Eighteen controls holding 153 safeguards, from the Center for Internet Security. Nobody is short of security advice, so the list is not the contribution — the sequence is. These are opinionated about which control you build first, and that opinion is what you are actually buying.
There are eighteen CIS Controls. Two of them decide the rest.
Eighteen controls is not what the framework contributes. The order you build them in is.
Our promise
“A checklist is an intention. Measurement is evidence.”
Every finding is written against a clause of the instrument itself — defensible line by line, to anyone who asks. The fee is fixed at $6,500, and nothing is charged until you approve it.
- Each additional tool
- $1,500
- Re-audit, same scope
- $4,200
- Renewal, every twelve months
- $5,500 locked
This costs more than the estate ladder, and it should. The ladder is a private assessment written for you. A framework audit produces a published summary iDharma maintains for twelve months - a notice template where the law requires one, a 60-day expiry warning, and a quarterly check that the summary is still live and still linked.
Request this auditThe Controls, in three chapters
Three Implementation Groups say how far along that sequence you need to go. IG1 is essential hygiene and the floor for every organisation; IG2 and IG3 are decisions rather than achievements, taken against the attacks you actually face and the budget you actually have to spend.
Controls 1 and 2 are inventory, and everything after them is scoped from what those two produce. A new AI estate fails them almost without exception, because the models and the pipelines arrived as product features rather than as assets anybody thought to catalogue at the time.
Not how many you do, how far along you go.
IG1 is the floor for everyone. Past it, the group is a decision.
- IG1 — essential hygiene, the floor for everybody
- IG2 — where most teams with security resource belong
- IG3 — chosen under sustained, targeted attack
- The choice is yours to make, and to write down
- Models in production, and the ones behind them
- Inference endpoints nobody registered as assets
- Notebook environments and training pipelines
- Training corpora, retrieval indexes and prompt logs
The list is published. The order is the work.
The organisation that picks the group
Nothing here is imposed on anybody, so the only person who decides how far along the sequence you go is you. IG1 is the floor rather than an ambition, and choosing to go beyond it is a judgement about the attacks you actually face and the money you actually have available to spend on any of it.
The customer with the questionnaire
Most organisations meet the Controls through somebody else's due diligence rather than by choosing them for themselves. That changes the useful answer: not how many safeguards you hold, but which group you work to and why you drew the line exactly where you drew it, in writing.
Nobody certifies you against these
CIS accredits no assessors and issues no certificate against the Controls, so any firm offering you one is selling something that does not exist. We review against them in their own order and write down what is missing, in the sequence it should actually be built, not the order you bought it in.
“We started with the AI-specific controls.”
Start at Control 1. Nobody has it.
The order is the contribution. Discarding it discards the framework.
- Who it is for
- New AI estates
- CSF & ISO 27001 users
- Finite security budgets
- Vendor questionnaires
- First security programmes
Inventories were built before the AI estate existed, so they contain none of it. Controls 1 and 2 are where that shows, immediately.
Safeguards get built in the order they are easiest rather than the order published. That is the framework’s one opinion, discarded.
A group is drifted into rather than chosen. Nobody can say which bar they are working to, so nothing can be graded against it.
Three questions. Then you’ll know.
No email. No signup. A starting point, not a determination.
Your group check
Four moves, and the first one decides the rest.
The framework’s own sequence, which is the part worth keeping. Built in a different order, these stop being the CIS Controls.
-
Inventory
Before anythingControls 1 and 2, with models and pipelines included. Everything after this is scoped from it.
-
Pick the group
Then chooseIG1, IG2 or IG3, decided against the attacks you actually face, and written down with its reasoning.
-
Build
In orderThe safeguards in the sequence the framework sets them, not in the order they happen to be easiest.
-
Measure
Every quarterA ticked box records an intention. What counts is whether the safeguard is still operating today.
Teams reach for the interesting safeguards first, because inventory is nobody’s favourite week. Built on an estate nobody has listed, every control after the second one is applied to a system somebody assumed rather than found.
What the control asks, what we ship
All eighteen controls, in the order the framework sets them. Paired, so every claim can be checked against the ask.
- Asset and software inventory Controls 1-2 - Where every AI estate fails
- Every model, inference endpoint, notebook environment and pipeline listed with an owner - the artefact every control after this one is scoped from, and the one almost nobody has.
- Data protection and configuration Controls 3-4 - Classify, then harden
- Training corpora, retrieval indexes, evaluation sets and prompt logs classified before they are controlled, and model serving hardened against a baseline rather than a default.
- Account and access management Controls 5-6 - Who can reach what
- Who can read training data, launch a fine-tune and change production inference, reviewed against the team you have now rather than the one that set the estate up.
- Vulnerability and audit logs Controls 7-8 - Find it, then see it
- The ML stack inside the vulnerability programme, which it usually is not, and logs that are useful, retained, and actually read by somebody.
- Malware, email and recovery Controls 9-11 - Defences and the way back
- The conventional defences assessed as they stand, and recovery tested rather than documented - including what restoring a model artefact actually means.
- Network infrastructure and defence Controls 12-13 - The layer nobody owns
- The segmentation and monitoring around inference infrastructure, which tends to sit between two teams and therefore belong to neither of them.
- Training and service providers Controls 14-15 - People, and who you buy from
- Awareness that reaches the people building models, and model and cloud providers managed as the service providers they are, with terms and review to match.
- Applications, response and testing Controls 16-18 - Build, react, prove
- Secure development covering ML code, an incident plan that has been exercised on an AI-specific scenario, and testing that reaches the inference path.
The estate, independently counted
From one production model to the whole estate.
-
Inventory
Controls 1 and 2 first: what the estate holds, models included.
-
Review in order
All eighteen in the framework's own sequence, scoped to your group.
-
Rank and hand over
You see the draft first. Then the gaps in build order - dated.
Why teams choose iDharma to run the review
Independent by design
We sell none of the tooling, platforms or controls we assess. Nothing we find is convenient for us.
The order is kept
Reviewed in the framework's own sequence, so the gap list arrives as a build order already.
The AI estate counted
Models, pipelines and prompt logs treated as the assets they are, which is where Control 1 breaks.
Scoped to your group
IG1, IG2 or IG3 agreed before we start, so nothing gets graded against a bar you never chose.
Four marks, struck on every report.
What you get
Concrete artefacts, each with a name and a format - you know what lands before you buy.
CIS Controls v8 review
The full review: where the estate stands against all eighteen controls in the framework's own order, scoped to the Implementation Group you chose, with each gap placed in the sequence it should be closed rather than ranked by how easy it is. Where a safeguard is genuinely arguable at your scale - and at the IG boundaries several always are - it says so instead of grading you against the wrong bar.
Asset and software inventory
Models, endpoints, notebooks and pipelines listed with owners, in the form the two controls expect rather than as a spreadsheet.
Implementation Group memo
Which group you work to and why, written down before a customer asks - because the reasoning is the part their questionnaire cannot supply.
Safeguard gap list
What is missing, placed in the framework's own sequence, so the list arrives as a plan rather than as eighteen simultaneous priorities.
Data classification map
Training corpora, retrieval indexes, evaluation sets and prompt logs classified, because a control cannot protect data nobody has categorised.
Benchmark baseline note
Where the per-technology Benchmarks apply across your serving stack, and where a default is quietly doing the job of a hardened configuration.
Policy and procedure set
The documents the controls expect, under version control and written to your operations rather than lifted from a template library.
Real numbers, upfront.
- Scope
- All 18, at your group
- Output
- A build order, not a score
- Re-review
- As the estate grows - $5,500 against your recorded inventory
Eighteen controls is eighteen controls, so the fee is flat - and nothing is charged until you approve the scope.
Request this assessment- Asset & software inventory, AI included
- All 18 controls at your chosen group
- 29 policy and procedure documents
- Gap list, in the framework’s build order
Four things a questionnaire will ask you to produce
A checklist is not evidence. Each of these is either in your hand on the day somebody asks, or it is not.
The inventory,
whole
Assets and software, models and pipelines included, each with an owner. Every control after the second is scoped from this, so a partial list shortens the review.
The group,
chosen
Which Implementation Group you work to, and the reasoning behind it. A group picked deliberately and written down beats a higher one claimed and unevidenced.
The order,
kept
Safeguards built in the sequence the framework sets, not the order they were easiest. The ordering is the contribution; discarding it discards the framework itself.
The proof,
current
Evidence that a safeguard is still operating, not a box ticked once at implementation. A checklist records an intention; measurement is what a reviewer can actually check.
Four cards, and the date on each one is part of the card.
Plain answers
Mandatory, frameworks, groups, inventory, cost. Answered straight.
Request this assessmentAre the CIS Controls mandatory?
No. They are voluntary, and there is no certification, no accredited assessor and no seal. They become an obligation the way most voluntary frameworks do - through somebody else's contract or questionnaire.
Are they a replacement for ISO 27001 or NIST CSF?
Which Implementation Group should we target?
IG1 is the floor for everybody. Beyond that it is a judgement about the attacks you actually face and the budget you actually have - and a group chosen deliberately, with the reasoning written down, beats a higher one claimed.
Why does inventory matter so much for an AI estate?
Because Controls 1 and 2 scope every control after them, and an inventory built before the AI estate existed contains none of it. Models, endpoints, notebooks, pipelines and prompt logs are assets and data, and almost none of them are on the list.
What does an iDharma CIS Controls review cover, and what comes with it?
A flat fee, stated in full on this page, with nothing charged until you approve the scope. It covers the asset and software inventory, the group memo, the gap list in build order, the data classification map and the policy suite the review writes against.
Request your CIS Controls review
Tell us what the estate runs and we come back with a scoping call inside a day.
What we need from you
Nothing you do not already have. Most of it comes out of your asset inventory and the last review, in an afternoon, and we tell you which extracts before you commit.
- The asset and software inventory as it stands today
- Which Implementation Group you believe you are in
- What the AI estate runs, models and pipelines included
- Any existing CIS assessment, however partial
- Who asked you for this, if anybody did
What happens next
- You send the five items we need.
- We call to scope it within one business day.
- Nothing is charged until you approve the scope.
Where this page gets its facts
Where the claims on this page come from, and what they are worth - stated, not assumed.
What it is drawn from
- The CIS Critical Security Controls v8, published by CIS
- The CIS Benchmarks, its per-technology companion
- Version
- CIS Controls v8
- Enforced by
- Contract only
What it means
- General information about what the Controls describe — not legal advice, and not a determination about your programme.
- Where a safeguard is genuinely arguable at your scale, and at the Implementation Group boundaries several always are, our reports say so rather than grade you against a bar you never chose.
Scope & limitation
- The framework’s totals are printed; the per-group splits are not. Eighteen controls, 153 safeguards and three Implementation Groups are CIS’s own figures. How many safeguards fall inside each group is not checked here, and an unchecked count on an indexed page is a published claim — read those from CIS, along with the v7.1 change list.
- There is no certificate, from iDharma or anyone. CIS accredits no assessors. We review in the framework’s order and write down what is missing.
Something on this page out of date?
Tell usFrom Insights
Before you commission one
How to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
What Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Startups, Meet Your AI Stack: Budget‑Friendly Tools That Scale
For early-stage founders, building an AI-powered toolkit doesn’t have to break the bank. From ideation to growth mode, here’s how startups can tap into affordable, effective AI tools to autom