Frameworks · Global standards

CIS Controls v8 compliance, run as a living system

The CIS Critical Security Controls v8 define a prioritised set of safeguards grouped into implementation groups, widely used as a practical technical baseline.

Who it applies to

Organisations that want a prioritised technical baseline, often beneath ISO 27001 or a sector mandate.

What it demands

Basic cyber hygiene

Inventory of assets and software, data protection, secure configuration and account management.

Operational safeguards

Vulnerability management, log management, malware defences and recovery.

Programme safeguards

Penetration testing, awareness training and incident response management.

How Compli-Once runs it

  • 1

    Safeguards modelled per implementation group so scope matches your maturity.

  • 2

    Crosswalked to ISO 27001, SOC 2 and NIST so technical evidence is reused everywhere.

  • 3

    Vulnerability and drill evidence carries expiry, so lapses raise work rather than findings.

What you already satisfy

CIS Controls v8 overlaps with frameworks you may already run. The crosswalk quantifies existing coverage on day one, before you plan a single task.

Implement once, satisfy many

Access control
ISO 27001 A.5.15SOC 2 CC6.1SEBI CSCRF PR.AARBI CSF Access Mgmt
Incident response
ISO 27001 A.5.24SOC 2 CC7.3SEBI CSCRF 6-hour report
Change management
ISO 27001 A.8.32SOC 2 CC8.1PCI DSS v4 6.5

In a representative demonstration environment, 61% of a newly adopted regulatory framework was already satisfied by the existing ISO 27001 programme.

Illustrative, computed live per tenant in the platform.

Frequently asked questions

Which implementation group applies?

Scope is configured per tenant, so only the safeguards in your chosen group are assessed and reported.

Can CIS evidence serve an audit?

Yes. The same evidence records are requested by auditors through the portal, with owner and date intact.

You're done. We're not.

The audit ends. The readiness doesn't. See it on your own data.