Compliance / CIS Controls

CIS Critical Security Controls for MSPs

A prioritized, action-based list of 18 safeguard families — organized into Implementation Groups (IG1/IG2/IG3) by org size and risk — that tells you exactly what to do, not just what outcome to aim for.

Why this reaches an MSP, not just the client

Cyber-insurance applications and RFPs increasingly ask questions lifted almost verbatim from the CIS Controls (asset inventory, patch cadence, access management, vulnerability scanning) — an MSP that already tracks its safeguards against the framework answers those questions with evidence instead of reconstructing the mapping under deadline.

What the Nexus compliance module tracks

  • A three-state posture — implemented, partial, planned — tracked per safeguard, tagged to the Implementation Group (IG1/IG2/IG3) it belongs to
  • Evidence attached directly to the safeguard it satisfies, the same evidence model used across every other framework page
  • Gap reporting scoped to the IG1 baseline first, so the realistic near-term bar is visible instead of buried under IG2/IG3 aspirational controls
  • A QBR rollup that shows safeguard coverage in the CIS vocabulary a cyber-insurance underwriter or auditor already uses

This describes what the module tracks against CIS Controls — not a claim that Nexus or any client on it is certified or audited against it. See the compliance & QBR module for the full picture, or read the blog for more on how we think about compliance tooling.

Ready to see CIS Controls posture tracked for real?

Join the design-partner cohort and we'll walk through the control mapping for your own clients.