Compliance guide

Implement CIS Controls v8.1 in PurpleWASP

Select an Implementation Group, confirm programme scope, work through targeted Safeguards, reuse shared organisation Controls and assurance, and use Drivers / Improve Score to prioritise the next action.

Security Manager, Compliance Manager, IT Manager, Control owner or authorised contributor Ongoing cybersecurity implementation programme Updated 19 September 2026

What PurpleWASP CIS Controls v8.1 supports

PurpleWASP treats CIS Controls v8.1 as a programme and Safeguard layer over shared organisation Controls. The current catalogue contains 18 CIS Controls and 153 Safeguards. The programme selects an Implementation Group (IG1, IG2 or IG3), establishes scope and accountability, then derives Safeguard coverage and implementation from the authoritative Control Management records.

AreaPurpleWASP capability
Programme setupSelect baseline IG, whole/partial scope, owner, business context and rationale; save draft and confirm a versioned baseline.
Safeguard catalogueBrowse/search all 153 Safeguards and filter by CIS Control, target, minimum IG and derived state.
Control reuseUse PurpleWASP canonical recommendations and adopted organisation Controls without duplicating implementation state.
AssuranceSurface governance documents, Risks, evidence, assessments, tests, issues and exceptions from shared Control Management.
ImprovementUse internal Drivers / Improve Score and the operational queue to prioritise concrete next work.
IntegrityReconcile programme lifecycle, target counts, Safeguard aggregation and readiness-model consistency.

1. Confirm setup and scope

Open Setup & Scope, select the baseline Implementation Group, define whether the programme covers the whole organisation or a justified partial scope, assign an accountable user/function and record the IG rationale/business context. Save a draft first, then confirm it when the configuration is ready to become the reporting baseline.

Confirmed programmes are historical baselines. Later changes create or reuse a successor draft rather than silently rewriting the confirmed programme.

2. Select the Implementation Group

Implementation Groups are cumulative. PurpleWASP currently targets 56 Safeguards for IG1, 130 for IG2 and 153 for IG3. Choose the baseline from the organisation's actual risk, complexity, sensitive data, critical services, threat exposure and security capability rather than from a desired dashboard percentage.

Higher-IG Safeguards can be added explicitly to a lower baseline when the organisation wants a narrower extension.

3. Work through targeted Safeguards

The Safeguards page separates the full 153-Safeguard catalogue from the current programme target. Use the filters to focus on the selected IG, a particular CIS Control, a minimum IG or a derived implementation state. Open a Safeguard workspace when you need to understand why a status was derived and which organisation Controls support it.

4. Keep Control coverage separate from implementation

Coverage required means the Safeguard is in target but PurpleWASP does not yet have effective applicable organisation-Control coverage. It is intentionally different from Not implemented, which means coverage exists and the authoritative Control state indicates the requirement is not operating.

Unknown/uncovered is not the same as failed. This distinction prevents an organisation with incomplete mapping from being reported as if every unmapped Safeguard had already been assessed and failed.

5. Use the Safeguard workspace

The workspace shows the framework-specific target/applicability decision, PurpleWASP canonical Control recommendations and any adopted organisation Controls currently providing coverage. The assurance tabs then reuse the shared records for Policies & Documents, Risks, Evidence, Tests & Assessments, Issues & Exceptions and cross-framework relationships.

If no organisation Control is mapped, use Adopt control or Control Management's mapping workflow. Once the Control is adopted/mapped, CIS derives its state from that authoritative record rather than creating a CIS-only duplicate.

6. Use Drivers / Improve Score

The dashboard and improvement page use a PurpleWASP internal implementation-readiness model across setup/scope, Safeguard Control coverage, Control implementation, governance documents, current evidence, assessment/testing and issue/exception impact. Use the potential gain to prioritise work, then fix the underlying Control/assurance record.

Not an official CIS score. PurpleWASP Assessment Coverage, Implementation Progress and Readiness are management indicators and must not be described as CIS certification, conformance or an official CIS Controls Assessment Specification result.

7. Validate integrity and programme lifecycle

Use the Integrity page before final sign-off. It checks the current catalogue/programme state, target reconciliation, Safeguard aggregation and readiness-model consistency. It complements—not replaces—RBAC and end-to-end workflow testing.

Content and licensing boundary

PurpleWASP defaults to identifier_only CIS content mode. In that mode the UI uses identifiers such as “CIS Control 17” and “CIS Safeguard 17.3” plus PurpleWASP-authored implementation context instead of redistributing the official CIS Safeguard wording. Enable a licensed content mode only where the deployment has confirmed rights appropriate to the intended commercial use.

Use CIS as the authoritative content source. Obtain the current CIS Controls v8.1 material directly from CIS and review the applicable CIS Terms of Use before reproducing or redistributing official content.

Implementation guides

Use the first-time handbook for programme owners and implementation teams, and the technical guide for developers, administrators and implementation partners.

Download the CIS first-time implementation handbook

Download the CIS technical implementation guide

Common problems

The dashboard shows low coverage

Open the Safeguards page and filter to Coverage required. Adopt/map appropriate organisation Controls first; do not convert unknown coverage into Not implemented merely to remove the gap.

A confirmed programme changed unexpectedly

Confirmed programmes should remain immutable. Saving a programme/Safeguard decision after confirmation should create or reuse a successor draft and leave reporting on the current confirmed baseline until the draft is confirmed.

Evidence/test/issues counts look different between the summary and tabs

Confirm whether the headline is showing current/actionable records while the tab includes historical records. Use clear labels so different populations are not mistaken for a reconciliation defect.

Official CIS text appears in a commercial identifier-only deployment

Check PW_CIS_CONTENT_MODE and the deployment's licensed-content configuration before exposing or distributing official/derivative CIS content.