Skip to main content
← All answers
Fundamentals

How many CIS benchmarks exist?

More context

The catalog is broad because secure configuration is technology-specific: the settings that harden a Windows Server bear no resemblance to those that harden a Kubernetes cluster or a PostgreSQL instance. Each benchmark is a self-contained document for one technology and often one major version of it, which is why the count runs into the hundreds rather than being a single universal checklist that could never fit such different systems.

That version specificity has a practical consequence: the catalog is a moving target. When a vendor ships a new major release, the corresponding benchmark eventually updates to match, and new categories of technology attract entirely new benchmarks over time. An organization tracking its estate against CIS content therefore has to keep the benchmark versions it scans against current, not treat the mapping as a fixed decision made once.

Related questions

Executive Briefing

More questions on Fundamentals?

Our compliance engineers can show you exactly how CISGuard handles Fundamentals in a briefing scoped to your environment.