ShopCIS Controls Playbook Library
CIS Controls v8.1 · implementation, not restatement

Implement the CIS Controls without starting from a blank page

The framework tells you what. This library is the how: the 18 controls as real playbooks, what good looks like, how to implement it on a Windows / AD / Microsoft 365 estate, the common mistake, and the evidence an assessor asks for. Written by a working security practitioner.

See what's in the library First: how ready am I? →

  • 18 control playbooks · all 153 safeguards tracked
  • Mapped to ISO 27001:2022, NIST CSF 2.0, 800-53 & NIS2
  • Inventories & registers pre-seeded with worked examples
  • No DRM · editable files you own
Start free

Two free resources before you spend anything

Score your essential-hygiene posture first, then take the one-page reference. Both are genuinely useful on their own, and the best way to judge whether the paid library is worth it.

CIS IG1 Readiness Scorer

Free

Answers Where do we stand on essential cyber hygiene?

Fifteen plain-English questions across the highest-consequence IG1 safeguards, giving you a banded score and the single most valuable thing to do next, in about ten minutes.

  • Interactive
  • 10 minutes
  • No signup
£0on this page
Run the readiness scorer

CIS Controls v8.1 on One Page

Free

Best for pinning above your desk

The whole framework distilled: the 18 controls with the one thing to get right on each, the Implementation Groups, the four safeguards that save you, and the order to do it all in.

  • 1 page
  • PDF
  • Print-ready
£0instant download
Download the cheat sheet
Free IG1 readiness scorer

How ready are you for essential cyber hygiene?

IG1 is the 56 safeguards that define essential cyber hygiene, the floor every organisation is judged against. Answer honestly for the whole organisation. Score each: Yes = 2, Partly = 1, No or Don't know = 0. This is a self-assessment, not a certification.

1. Do you have a current inventory of all devices (incl. cloud and remote), updated automatically or reconciled at least monthly? Safeguard 1.1
2. Do you have a current inventory of installed software, with end-of-life software flagged? Safeguards 2.1 to 2.2
3. Do IT staff use separate, dedicated admin accounts (not their everyday account) for privileged work? Safeguard 5.4 · one of the four that save you
4. Is MFA enforced on all administrator accounts? Safeguard 6.5 · one of the four that save you
5. Is MFA enforced on all remote and internet-facing access? Safeguards 6.3 to 6.4
6. Are dormant accounts disabled, and are leavers' accounts disabled promptly? Safeguards 5.3, 6.2
7. Are devices configured to a hardened baseline enforced by policy (GPO/Intune), not left at defaults? Safeguard 4.1
8. Is operating-system patching automated? Safeguard 7.3
9. Is third-party application patching automated (browsers, runtimes, PDF/Java-class apps)? Safeguard 7.4
10. Is full-disk encryption on all laptops, with recovery keys escrowed? Safeguard 3.6
11. Do you have automated backups with one immutable or offline copy ransomware cannot reach? Safeguards 11.3 to 11.4 · one of the four that save you
12. Have you actually restored from backup recently to confirm it works? Safeguard 11.5 · one of the four that save you
13. Is DNS filtering enforced and modern anti-malware (auto-updating) on all devices, servers included? Safeguards 9.2, 10.1 to 10.2
14. Do all staff get security-awareness training on onboarding and at least annually, with completion tracked? Safeguard 14.1
15. Is there a named incident lead and a simple, known way for staff to report a suspected incident? Safeguards 17.1 to 17.3

JavaScript is off, so score it yourself: Yes = 2, Partly = 1, No = 0, out of 30. 25+ is a strong IG1 posture; 17 to 24 has real gaps; 9 to 16 is early; under 9 is exposed. Whatever your total, a "No" on questions 3, 4, 11 or 12 is worth fixing before anything else, they are the four that save you.

Prefer paper? The printable worksheet is in the free cheat sheet and the Starter Pack workbook.

Entry, the on-ramp

Not ready for the full library? Start here.

A guided workbook and the complete 56-item IG1 checklist. Enough to get a small team to essential cyber hygiene, and everything maps straight onto the Core library when you outgrow it.

CIS Implementation Workbook

.PDF

Best for a small team starting cold

One guided document you work top to bottom: scope, your Implementation Group, governance, a first self-score, a starter risk list, the four that save you, and a gap list that becomes your project plan.

  • 8 sections
  • Fill-in
  • Maps to Core

CIS IG1 Checklist

.XLSX

Best for a fast self-assessment

All 56 IG1 safeguards as concrete items, each with what "done" looks like, plus Status / Owner / Evidence columns so it doubles as an assurance tracker with a per-control roll-up.

  • 56 safeguards
  • Self-score
  • Trackable
Entry bundle

CIS Starter Pack

The Workbook and the IG1 Checklist together, the fastest way to find out where you stand and what to fix first.

  • CIS Implementation Workbook
  • CIS IG1 Checklist (56 safeguards)
Coming soon Pricing under review Coming soon

Launching shortly

Core, flagship The CIS Controls Playbook Library

Everything to go from "we've never done this" to an evidenced control programme

Eleven deliverables that fit together: the playbooks explain it, the tracker records it, the inventories and registers feed it, the policies document it, the roadmap sequences it, the maturity workbook scores it, and the board pack proves management owned it.

  • 01The 18 Control PlaybooksEvery control as what-good-looks-like, how to implement it (Microsoft-stack specifics), the common mistake, how to validate, and the evidence to file. Split IG1/IG2/IG3.
  • 02Safeguard Implementation TrackerAll 153 safeguards with IG flags, asset type, security function and Status/Owner/Evidence/Review. Your system of record. Spreadsheet.
  • 03Enterprise Asset InventoryThe Control 1 foundation, pre-seeded and ready, including a worked unauthorised-asset example.
  • 04Software InventoryThe Control 2 foundation with a support-status flag, seeded with EOL and unauthorised-software examples.
  • 05Risk RegisterTen worked, control-mapped risks (ransomware, Kerberoasting, MSP compromise…) with 5×5 inherent/residual scoring and treatments.
  • 06Framework MappingAll 18 controls cross-walked to ISO/IEC 27001:2022, NIST CSF 2.0, NIST 800-53 Rev.5 and NIS2 Article 21. Spreadsheet.
  • 07Policy & Standard PackEight ready-to-adopt policies covering the documented half of Controls 1 to 15 and 17. Short enough to actually maintain.
  • 08IG1 → IG3 RoadmapA proportionate, dependency-aware sequence with owners and artifacts, plus the maintained-state cadence beyond go-live.
  • 09Maturity WorkbookScore every control 0 to 5, roll it up per control and per IG, and show the trend line quarter on quarter.
  • 10Audit & Evidence WorkbookEvery control mapped to the artifact an assessor asks for, plus an assessment-readiness checklist. The audit becomes a lookup.
  • 11Board Reporting PackThe quarterly report, the management sign-off record, the director-training record, and a six-slide board spec. The governance evidence teams rarely produce.
One-time · yours to keep

CIS Controls Playbook Library

All eleven deliverables in one download. Built for the IG1-bound SMB and the consultant, MSP or internal team serving one, proportionate, practical, and mapped to the frameworks you already report against.

  • 18 control playbooks + IG1→IG3 roadmap
  • 153-safeguard tracker + inventories + risk register
  • Framework mapping + 8-policy pack
  • Maturity workbook + audit workbook + board pack
Coming soon Pricing under review Coming soon

Launching shortly

Premium, for teams & MSPs

Deliver the CIS Controls to a whole portfolio, or run the room

For the people who take others through the CIS Controls: consultants, MSPs, and internal leads. Licensed for client delivery and rebrandable.

CIS Team / MSP Edition

.PDF+.XLSX

Best for MSPs, MSSPs and vCISOs

A productised 5-phase IG1 engagement you can quote and repeat, a portfolio-wide multi-client posture tracker, and the provider's own obligations, because if you hold privileged access, you are your clients' biggest supply-chain risk.

  • Multi-client tracker
  • Rebrandable
  • Engagement model
Coming soonpricing under review
Coming soon

CIS Controls Workshop Pack

.PPTX+.PDF

Best for running a prioritisation session

A ready-to-run 3-hour workshop: a 22-slide deck and a facilitator guide with a minute-by-minute run sheet, that turns "we should look at the CIS Controls" into an owned, prioritised top-ten action list in one sitting.

  • 22 slides
  • Facilitator guide
  • Run sheet
Coming soonpricing under review
Coming soon
Bundle · best value

Controls + Compliance

The CIS Controls are how you implement the technical measures NIS2 Article 21 demands. Pair the Playbook Library with the NIS2 Compliance Toolkit and cover both the controls and the directive with one connected evidence base, at a saving over buying them apart.

Two lines, one bundle Coming soon Bundle pricing under review
Choose your tier

From free readiness score to full portfolio delivery

Every tier is a step up from the last, and each one credits into the next. Start where you are.

TierWhat you getBest forPrice
Free IG1 readiness scorer + one-page cheat sheet "Where do we stand?" $0 Start
Entry Starter Pack: Implementation Workbook + 56-item IG1 Checklist A small team starting cold Coming soon Preview
Core Playbook Library: 18 playbooks, 153-safeguard tracker, inventories, registers, policies, roadmap, maturity + audit workbooks, board pack Building an evidenced programme Coming soon Preview
Premium Team / MSP Edition · Workshop Pack Delivering CIS to others Coming soon See both
Bundle CIS Playbook Library + NIS2 Compliance Toolkit Controls and the directive together Coming soon See bundle
Before you buy

CIS Controls library FAQ

Is this affiliated with the Center for Internet Security?

No. This is independent implementation guidance written by a practitioner. The authoritative CIS Controls and Safeguards text is owned by CIS and is free at cisecurity.org/controls. We reference and paraphrase the framework for implementation, we do not reproduce it, and this is not a CIS certification.

Who is the library for?

IG1-bound SMBs and the consultants, MSPs and internal IT/security teams serving them. It is written to be proportionate, a 40-person firm is not held to a hospital's standard, and it is anchored to CIS Controls v8.1 with a strong Windows / Active Directory / Microsoft 365 focus.

What format do I receive?

Editable working files: the playbooks, roadmap, maturity workbook, audit workbook and board pack as PDFs; the 153-safeguard tracker, inventories, risk register and framework mapping as spreadsheets; the eight policies as ready-to-adopt templates. Nothing is DRM-locked and nothing phones home.

Does it map to ISO 27001, NIST or NIS2?

Yes. Every one of the 18 controls is cross-walked to ISO/IEC 27001:2022 Annex A, NIST Cybersecurity Framework 2.0, NIST SP 800-53 Rev. 5 and NIS2 Article 21. Collect the evidence once and satisfy multiple assessments, and most cyber-insurance questionnaires. If you also face NIS2, see the Controls + Compliance bundle.

How is this different from the free CIS material?

The free CIS material tells you what each safeguard requires. This tells you how to implement it on a real estate: what good looks like, the Microsoft-stack specifics, the common mistake that fails an audit, how to validate it, and the exact evidence to file. Plus pre-filled trackers, inventories, registers, policies, a phased roadmap and a board pack. The blog shows the depth for free, read it first.