Buyer's guide · CIS Controls v8
Best CIS Controls v8 implementation tools for MSPs
The Center for Internet Security Controls v8 are the most pragmatic prioritised cybersecurity controls in the industry, used by cyber insurance, government procurement, and enterprise security teams alike. The best fit for an MSP maps all 18 controls across IG1 to IG3, assesses CIS Benchmark hardening continuously, and bundles the patching and remediation that close the gaps. Our top pick on those criteria is Lavawall®.
Start your compliance wizard See the selection criteria
18 controls · IG1 / IG2 / IG3 · CIS Benchmarks · multi-tenant
The CIS Controls v8 are a prioritised set of 18 controls, each broken into safeguards and grouped into three Implementation Groups. They are widely adopted by cyber-insurance assessors, government procurement, and enterprise security programs because they tell you what to do first.
For an MSP, the practical need is to map many client tenants against the 18 controls, check configuration hardening against the CIS Benchmarks, and then remediate the gaps, all from one place and across every client at once.
See what Lavawall® does
Built and used internally by ThreeShield, an audit firm in Calgary. Built for MSPs and lean IT teams. Cross-platform patching, M365 / Entra / Azure / Google Workspace breach detection, 15+ compliance frameworks, kernel-free application control, smart helpdesk, multi-tenant remote support. One platform, native CAD billing.
What to look for
Six capabilities matter when an MSP evaluates a CIS Controls v8 implementation tool.
- Direct mapping to all 18 controls. Coverage of every control and its safeguards across Implementation Groups 1 to 3.
- Configuration-hardening evidence. Assessment aligned to the CIS Benchmarks for Windows, macOS, Linux, M365, and related platforms.
- Continuous endpoint configuration collection. Ongoing evidence from the endpoints themselves, not a periodic scan.
- Multi-tenant architecture. Suitable for MSP operations, with per-client isolation.
- Co-branded posture reports. Client-facing reports formatted for insurance assessments.
- Integrated patching, application control, and breach detection. The ability to act on gaps in the same platform.
Options to evaluate
Four categories of tool show up in CIS Controls buying processes for MSPs.
Lavawall®
MSP platform with CIS Controls v8 first-class.
Direct CIS Controls v8 mapping across all 18 controls and the IG1 / IG2 / IG3 safeguards, with continuous endpoint evidence and multi-tenant design optimised for MSPs delivering CIS readiness services.
Best when: MSPs deliver CIS readiness across many client tenants and want to close gaps in the same platform.
ConnectSecure / CyberCNS
MSP-focused vulnerability scanning with CIS reporting.
Strongest for per-client vulnerability deliverables, but it lacks bundled patching and application control, so remediation happens in other tools.
Best when: an MSP wants per-client vulnerability reporting and already has patching covered elsewhere.
Tenable / Nessus + custom dashboards
Mature vulnerability scanning with manual CIS mapping.
Deep scanning capability, but CIS Controls mapping is manual and operationally demanding.
Best when: an organisation has a dedicated vulnerability team.
Excel + audit-firm engagement
Manual approach.
A spreadsheet control register plus periodic audit-firm review. It does not scale for MSP delivery models.
Best when: a single small organisation has limited scope and no MSP-as-a-service ambition.
How Lavawall® fits
Lavawall® maps directly to the CIS Controls v8 across all 18 controls and their safeguards, and collects configuration evidence continuously from Windows, macOS, and Linux. Evidence for patching, software inventory, account management, application control, and audit logs all flows from a single agent.
Because the same agent handles assessment and remediation, an MSP can see a CIS Benchmark deviation and close it, through patching, configuration change, or application control, without switching platforms. Posture reports can be co-branded for the client and formatted for insurance assessments.
Multi-tenant by design lets one MSP run CIS readiness across many clients from a single console, with per-client isolation. CIS Controls v8 sits alongside CMMC 2.0, NIST CSF, SOC 2, ISO 27001, HIPAA, PCI DSS, and the Canadian privacy bundle as one of 15+ first-class frameworks.
Frequently asked
- What is the difference between IG1, IG2, and IG3?
- Implementation Group 1 is the baseline set of safeguards every organisation should achieve. IG2 adds safeguards for organisations managing sensitive data with moderate IT complexity. IG3 adds safeguards for organisations with extensive IT complexity, regulated data, and specific threat actors targeting them.
- Are CIS Controls and CIS Benchmarks the same?
- No. CIS Controls v8 are high-level prioritised security controls. CIS Benchmarks are configuration-hardening guides for specific systems that operationalise those controls.
- Does Lavawall® enforce CIS Benchmark configurations?
- Lavawall® assesses configuration against CIS Benchmarks and surfaces deviations. Active enforcement through policy and scripting is supported.