CIS Controls vs NIST CSF is a comparison between a prioritised list of things to do and a framework for describing what you have done — and most organisations that pick one end up using the other as well. The CIS Critical Security Controls v8.1 are 18 Controls containing 153 Safeguards, ordered by what prevents the most damage soonest and tiered into three Implementation Groups: IG1 is 56 Safeguards of essential cyber hygiene, IG2 adds 74 to reach 130, and IG3 is all 153.
The NIST Cybersecurity Framework 2.0, published on 26 February 2024, is six Functions — Govern, Identify, Protect, Detect, Respond, Recover — with 22 Categories and 106 Subcategories written as outcomes, plus Tiers and Profiles for describing how well and how far an organisation achieves them. Neither is certifiable. CIS maps every Safeguard to a CSF 2.0 Function, and v8.1 was the release that realigned those mappings to CSF 2.0 and added the Govern function. This guide sets the two side by side on five differences, shows how the mapping works, explains which to start with for four common situations, and describes how the two run together.

CIS Controls vs NIST CSF: what each one is
The CIS Controls are published by the Center for Internet Security and maintained from attack data by a volunteer community. Each Control is a theme — Inventory and Control of Enterprise Assets, Data Protection, Audit Log Management — and each Safeguard inside it is a specific, testable action with a frequency: review the asset inventory bi-annually, address unauthorised assets weekly, lock sessions after 15 minutes. The Implementation Groups decide which Safeguards apply: IG1 for organisations with limited IT and security expertise, IG2 for those with dedicated IT staff, IG3 for those with security specialists and public-harm exposure. Our guide to the CIS Controls v8.1 covers all 18 and the three groups.
NIST CSF 2.0 is the successor to CSF 1.1, with the Govern Function added and the scope widened from critical infrastructure to all organisations. The Core is written as outcomes — “assets are inventoried”, “incidents are contained” — that say what should be true, not how. Tiers 1 to 4 describe the rigour of governance and risk management; Current and Target Profiles describe where the organisation is and wants to be against the outcomes it selects. Our guide to NIST CSF 2.0 vs 1.1 covers the 2024 changes.
CIS Controls vs NIST CSF: the five differences
| Difference | CIS Controls v8.1 | NIST CSF 2.0 |
|---|---|---|
| 1. What it tells you | What to do, in what order, how often — 153 prescriptive Safeguards | What outcomes to achieve — 106 Subcategories — without prescribing how |
| 2. Prioritisation | Built in: Controls are ordered and Implementation Groups define the starting set | None inside the Core; the organisation prioritises through Profiles and risk assessment |
| 3. Scope | Technical and operational security controls; governance added as a security function in v8.1 | Whole-programme: governance, supply chain, risk strategy, plus the technical outcomes |
| 4. Measurement | Safeguard implemented or not; CIS CSAT scores policy, implementation, automation and reporting per Safeguard | Tiers for governance rigour; Profiles for outcome achievement; no scoring built in |
| 5. Who uses it | IT and security teams that need a work list; small and mid-size organisations via IG1; CISA CPGs and many state requirements point at it | Executives, boards, regulators and assessors that need a common vocabulary; US federal expectations; many sector regulators reference it |
1. Prescription vs outcome
CSF Subcategory PR.PS-01 says configuration management practices are established and applied. CIS Safeguard 4.3 says configure automatic session locking after at most 15 minutes on general-purpose operating systems and 2 minutes on mobile devices. The CSF outcome is satisfied by the CIS Safeguard; the CIS Safeguard is one of many ways to satisfy the CSF outcome. That relationship is the whole CIS Controls vs NIST CSF comparison in miniature.
2. Prioritisation
The CIS Controls exist to answer “what first?” — Control 1 is asset inventory because everything downstream depends on it, and IG1 is the 56 Safeguards CIS calls essential cyber hygiene. The CSF deliberately does not rank its outcomes; it expects the organisation to build a Target Profile from its risk assessment. An organisation with no risk assessment and no security staff cannot use the CSF to decide where to start; it can use IG1.
3. Scope
CSF 2.0’s Govern Function — organisational context, risk management strategy, roles, policy, oversight, supply chain risk management — has no CIS equivalent beyond the governance function tag and the policy-defined dimension of CSAT. The CIS Controls assume someone has decided the organisation should be secure; the CSF includes deciding it.
4. Measurement
CIS Controls measurement is binary at Safeguard level with CSAT’s four-dimension scoring layered on; CSF measurement is the Tier (1 Partial to 4 Adaptive) and the gap between Current and Target Profile. Boards understand the second; engineers act on the first.
5. Demand
Cyber insurers, CISA’s Cybersecurity Performance Goals and several US state laws point at the CIS Controls or at IG1 specifically as a reasonable baseline. Federal agencies, sector regulators and international partners reference the CSF. A supplier questionnaire is more likely to ask for a CSF Profile; an insurer is more likely to ask whether IG1 is implemented.
CIS Controls vs NIST CSF: how the mapping works
CIS tags every Safeguard with one CSF 2.0 security function — Govern, Identify, Protect, Detect, Respond or Recover — and publishes a Safeguard-to-Subcategory mapping through the CIS Controls Navigator, alongside mappings to ISO 27001:2022, NIST SP 800-53 Rev 5, PCI DSS v4.0, CMMC 2.0, NIS2, DORA and others. The practical consequences:
| CSF 2.0 Function | CIS Controls that carry most of it | Gap when using CIS alone |
|---|---|---|
| Govern (GV) | Policy-defined dimension of every Safeguard; 15 Service Provider Management; 17.1 incident response process | Risk strategy, roles, oversight, supply chain strategy — CSF-only content |
| Identify (ID) | 1 Enterprise assets, 2 Software assets, 3.2 Data inventory, 7 Vulnerability management, 15 Service providers, 18 Penetration testing | Improvement (ID.IM) as a programme outcome |
| Protect (PR) | 3 Data protection, 4 Secure configuration, 5 Accounts, 6 Access control, 9 Email and browser, 10 Malware, 11 Data recovery, 12 Network infrastructure, 14 Awareness, 16 Application security | Little; this is where CIS is deepest |
| Detect (DE) | 8 Audit logs, 13 Network monitoring and defense | Adverse event analysis as an outcome |
| Respond (RS) | 17 Incident response management | Communication and analysis outcomes beyond the CIS process |
| Recover (RC) | 11 Data recovery; 17 recovery elements | Recovery communication |
CIS Controls vs NIST CSF: which to start with
| Situation | Start with | Then |
|---|---|---|
| Small organisation, no dedicated security staff | CIS Controls IG1 | Describe the result as a CSF Profile when a customer asks |
| Mid-size with IT staff, no framework yet | CIS Controls IG2 as the work list | CSF 2.0 Govern outcomes for the programme layer |
| Board or regulator asks for a framework | NIST CSF 2.0 Current and Target Profiles | CIS Safeguards as the implementation of the Protect and Detect gaps |
| Already ISO 27001 certified | Neither is required; CSF for the vocabulary, CIS for technical depth | Use the CIS mapping to ISO 27001:2022 to avoid duplicate evidence |
Our guide to the NIST CSF audit checklist covers testing CSF outcomes; CIS Controls assessment covers CSAT scoring.
Running CIS Controls and NIST CSF together
- Use the CSF as the frame and CIS as the content. Build the Target Profile from CSF 2.0 outcomes; populate each Protect, Detect, Respond and Recover outcome with the CIS Safeguards that implement it, using CIS’s own mapping.
- Take the Implementation Group as the Profile’s floor. IG1 or IG2 defines the minimum Safeguard set; the Profile adds the Govern outcomes and any risk-driven additions.
- Measure once. A CSAT assessment gives Safeguard-level scores; roll them up into the CSF Profile’s outcome status rather than assessing twice.
- Report in CSF, work in CIS. The board sees Functions and Tiers; the team sees Safeguards with owners and frequencies.
- Keep the mapping current. CIS updates the Navigator mappings when either side changes; v8.1’s realignment to CSF 2.0 is the reason to be on v8.1 rather than v8.
Frequently asked questions
What is the difference between the CIS Controls and NIST CSF?
The CIS Controls are a prioritised, prescriptive list of 153 Safeguards in 18 Controls, tiered into Implementation Groups; the NIST CSF 2.0 is an outcome-based framework of 6 Functions, 22 Categories and 106 Subcategories with Tiers and Profiles. CIS tells you what to do; CSF describes what should be true.
Do the CIS Controls map to NIST CSF 2.0?
Yes. CIS tags every Safeguard with a CSF 2.0 security function and publishes Safeguard-to-Subcategory mappings through the CIS Controls Navigator; v8.1 realigned the mappings to CSF 2.0 and added the Govern function.
Which is better for a small business?
CIS Controls IG1 — 56 Safeguards CIS defines as essential cyber hygiene — gives a small organisation a concrete starting list; the CSF assumes a risk assessment and a Profile the small organisation has not built yet.
Is either one certifiable?
No. Neither has an accreditation scheme or certificate. CIS CSAT scores implementation of the Safeguards; CSF Profiles and Tiers describe outcome achievement and governance rigour.
Can we use both?
Most organisations do: the CSF as the programme frame and reporting vocabulary, the CIS Controls as the implementation content for the technical outcomes, with the Implementation Group as the floor of the Target Profile.
Where this leaves you
Treat CIS Controls vs NIST CSF as a division of labour rather than a choice: the CIS Controls decide what to do first and how often, the CSF describes the programme to the people who fund and regulate it, and CIS’s own mapping joins them — so start with the Implementation Group that fits, frame it as a CSF Profile, and measure once.
References
- CIS — CIS Critical Security Controls v8.1 — What changed in v8.1, including the CSF 2.0 realignment and the Governance function.
- CIS — CIS Controls Navigator — Safeguard-level mappings to NIST CSF 2.0, ISO 27001:2022 and other frameworks; Implementation Group membership.
- NIST — Cybersecurity Framework 2.0 — The CSF 2.0 Core, Tiers and Profiles.
More on the CIS Controls
- CIS Controls vs NIST CSF — you are here
- CIS Controls v8.1: the 18 Controls and 3 Implementation Groups
- CIS Controls to ISO 27001 mapping
- CIS Controls assessment: CSAT and scoring
- CIS Controls implementation: the IG1 plan
- CIS Benchmarks vs CIS Controls
The Safeguard-level implementation tracker with Implementation Group and CSF function per row, the 18 Control policies and the CSF Profile template are in the CIS Controls v8.1 Toolkit, or start with the free templates.