Compliance / CIS Controls
CIS Critical Security Controls for MSPs
A prioritized, action-based list of 18 safeguard families — organized into Implementation Groups (IG1/IG2/IG3) by org size and risk — that tells you exactly what to do, not just what outcome to aim for.
Why this reaches an MSP, not just the client
Cyber-insurance applications and RFPs increasingly ask questions lifted almost verbatim from the CIS Controls (asset inventory, patch cadence, access management, vulnerability scanning) — an MSP that already tracks its safeguards against the framework answers those questions with evidence instead of reconstructing the mapping under deadline.
What the Nexus compliance module tracks
- A three-state posture — implemented, partial, planned — tracked per safeguard, tagged to the Implementation Group (IG1/IG2/IG3) it belongs to
- Evidence attached directly to the safeguard it satisfies, the same evidence model used across every other framework page
- Gap reporting scoped to the IG1 baseline first, so the realistic near-term bar is visible instead of buried under IG2/IG3 aspirational controls
- A QBR rollup that shows safeguard coverage in the CIS vocabulary a cyber-insurance underwriter or auditor already uses
This describes what the module tracks against CIS Controls — not a claim that Nexus or any client on it is certified or audited against it. See the compliance & QBR module for the full picture, or read the blog for more on how we think about compliance tooling.
Other frameworks
SOC 2
The audit framework a lot of your clients' own customers require them to answer for — and that requirement flows straight down to you as their MSP.
NIST CSF
A widely-adopted, vendor-neutral structure for cybersecurity posture — Identify, Protect, Detect, Respond, Recover — that shows up in RFPs, cyber-insurance questionnaires, and board conversations alike.
HIPAA
If any client handles protected health information, HIPAA's Security Rule reaches your MSP the moment you touch their systems — business associate agreement or not.
Ready to see CIS Controls posture tracked for real?
Join the design-partner cohort and we'll walk through the control mapping for your own clients.