CIS Controls Compliance

The CIS Controls Foundation, Continuously Maintained

Lansweeper gives IT and security a shared view of every asset, so Controls 1 and 2 are met with evidence, coverage gaps are closed before they accumulate, and every downstream control builds on data you can trust.

Trusted by 30,000+ environments to provide confident IT and security decisions.

  • Customer-Logo-_Cambridge-University
  • Customer-Logo_Warner-Music-Group
  • Customer-Logo_Red-Bull
  • Customer-Logo_Nvidea
  • Customer-Logo_Maersk
  • Customer-Logo_Lockheed-Martin
  • Customer-Logo_Hilton
  • Customer-Logo_Fujifilm
  • Customer-Logo_EA-Games
  • Customer-Logo_Caltech
  • Customer-Logo_American-Airlines
  • CIS Controls Fail When the Asset Inventory Does
    Most organizations have the framework. Few have the asset foundation required to make it work.
    Which hardware assets are connected to our environment?
    Where is unauthorized or unsupported software running?
    How confident are we that security controls actually reach every device?
    What would a CIS assessor find in our environment that we haven't already?
    The result?
    Controls 1 and 2 that can't be demonstrated, and downstream controls built on incomplete data.
    One Trusted Source of Asset Intelligence for CIS Compliance
    Get a complete foundation for CIS Controls compliance, starting with the hardware and software inventory that every other control depends on.
    Every connected device discovered automatically.
    All installed software detected, tracked by version and publisher, and flagged when unauthorized.
    Configuration states, patch status, and access controls validated against CIS Benchmarks.
    Audit-ready documentation generated from current asset records.
    The payoff?
    Controls 1 and 2 fully evidenced, and an asset foundation that makes every downstream security effort more reliable.

    Benefits

    A CIS Controls Foundation That Compounds

    When your asset inventory is complete from day one, every CIS control built on top of it becomes more reliable, and stays that way as environments change.

    Assessment Confidence Before the Audit Arrives

    When Controls 1 and 2 are continuously maintained — not manually assembled — your team enters every review with evidence already current, and no gaps to explain.

    Downstream Controls That Actually Work

    Controls 3 through 16 inherit whatever accuracy Controls 1 and 2 provide. Validated hardware and software inventory means vulnerability management, secure config, and access control efforts all act on accurate data.

    One Foundation Across the Full Framework

    The asset intelligence that satisfies Controls 1 and 2 is the same foundation that supports additional controls. Coverage compounds without adding tools.

    IT Asset Details

    CIS® CONTROL #1

    Every Connected Device, Known and Authorized

    Inventory & Control of Enterprise Assets

    Discover everything, automatically. Lansweeper automatically discovers every connected device — across IT, OT, IoT, and cloud — using unmatched network discovery. From switches and laptops to rogue devices and shadow IT, you get complete visibility to close CIS Controls compliance gaps and reduce exposure.

    Software Asset Inventory

    CIS® CONTROL #2

    Every Software Title Tracked, Governed, and Flagged

    Inventory & Control of Software Assets

    Lansweeper detects all installed software across every discovered device, tracks versions, publishers, and usage, and flags unauthorized or unsupported applications. Whitelisting and BI features support policy enforcement and software governance.

    Success Story

    Real-World Results: Herman Miller

    Herman Miller used Lansweeper to gain the complete asset visibility required to meet CIS Controls 1 and 2—eliminating blind spots across their IT estate. By automatically discovering and managing both hardware and software, they strengthened their security posture and simplified audit prep.

     

    Supporting More CIS Controls, Smarter

    • CIS.png

      Data Protection

      CIS Control #3: Track encryption and secure sensitive data.

      Track encryption status and secure sensitive data across your endpoints. Enforce encryption policies and reduce the risk of data loss or theft.

    • CIS.png

      Secure Configurations

      CIS Control #4: Eliminate misconfigurations at scale.

      Audit and standardize configurations with built-in checks for firewalls, services, registry settings, and more—aligned with CIS Benchmarks.

    • CIS.png

      Account Management

      CIS Control #5: Audit your accounts instantly.

      Scan AD, O365, and Exchange to uncover orphaned users, weak policies, and unauthorized privileges—enabling secure, compliant access control.

    • CIS.png

      Access Control Management

      CIS Control #6: Implement SSO, MFA, and role-based controls.

      Support SSO and MFA, define asset scopes, and enforce granular access policies to minimize internal risk.

    • CIS.png

      Vulnerability Management

      CIS Control #7: Stay ahead of threats.

      Surface real-time threats from VulnCheck, CISA, and MSRC. Prioritize by exploitability and remediate faster using actionable risk insights.

    • CIS.png

      Audit Log Management

      CIS Control #8: Collect, centralize, and review your logs.

      Collect and correlate event logs across devices. Monitor login patterns, detect anomalies, and support security investigations and reporting.

    • CIS.png

      Email and Web Browser Protections

      CIS Control #9: Identify outdated clients before they become a risk.

      Track browser and email client versions across your network to ensure only secure, supported applications are in use.

    • CIS.png

      Malware Defenses

      CIS Control #10: Validate protection across all endpoints.

      Verify antivirus presence, status, and updates. Scan endpoints for malware indicators and enforce protection policies across all devices.

    • CIS.png

      Network Infrastructure Management

      CIS Control #12: Stay current, stay secure.

      Identify and retire outdated network hardware. Monitor lifecycle and firmware status to support upgrades and reduce downtime risk.

    • CIS.png

      Network Monitoring and Defense

      CIS Control #13: Proactively detect threats.

      Detect suspicious activity through event log insights. Lansweeper supports alerting and enriches SIEM/SOAR workflows with asset context.

    • CIS.png

      Application Software Security

      CIS Control #16: Prioritize software vulnerabilities.

      Prioritize software vulnerabilities by real-world risk. View severity, affected devices, and patch status in one place to streamline triage.

    How it works

    Built for IT and Security Teams

    Discover every asset, understand what’s at risk, and push trusted data to the tools that take action.

    network discovery hero default dark 02
    insights hero default dark 02
    orchestration hero default dark 02.1
    • See what’s actually there

      Continuously discover and classify every asset across IT, OT, cloud, and IoT — managed, unmanaged, and shadow — without manual effort.

    • Know what matters most

      Normalize and apply context, vulnerability data, and lifecycle signals to assess risk, forecast spend, and surface optimization opportunities.

    • Act with confidence across tools

      Deliver trusted asset intelligence to ITSM, CMDB, and security tools so actions are accurate, scoped, and prioritized.

    INTEGRATIONS

    Turn Asset Intelligence Into Action Across Your Stack

    Lansweeper feeds trusted, continuously updated asset intelligence into the tools that take action.

    Ready to get started?

    Explore the full platform, free for 14 days.
    No credit card required.

    Need help evaluating?
    Get guidance on pricing at scale and enterprise requirements.
    Talk to sales
    Clear pricing as you grow
    Transparent plans that scale with your environment.
    View plans & pricing
    • What are CIS Controls and why are they important?

      The CIS Critical Security Controls are a prioritized set of cybersecurity best practices designed to help organizations reduce risk and improve security posture in a structured, measurable way. The framework starts with the premise that you cannot protect what you don’t know you have — making complete, continuously validated hardware and software inventory the foundation everything else depends on. Organizations that can’t demonstrate Controls 1 and 2 typically have gaps across every downstream control as well.

    • Which CIS Controls are supported by Lansweeper?

      Lansweeper directly supports implementation of Controls 1 and 2 — hardware and software asset inventory — and contributes to 11+ additional controls including data protection (3), secure configurations (4), account management (5), vulnerability management (7), and network monitoring (13). The platform delivers the asset visibility, configuration data, and automation required to meet control requirements and generate audit-ready evidence.

    • How does Lansweeper support CIS Control 1 and 2?

      CIS Control 1 requires a complete, continuously maintained inventory of all authorized hardware. CIS Control 2 requires the same for software. Lansweeper automatically discovers every connected device and detects all installed software across IT, OT, cloud, and IoT environments, eliminating the manual effort and inventory gaps that cause Controls 1 and 2 failures. Discovery is continuous, not periodic, so the inventory reflects the current state of the environment at any point.

    • How does Lansweeper help prepare for a CIS assessment?

      CIS assessments start with Controls 1 and 2: if the asset inventory is incomplete, every downstream control is suspect. Lansweeper provides a continuously validated hardware and software inventory with configuration states, patch status, and access records maintained in one place. When an assessment begins, evidence for Controls 1 and 2 is already current, and supporting data for downstream controls is available on demand.