Skip to content
Resources

CIS Controls v8 to Cyber Essentials: the mapping.

How the CIS Controls v8 Implementation Group 1 safeguards map to the five Cyber Essentials technical control areas. For organisations working across both frameworks.

Overview

Two frameworks. Significant overlap.

Cyber Essentials defines five technical control areas that organisations must address to achieve certification. CIS Controls v8 defines 18 control groups with 56 safeguards in Implementation Group 1 alone. Despite the difference in scope and detail, there is substantial alignment between the two frameworks at the practical implementation level.

Organisations that have addressed Cyber Essentials will have partially addressed a number of CIS Controls IG1 safeguards. Organisations that have completed a CIS M365 Benchmark assessment will typically find that Cyber Essentials certification is achievable with limited additional effort.

The five control areas

Cyber Essentials mapped to CIS Controls.

Firewalls

Boundary firewalls and internet gateways. Maps primarily to CIS Control 12 (Network Infrastructure Management) and CIS Control 13 (Network Monitoring and Defence).

Secure configuration

Computers and network devices configured securely. Maps to CIS Control 4 (Secure Configuration of Enterprise Assets) and CIS Control 2 (Inventory and Control of Software Assets).

User access control

Access to systems limited to authorised users. Maps to CIS Control 5 (Account Management) and CIS Control 6 (Access Control Management).

Malware protection

Protection against malware. Maps to CIS Control 10 (Malware Defences) and CIS Control 9 (Email and Web Browser Protections).

Patch management

Software kept up to date. Maps to CIS Control 7 (Continuous Vulnerability Management) and CIS Control 2 (Inventory and Control of Software Assets).

How a CIS M365 assessment supports Cyber Essentials

A CIS Microsoft 365 Benchmark assessment directly addresses the Cyber Essentials control areas of secure configuration, user access control, and malware protection within the M365 platform. Organisations that address the CIS M365 recommendations will find the Cyber Essentials questionnaire significantly easier to complete for cloud-hosted workloads.

Interested in a Cyber Essentials readiness assessment?

The Datatechs Cyber Essentials assessment covers all five technical control areas with specific guidance for Microsoft 365 environments.