Who uses CIS benchmarks?
More context
The reason adoption clusters in regulated sectors is that those organizations must not only be secure but be able to prove it to an external party. A publicly documented, community-vetted baseline gives them a neutral reference that an auditor already recognizes, so debates shift from whether a setting is reasonable to whether the system meets an agreed standard. That shared vocabulary is far more valuable than a hardening guide each company invents on its own.
The benchmarks also gain reach indirectly through the frameworks that point at them. When a national standard or a sector regulation expects secure configuration, it often leans on CIS content as the concrete implementation detail behind an otherwise abstract control. As a result many organizations end up following the benchmarks because the framework they answer to assumes them, even when they never set out to adopt CIS content deliberately.