Experience

120+

Employees

520+

Projects

Our structured approach follows the three Implementation Groups and ensures each phase delivers measurable security improvements.

Our Approach:

Assessment: Gap analysis of all 18 controls against your current state

Prioritization: Classification by Implementation Group and business risk

Implementation: Technical deployment with per-control validation

Integration: Connection to existing SIEM, IAM, and ITSM systems

Monitoring: KPI-based effectiveness measurement and maturity tracking

Sarah Richter

Sarah Richter

Head of Information Security, Cyber Security

Expertise & Experience:

10+ years of experience, CISA, CISM, Lead Auditor, DORA, NIS2, BCM, Cyber and Information Security

Our Services

We offer you tailored solutions for your digital transformation

Top 20 CIS Controls Assessment

Comprehensive evaluation of your current security posture against the Top 20 CIS Critical Security Controls.

  • Detailed gap analysis of all Top 20 CIS Controls
  • Assessment according to Implementation Groups (IG1, IG2, IG3)
  • Risk priority matrix and business impact assessment
  • Tailored implementation roadmap

Strategic Implementation Planning

Development of a strategic roadmap for the phased implementation of the Top 20 Controls.

  • Prioritization according to Implementation Groups and business criticality
  • Resource planning and budget optimization
  • Change management and stakeholder alignment
  • Timeline development with milestone definition

Technical Implementation

Hands-on technical implementation of prioritized CIS Controls in your IT environment.

  • Technical implementation according to best practices
  • Integration with existing security tools and systems
  • Automation and orchestration of controls
  • Testing and validation of implemented measures

Monitoring & Continuous Improvement

Establishment of a sustainable monitoring and improvement system for the Top 20 Controls.

  • Development of KPIs and measurement criteria for each control
  • Automated monitoring and alerting systems
  • Regular effectiveness analyses and optimization
  • Compliance reporting and audit documentation

Looking for a complete overview of all our services?

View Complete Service Overview

Our Areas of Expertise

Our expertise in managing regulatory compliance and transformation, including DORA.

Frequently Asked Questions about CIS Controls Implementation: All 18 Controls v8

What are the CIS Controls v8 and how many controls are there?

CIS Controls v8 (currently v8.1, released June 2024) comprises 18 prioritized security measures with 153 safeguards in total. They were developed by the Center for Internet Security based on real-world attack data. The 18 controls replace the former 20 controls from version 7 — through consolidation and addition of new areas like Data Protection (Control 3) and Service Provider Management (Control 15). The controls are organized into three Implementation Groups (IG1, IG2, IG3) that enable phased implementation based on organization size and risk profile.

What changed between CIS Controls v7 (20 controls) and v8 (18 controls)?

In version 8, the framework was consolidated from 20 to 18 controls. The former controls for email and browser protection were integrated into other controls, and new topics were added: Data Protection (Control 3), Service Provider Management (Control 15), and Application Software Security (Control 16). Additionally, v8 introduced the concept of safeguards — 153 specific individual measures replacing the former sub-controls. The Implementation Groups (IG1 with 56, IG2 with 74, IG3 with 23 safeguards) replace the old Basic/Foundational/Organizational categorization.

What are the three Implementation Groups and which one fits our organization?

Implementation Group 1 (IG1) comprises 56 safeguards and suits organizations without a dedicated security team. According to CIS, it addresses over 90% of the most common attacks and can be implemented in three to six months. Implementation Group 2 (IG2) adds 74 additional safeguards for organizations with their own IT security team and more complex infrastructure. Implementation Group 3 (IG3) adds the remaining 23 safeguards and targets organizations with a SOC team and high maturity level. ADVISORI recommends always starting with IG1 and increasing maturity step by step.

How long does CIS Controls v8 implementation take?

Duration depends on the chosen Implementation Group and your current maturity level. IG1 (56 safeguards) can be implemented in three to six months for most organizations. For IG2, plan an additional six to twelve months; for IG3, another six months. ADVISORI begins with a gap analysis that maps your current state against all 18 controls within two to three weeks. This produces a prioritized roadmap that addresses quick wins first, delivering the greatest security improvement with the least effort.

How do CIS Controls map to ISO 27001, NIS2, and DORA?

CIS Controls v8 can be mapped directly to other frameworks. Approximately 80% of ISO 27001 Annex A measures are covered by the CIS Controls. For NIS2, the controls provide a practical implementation guide for the required risk management measures. In the context of DORA, they particularly support ICT risk management and incident response requirements. ADVISORI creates a compliance mapping with every implementation showing which regulatory requirements are covered by which CIS safeguards.

What does CIS Controls implementation cost?

Costs vary by scope, organization size, and target Implementation Group. An initial gap analysis for all 18 controls typically starts in the low five-figure range. Full IG1 implementation for a mid-sized company generally falls between EUR 50,000 and 150,000 — including consulting, tool integration, and training. Return on investment materializes through reduced cyber insurance premiums (15§30% reduction), shorter audit cycles, and avoided incident costs.

What tools and technologies are needed for CIS Controls implementation?

Technical requirements depend on the Implementation Group. For IG1, existing tools often suffice: Active Directory for access management, group policies for configuration hardening, and existing monitoring tools. From IG2 onward, specialized solutions are recommended such as SIEM systems (e.g., Microsoft Sentinel, Splunk), vulnerability scanners (Tenable, Qualys), and PAM solutions (BeyondTrust, CyberArk). ADVISORI integrates the controls into your existing tool landscape and avoids unnecessary new acquisitions.

Let's

Work Together!

Is your organization ready for the next step into the digital future? Contact us for a personal consultation.

Your strategic success starts here

Our clients trust our expertise in digital transformation, compliance, and risk management

Ready for the next step?

Schedule a strategic consultation with our experts now

30 Minutes • Non-binding • Immediately available

For optimal preparation of your strategy session:

Your strategic goals and challenges
Desired business outcomes and ROI expectations
Current compliance and risk situation
Stakeholders and decision-makers in the project

Prefer direct contact?

Direct hotline for decision-makers

Strategic inquiries via email

Detailed Project Inquiry

For complex inquiries or if you want to provide specific information in advance