Compliance (CIS)
CIS Critical Security Controls v8 alignment scored from your Atlas assessment.
Where it lives
Sidebar → Compliance (/compliance)
This page is CIS CSC v8, not a specific commercial framework. For SOC 2 / ISO / GDPR / DPDP / ISO 9001, use the Frameworks tab.
What you see
Each CIS control group (1–18) shows an alignment bar from your Yes / Partial / No answers.
Examples of groups:
- Inventory of Enterprise Assets
- Inventory of Software Assets
- Data Protection
- Continuous Vulnerability Management
- Service Provider Management
- Incident Response Management
Maturity labels on this page: Initial, Developing, Defined, Advanced.
Read the heat
Low bars are the CIS groups to tackle next — they should match Roadmap Do now.
Drill into Assessment
Change answers in Assessment, submit, then return here.
Map to a framework
When you need auditor language, open the matching framework workspace. Cross-Framework shows shared tasks.
Completing a SOC 2 task does not automatically tick the CIS group. Re-submit Assessment when the underlying control is truly in place so this page and the Dashboard score stay aligned.