Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CIS Benchmarks compared with the CIS Controls

CIS Benchmarks vs CIS Controls: A Clear Guide for 2026

The CIS Benchmarks and the CIS Controls come from the same organization, are often named in the same sentence, and answer completely different questions. The Controls tell you what to do and in what order. The Benchmarks tell you how to configure a specific piece of technology once you have decided to do it.

Confusing them produces two recognizable failures: a security program that adopts a framework and never changes a single system setting, or a hardening project that locks down servers while the asset inventory nobody maintains hides half the estate. This guide sets out what each is, how they fit together, and which one to reach for.

CIS Benchmarks vs CIS Controls: scope, form and what each is used for
One is a prioritized program; the other is a configuration standard per technology.

CIS Benchmarks vs CIS Controls at a glance

  CIS Controls CIS Benchmarks
What it is A prioritized set of 18 controls containing 153 safeguards (v8.1) 100+ prescriptive configuration guides, one per technology
Scope The whole security program One product family at a time — Windows, Linux, AWS, Kubernetes, Cisco, iOS
Granularity “Securely configure enterprise assets and software” The specific setting, its recommended value, and the audit and remediation steps
Who uses it Security leadership planning what to fund next Engineers building and auditing a system image
Tailoring Implementation Groups 1 to 3 Profile levels — Level 1, Level 2, and a STIG profile

What the CIS Benchmarks are

Each benchmark is a consensus-developed configuration guide for one technology, covering more than 25 vendor product families across operating systems, cloud providers, server software, network devices, mobile platforms, desktop applications and DevSecOps tooling. Every recommendation states the setting, the rationale, how to audit it and how to remediate it — which is what makes a benchmark usable as an engineering document rather than a policy.

They are published free of charge in PDF form. Membership products layer tooling on top: automated assessment against a benchmark, tailored recommendation sets, and pre-hardened virtual machine images for cloud deployment.

The three profile levels

  • Level 1 — the base recommendation. Intended to lower the attack surface without an extensive performance impact and without hindering business functionality. If you are hardening a fleet for the first time, this is the profile.
  • Level 2 — defense in depth, for environments where security is paramount. These recommendations can have an adverse effect if applied without care, which is a polite way of saying they will break things you did not know depended on the default.
  • STIG profile — replaces the former Level 3. It contains the STIG-specific recommendations for organizations that must comply with the Defense Information Systems Agency’s Security Technical Implementation Guides, and includes the Level 1 and Level 2 recommendations as well.

Choose the profile per system class, not per organization. A domain controller and a developer laptop do not belong on the same profile, and pretending otherwise is how a hardening project stalls at the first outage.

Where the CIS Benchmarks meet the CIS Controls

The join is precise. The Controls include a safeguard requiring secure configuration of enterprise assets and software and the maintenance of documented configuration standards. The Benchmarks are those configuration standards, already written, already justified, already auditable. Adopting the relevant benchmark discharges the “documented standard” half of the safeguard on day one and leaves you the harder half — deployment, drift detection and exception management.

Read in that direction, the pairing is efficient:

  1. Use the Controls to decide what to do next, tailored by Implementation Group. Our guide to the CIS Controls v8.1 covers the 18 controls and the three groups.
  2. Use the Benchmarks to decide what “configured securely” means for each platform you actually run.
  3. Keep the exceptions in one register, with an owner and a review date, because the recommendations you deliberately do not apply are the ones an auditor will ask about.

Which one does a compliance requirement mean?

When a customer questionnaire or a contract says “CIS”, it almost always means one of two things, and the distinction changes the work:

  • “Aligned to the CIS Controls” — a program-level claim. Evidence is your safeguard-by-safeguard implementation record and your Implementation Group determination.
  • “Systems hardened to CIS Benchmarks” — a technical claim about builds. Evidence is a benchmark assessment report per platform, a documented profile level, and the exception register.

Neither is a certification. There is no CIS certificate and no accredited body auditing you against either document — which is exactly why the evidence you keep yourself matters. Where a certifiable framework is the goal, both feed it: ISO 27001 needs configuration standards and evidence of their application, and CIS material supplies both without inventing house rules from scratch. See our guide to the Statement of Applicability for where that evidence lands.

Frequently asked questions

Are the CIS Benchmarks free?
Yes, as PDF downloads. Automated assessment tooling, tailored benchmarks and pre-hardened cloud images sit behind membership.

How many CIS Benchmarks are there?
More than 100 configuration guides spanning over 25 vendor product families, from operating systems and cloud platforms to network devices, browsers and container tooling.

Should we apply Level 1 or Level 2?
Level 1 as the default; Level 2 for systems where security outweighs convenience and where you can test the impact first. The STIG profile only if DISA STIG compliance is a requirement.

Can we be certified against the CIS Benchmarks?
No. You can produce an assessment report showing conformance to a named benchmark and profile, and that is what customers actually ask for.

Do the CIS Benchmarks replace the CIS Controls?
No — they implement part of them. The Controls set priorities across the whole program; the Benchmarks answer one safeguard, deeply, per technology.

Where this leaves you

Use the CIS Controls to choose the work and the CIS Benchmarks to do it. Pick the Implementation Group that matches your size and risk, adopt the benchmark for each platform you run, set the profile level per system class rather than across the estate, and keep an exception register with owners and review dates. The pairing costs nothing to obtain and removes the two most common excuses in a security program — not knowing what to do next, and not knowing what “hardened” means.

References

More on security baselines

Configuration standards, exception registers and safeguard implementation records are in the CIS Controls v8.1 Toolkit, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.