FORGED GOODSsmall, specific, verified digital tools

List All 153 CIS Controls v8 Safeguards for Your Compliance Tracker

If you're building a compliance tracking spreadsheet, audit inventory, or security roadmap, you need the full roster of CIS Controls v8 safeguards. The CIS Controls v8 framework organizes 153 distinct safeguards across 18 controls. Knowing which safeguards exist—and in what order—is the first step before you can assign ownership, set priority, or map them to SOC 2 or ISO 27001 requirements.

This guide shows you where to get the authoritative list, how to organize it for practical use, and what metadata to capture alongside each safeguard so you can actually track progress.

Where the Official List Lives

The CIS Controls v8 safeguards are published in the official CIS Controls v8 PDF, available free from the Center for Internet Security website. The document lists all 153 safeguards organized under 18 controls, each numbered sequentially (for example, Control 1 has safeguards 1.1 through 1.12). Download the PDF directly from CIS; it is the canonical source and updates occasionally, so check the publication date when you retrieve it.

Do not rely on third-party summaries or blog posts for the complete list—they often omit safeguards or contain outdated numbering. The PDF is your single source of truth.

How to Extract and Organize the Safeguard List

The CIS PDF presents safeguards in a narrative format with descriptions. To build a usable inventory, extract each safeguard number and title into a simple table:

A ready-made spreadsheet with all 153 safeguards pre-filled and mapped to SOC 2 and ISO 27001 clauses skips the manual data entry and cross-referencing of three separate standards documents—a task that typically takes 8–12 hours of reconciliation work.

Safeguards Grouped by Control Category

Understanding the distribution helps you prioritize implementation. CIS Controls v8 groups safeguards into roughly six categories:

Governance & Risk Management: Controls 1–4 cover inventory, asset management, data protection, and access control—18 safeguards total. These are foundational and often required first by auditors.

Security Operations: Controls 5–8 address account management, logging, email and web security, and malware defense—20 safeguards. Most require active tooling and monitoring.

Incident Response & Recovery: Controls 9–12 cover incident response, business continuity, network architecture, and service continuity—17 safeguards. Often revisited during crisis scenarios and audits.

Security Awareness & Training: Control 13 is dedicated to user training—4 safeguards that require organizational buy-in and ongoing effort.

Secure Software Development & Supply Chain: Controls 14–18 address secure development, code integrity, third-party risk, and security development frameworks—71 safeguards. These apply mainly to product companies and engineering teams.

Use this breakdown to identify which control families are most relevant to your organization's risk profile.

Common Pitfalls When Listing and Tracking Safeguards

Skipping the full list: Teams often cherry-pick the safeguards they think they need, missing critical dependencies. For example, you cannot properly implement safeguard 6.2 (logging and monitoring) without completing safeguard 5.2 (account lifecycle management).

Mixing v7 and v8 numbering: CIS Controls v8 renumbered safeguards from v7. If your compliance roadmap or audit checklist references v7 safeguard numbers, cross-reference them explicitly. The official CIS Controls v8 document includes a v7-to-v8 mapping table.

Treating all safeguards as equal priority: CIS does not rank safeguards by criticality—you must. Pair the full list with threat modeling or risk assessment to decide which safeguards to implement first. SOC 2 and ISO 27001 auditors typically expect foundational controls (inventory, access control, logging) before optional or advanced safeguards.

Not capturing safeguard context: A bare list of safeguard IDs is useless without implementation guidance. For each safeguard, also record the control description (from the PDF), the implementation group (IG1, IG2, or IG3), and relevant SOC 2 or ISO 27001 mappings if you are pursuing those certifications.

Next Steps: From List to Roadmap

Once you have the full list of 153 safeguards, decide which ones apply to your environment. Not every safeguard is relevant—for example, safeguards in Control 14 (Secure Software Development) apply primarily to teams that write production code; a managed services provider may deprioritize them.

For each safeguard you commit to, define success criteria (what does "complete" look like?), assign an owner, and set a target date. Review progress quarterly and update implementation status. If you are pursuing SOC 2 Type II or ISO 27001 certification, overlay the official mappings from those frameworks so you can track dual compliance in one inventory.

Use the full list as your baseline. Attempting to build a compliance tracking system without it will result in gaps, rework, and audit findings.

Skip the manual work: Startup Security Compliance Mapper: CIS v8 → SOC 2 & ISO 27001 Spreadsheet — €29, verified, instant download. Buy