CIS CONTROLS v8.1RUN THE WORLD'S MOST-DEPLOYED CYBER BASELINE AS A MANAGED PROGRAM
Assess, prioritize, remediate, and prove CIS CONTROLS v8.1 from one platform — with AI governance and shadow-tool visibility built into the same workflow your auditors and insurers already ask about.
CIS CONTROLS IN 60 SECONDS
18 Controls, 153 Safeguards
CIS CONTROLS v8.1 is the prioritized cybersecurity baseline maintained by the Center for Internet Security — the same one insurers, regulators, and enterprise buyers anchor their questions to.
Scoped by Implementation Group
Every Safeguard is tagged IG1 (essential hygiene), IG2 (depth for growing organizations), or IG3 (advanced) so you size the program to your risk, not someone else's checklist.
Now in cyber-insurance and AG safe-harbor laws
Cyber-insurance applications, state attorney-general safe-harbor statutes, and enterprise vendor questionnaires all reference CIS v8.1 — and the same buyers now want AI governance evidence in the same breath.
THE CIS PROBLEM NOBODY WARNED YOU ABOUT
These are the gaps that stall cyber-hygiene programs — and quietly burn budget before auditors or insurers even arrive.
Cyber hygiene lives in spreadsheets
Security teams track 153 CIS Safeguards across tabs and screenshots, so coverage drifts, owners disappear, and audits stall before they start.
Implementation Groups get misapplied
Without a structured tool, organizations over-scope to IG3 and burn budget — or under-scope to IG1 and leave real exposure open.
AI and shadow IT outrun the baseline
New AI tools and agentic workloads land daily, but legacy cyber-hygiene programs have no way to fold them into CIS coverage — so the most volatile assets stay invisible.
WHAT YOU GET WITH RAIC
Buyer outcomes first. Every value below ties to a Safeguard your auditor, insurer, or enterprise customer already plans to test.
Full CIS CONTROLS v8.1 catalog, pre-loaded
All 18 Controls and 153 Safeguards ship pre-loaded, with the official Implementation Group (IG1, IG2, IG3) and Asset Type metadata on every row — no spreadsheet to maintain.
One-click Implementation Group scoping
Filter your program to IG1 essential hygiene, IG2 depth, or IG3 advanced, then track coverage and gaps live by Group so leadership sees progress in their language.
POA&M register plus evidence vault
Convert any Safeguard gap into a tracked remediation item with owner, due date, and status — then attach fingerprinted, hash-chained evidence so auditors and insurers verify proof rather than accept promises.
Crosswalks to the frameworks buyers ask about
Live mapping from every Safeguard to NIST CSF 2.0, ISO 27001, SOC 2, and the EU AI Act so one piece of evidence answers multiple questionnaires.
Board-ready reports and Aslan AI (Enterprise)
Capture posture snapshots for trend reporting, and ask plain-English questions cited against your live CIS data — built for the audiences that fund and govern the program.
WHAT'S INSIDE THE CIS MODULE
Each capability covers a named CIS Control family — and produces the artifact your auditor or insurer will request.
Asset and software inventory you can trust
Covers Controls 1 and 2 with a living register of enterprise and software assets, owners, and authorization status — the foundation every other Safeguard depends on.
Data protection and classification
Covers Control 3 with sensitivity tagging, handling rules, and evidence that protected data stays where your policies say it does.
Secure configuration and change discipline
Covers Controls 4 and 7 with baseline configuration tracking and vulnerability management workflows so drift and unpatched systems surface before attackers find them.
Account and access management
Covers Controls 5 and 6 with account inventory, privileged-access oversight, and access-review evidence aligned to your joiner-mover-leaver process.
Audit log management with retention
Covers Control 8 with logging coverage, retention proof, and review cadence — the evidence both insurers and incident responders ask for first.
Email, browser, and network defenses
Covers Controls 9, 12, and 13 with hardening posture, monitoring, and shadow-tool visibility — including the AI services employees adopt without telling IT.
Incident response with corrective action
Covers Control 17 with a documented response workflow, root cause, corrective action, and effectiveness verification — the artifacts auditors and regulators expect.
Penetration testing and continuous improvement
Covers Controls 18 and the awareness-training scope of Control 14 with scheduled testing, findings tracking, and training evidence tied back to the Safeguards they support.
PRICING THAT MATCHES YOUR CIS PROGRAM STAGE
Pick the tier that matches where your program sits today. Move up as your scope and reporting needs grow.
Professional — $499/month
CIS CONTROLS v8.1 hub, IG1/IG2/IG3 scoping, POA&M register, evidence vault, and standard reports included.
Enterprise — Custom
Adds Aslan AI Copilot, scheduled posture snapshots, multi-framework crosswalks, and MSP multi-tenant rollups.
MSP Partners — included per tenant
Deliver CIS CONTROLS assessments to every client tenant from the Partner Portal with no per-client license cost.
WHY MOVE NOW
Insurers, regulators, and enterprise buyers already anchor to CIS Controls v8.1 — and the same buyers now demand AI governance evidence alongside it. RAIC delivers both from one pane of glass.
- Cyber-insurance applications already ask for CIS v8.1 coverage by Implementation Group — vague answers cost premium dollars.
- State attorney-general safe-harbor laws cite CIS CONTROLS as a recognized standard — adoption is now a litigation shield, not a checkbox.
- Enterprise vendor questionnaires bundle CIS coverage with explicit AI governance attestations — losing one loses the deal.
- Shadow AI keeps expanding your asset surface — CIS coverage that ignores AI is already out of date.
CIS Controls v8.1 Framework Assessment
Run a scored CIS Controls v8.1 readiness assessment inside RAIC and export the results — plus the underlying evidence — as an audit-ready download. Stop rebuilding the same gap analysis in spreadsheets.
Scored assessment
Question-by-question readiness scoring with maturity bands, owner assignment, and re-assessment cadence.
Mapped to the standard
Every item maps to all 18 Controls and 153 Safeguards across IG1, IG2, and IG3 — so a single answer drives both the score and the evidence trail.
Downloadable evidence
Export a branded DOCX report plus a ZIP of the underlying evidence (RhindonCyber_CIS-Controls-Assessment_*.docx + .zip) — ready to hand to your auditor.
Framework Assessment + downloadable evidence is available on ISO 42001, NIST AI RMF, EU AI Act, SOC 2, CIS Controls v8.1, and HIPAA.
From the Resources library
Pair CIS CONTROLS coverage with the adjacent frameworks your buyers and regulators already ask about.
TAKE THE NEXT STEP
Three doors. One team. Pick the one that fits where your CIS program is today.
