ISO 27001:2022 vs CIS Controls v8
What is the difference between ISO 27001:2022 and CIS Controls v8?
ISO 27001:2022 is a information security framework applying in International, with 56 controls across 5 domains. CIS Controls v8 is a other framework applying in International, with 153 controls across 18 domains. They govern different subjects, so the overlap is limited to the governance requirements they share. The mapping below shows where that is.
Measured coverage between these frameworks
We map controls between these two frameworks in a knowledge graph and have a person review every mapping before it is published. Below is what that review found. The figures are read live from the graph, not written by hand.
CIS Controls v8 into ISO 27001:2022
50.5%47 of 93 ISO 27001:2022 controls carry evidence from CIS Controls v8, leaving 46 to satisfy separately.
208 candidate mappings were examined and 68 were rejected on review, signed off 2026-08-19.
Read the full crosswalk, including every rejected mapping →ISO 27001:2022 into CIS Controls v8
66.7%102 of 153 CIS Controls v8 controls carry evidence from ISO 27001:2022, leaving 51 to satisfy separately.
382 candidate mappings were examined and 240 were rejected on review, signed off 2026-08-19.
Read the full crosswalk, including every rejected mapping →Coverage is directional. Mapping A into B is a different measurement from B into A, because the two standards do not carry the same depth on the same subjects.
Questions people ask about ISO 27001:2022 and CIS Controls v8
What is the difference between ISO 27001:2022 and CIS Controls v8?
Do I need both ISO 27001:2022 and CIS Controls v8?
How do ISO 27001:2022 and CIS Controls v8 controls map to each other?
Which framework should I implement first, ISO 27001:2022 or CIS Controls v8?
Each framework on its own
See all control mappings with interactive gap analysis
Explore the complete mapping between ISO 27001:2022 and CIS Controls v8 on our compliance platform.