Buyer's guide · CIS Controls v8
Best CIS Controls v8 implementation tools for MSPs
The best CIS Controls v8 tool for an MSP maps all 18 controls across IG1 to IG3, assesses CIS Benchmark hardening continuously, and bundles the patching and remediation that close the gaps. Lavawall® is built to meet those criteria. The Center for Internet Security Controls v8 are a prioritized set of cybersecurity controls used by cyber insurance, government procurement, and enterprise security teams alike.
Start your compliance wizard See the selection criteria
18 controls · IG1 / IG2 / IG3 · CIS Benchmarks · multi-tenant
The CIS Controls v8 are a prioritized set of 18 controls, each broken into safeguards and grouped into three Implementation Groups. They are widely adopted by cyber-insurance assessors, government procurement, and enterprise security programs because they tell you what to do first.
For an MSP, the practical need is to map many client tenants against the 18 controls, check configuration hardening against the CIS Benchmarks, and then remediate the gaps, all from one place and across every client at once.
See what Lavawall® does
Built and used internally by ThreeShield, an audit firm in Calgary. Built for MSPs and lean IT teams. Cross-platform patching, M365 / Entra / Azure / Google Workspace breach detection, 70+ compliance frameworks, administrator elevation and execution prevention (no kernel driver), smart helpdesk, multi-tenant remote support. One platform, native CAD billing.
What to look for in a CIS Controls v8 tool
Six capabilities matter when an MSP evaluates a CIS Controls v8 implementation tool.
- Direct mapping to all 18 controls. Coverage of every control and its safeguards across Implementation Groups 1 to 3.
- Configuration-hardening evidence. Assessment aligned to the CIS Benchmarks for Windows, macOS, Linux, M365, and related platforms.
- Continuous endpoint configuration collection. Ongoing evidence from the endpoints themselves, not a periodic scan.
- Multi-tenant architecture. Suitable for MSP operations, with per-client isolation.
- Co-branded posture reports. Client-facing reports formatted for insurance assessments.
- Integrated patching, application control, and breach detection. The ability to act on gaps in the same platform.
Options to evaluate
Four categories of tool show up in CIS Controls buying processes for MSPs.
Lavawall®
RMM with CIS Controls v8 first-class.
Lavawall® is a multi-tenant RMM and remote support platform for MSPs and IT teams, with patching, security monitoring, Microsoft 365 and Google Workspace breach detection, and compliance built into the same agent and console. Direct CIS Controls v8 mapping across all 18 controls and the IG1 / IG2 / IG3 safeguards, with continuous endpoint evidence and multi-tenant design optimized for MSPs delivering CIS readiness services.
Best when: MSPs deliver CIS readiness across many client tenants and want to close gaps in the same platform.
ConnectSecure / CyberCNS
MSP-focused vulnerability scanning with CIS reporting.
Strongest for per-client vulnerability deliverables. Check ConnectSecure’s documentation for bundled patching and application control.
Best when: an MSP wants per-client vulnerability reporting and already has patching covered elsewhere.
Tenable / Nessus + custom dashboards
Mature vulnerability scanning with custom dashboards.
Deep scanning capability. Check Tenable’s documentation for how it maps to the CIS Controls.
Best when: an organization has a dedicated vulnerability team.
Excel + audit-firm engagement
Manual approach.
A spreadsheet control register plus periodic audit-firm review. It does not scale for MSP delivery models.
Best when: a single small organization has limited scope and no MSP-as-a-service ambition.
How Lavawall® fits
Lavawall® maps directly to the CIS Controls v8 across all 18 controls and their safeguards, and collects configuration evidence continuously from Windows, macOS, and Linux. Evidence for patching, software inventory, account management, administrator elevation, and audit logs all flows from a single agent.
Because the same agent handles assessment and remediation, an MSP can see a CIS Benchmark deviation and close it, through patching, configuration change, or execution prevention, without switching platforms. Posture reports can be co-branded for the client and formatted for insurance assessments.
Multi-tenant by design lets one MSP run CIS readiness across many clients from a single console, with per-client isolation. CIS Controls v8 sits alongside CMMC 2.0, NIST CSF, SOC 2, ISO 27001, HIPAA, PCI DSS, and the Canadian privacy bundle as one of 70+ frameworks.
Frequently asked
- What is the difference between IG1, IG2, and IG3?
- Implementation Group 1 is the baseline set of safeguards every organization should achieve. IG2 adds safeguards for organizations managing sensitive data with moderate IT complexity. IG3 adds safeguards for organizations with extensive IT complexity, regulated data, and specific threat actors targeting them.
- Are CIS Controls and CIS Benchmarks the same?
- No. CIS Controls v8 are high-level prioritized security controls. CIS Benchmarks are configuration-hardening guides for specific systems that operationalize those controls.
- Does Lavawall® enforce CIS Benchmark configurations?
- Yes, through policy and scripting. Lavawall® also assesses configuration against CIS Benchmarks and surfaces deviations.