You decide
- Whether the evidence meets your obligations
- Which open gaps to close first
- Whether you meet the standard
For teams that want a practical, prioritized baseline
The CIS Critical Security Controls are a prioritized set of safeguards that defend against the most common attacks, grouped so you start with the essentials and build from there. They're included in Complete IT and built into your Technology Posture Report, which shows each quarter which safeguards are in place.

It likely fits if you need to:
Know every device and app you have
Asset and software tracking
Device and app inventory evidence
Protect data and manage access
Access controls and data protection
Access and data protection evidence
Keep systems patched
Patching
Patch status evidence
Back up and recover
Tested backup and recovery
Recovery test records
Train staff and oversee service providers
Awareness training and provider reviews
Training and provider review records
Built into your Technology Posture Report, with every check mapped to CIS Controls, delivered every quarter without asking. The proof in your hands is never more than three months old.
Sample · Technology Posture Report
ACME Corp · Quarter 3 · Mapped to CIS Controls
Sample report for a fictional business. Example figures.

One question to ask yourself
In 30 minutes, we talk through your setup and you leave knowing which plan fits.
Book a callSee exactly what you'd receive each quarter, by email.
Get the sample Posture Report by email