Information Security
Available nowCIS Critical Security Controls · v8.1
The CIS Critical Security Controls v8.1 are a prioritized set of 18 Controls and 153 Safeguards: the defenses that stop the attacks organizations actually face, ordered so you can start with the essentials.
153
requirements tracked
Core plans
Access
Add-on from $29/mo
Scope
How much of the standard Keel models
Keel authors every leaf requirement in the scope declared below — all 153 of them, with nothing inside that scope left out. A test fails the build if the authored count and the declared count ever diverge, so this framework cannot quietly lose requirements after the fact.
- Authored in Keel
- 153 requirements
- In Keel’s scored scope
- 153 leaf requirements
Keel publishes this for every framework it ships, complete or not, so a readiness percentage can be read against a denominator you can see. Compare every framework
Who it is for
Who needs CIS Critical Security Controls?
- Teams that want concrete actions, not just outcomes to interpret
- Organizations targeting Implementation Group 1 (IG1) essential cyber hygiene
- Anyone who wants their security work to also count toward SOC 2 and ISO 27001
What Keel does
How Keel helps with CIS Critical Security Controls
- All 18 Controls and 153 Safeguards as a crosswalked framework
- Coverage that counts toward SOC 2, ISO 27001, PCI, and HIPAA simultaneously
- Readiness scoring so you can drive IG1 to done
Collect once, comply everywhere
CIS Critical Security Controls shares canonical controls with ISO/IEC 27001, NIST SP 800-53 and PCI DSS and others in the catalog. Implement one of those controls and it counts toward every framework it satisfies, so adding CIS Critical Security Controls rarely means starting from scratch.
Shares canonical controls with
- ISO/IEC 27001
- PCI DSS
- SOC 2
- SOX (Sarbanes-Oxley) Section 404
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST SP 800-171
- HIPAA
- GDPR
- COPPA
- Google Play Families
- Amazon Appstore Child-Directed Apps
- Apple App Store Kids Category
- ISO 9001
- AI Governance Essentials
- ISO/IEC 42001
- NIST AI Risk Management Framework
- EU AI Act
- ESG Essentials
- US Employment Law - Federal Baseline
Other frameworks: ISO/IEC 27001 · PCI DSS · SOC 2 · SOX (Sarbanes-Oxley) Section 404 · NIST Cybersecurity Framework · NIST SP 800-53 · All frameworks