Information Security & Cybersecurity

Automate CIS v8 self-assessment

CIS Controls v8 · Critical Security Controls

Prioritized set of actions to protect organizations and data from known cyber attack vectors, organized into 18 control groups with implementation groups for progressive adoption.

153 controls24/7 continuous monitoring
CIS v8 badgeCIS v8

What is CIS v8?

Prioritized set of actions to protect organizations and data from known cyber attack vectors, organized into 18 control groups with implementation groups for progressive adoption.

Who it applies to

Organisations that want a prioritised place to start rather than a comprehensive one. Unusually among these frameworks it is ordered by what to do first, which makes it a practical fit for small teams.

How the standard is organised

Controls broken into safeguards and grouped into implementation groups, so a smaller organisation can adopt the first tier without committing to the whole set.

Framework names, marks and abbreviations (ISO, SOC 2, PCI DSS, TISAX, HIPAA, GDPR and others) are trademarks of their respective standards bodies and are used here only to describe what the Bitkosh Compliance Management Platform helps you track and prepare for. The badges shown are original Bitkosh artwork, not the official marks. Bitkosh Technologies is not affiliated with, sponsored by, or endorsed by ISO, AICPA, the PCI Security Standards Council, ENX/VDA, or any other framework owner, and using this platform does not by itself confer or guarantee certification — certification/attestation is granted only by the relevant accredited third-party body.

CIS v8 on the Bitkosh platform

The 153 CIS v8 controls sit in one workspace, evidence is collected from the systems you already run, and shared controls satisfy the equivalent requirement in the other 34 frameworks at the same time — so a second framework costs a fraction of the first.

How the platform works

Frequently Asked Questions

Who publishes CIS v8, and who does it apply to?
CIS v8 is published by The Center for Internet Security. Organisations that want a prioritised place to start rather than a comprehensive one. Unusually among these frameworks it is ordered by what to do first, which makes it a practical fit for small teams.
How is CIS v8 conformance demonstrated?
Self-assessed against the published criteria. There is no certificate to obtain. Conformance is shown through mapped controls and retained evidence, and tested by a regulator or a counterparty rather than an auditor you appoint.
How is CIS v8 structured?
Controls broken into safeguards and grouped into implementation groups, so a smaller organisation can adopt the first tier without committing to the whole set. Bitkosh tracks 153 CIS v8 controls against it, each with its own evidence requirements, owner and review cadence.
Let's build together

Ready to automate CIS v8?

See how the Bitkosh Compliance Management Platform gets you audit-ready for CIS v8 and 34 other frameworks from a single control library.