Cybersecurity has moved from being a technical issue to a management responsibility. Many companies are therefore quickly encountering concepts such as CIS 18 and NIS2 – but what is the difference between them, and how do they relate to each other in practice?
This guide provides you with a clear overview, without buzzwords, and shows you how to work with both in a structured way.
What is CIS 18?
CIS 18 is an internationally recognized cybersecurity framework developed by the Center for Internet Security.
The framework consists of 18 specific security controls that together cover the most common and critical cyber risks.
CIS 18 focuses on action:
- What controls should be in place?
- How do we reduce risk in practice?
- How do we work systematically with safety in everyday life?
The framework is widely used by SMEs, larger companies, and cyber insurance companies as a benchmark for an "acceptable" level of security.
Read more about CIS 18 here:
https://securefirst.dk/cis18-compliance/
What is NIS2?
NIS2 is an EU directive adopted by the European Union that sets out mandatory cybersecurity requirements for selected companies and organizations.
NIS2 primarily concerns:
- Management responsibility and governance
- Risk management
- Documentation and reporting
- Handling and reporting of security incidents
Where CIS 18 describes how to work with security, NIS2 focuses on responsibilities, requirements, and consequences.
Read more about NIS2 here:
https://securefirst.dk/nis2-compliance/
CIS 18 vs. NIS2 – the brief difference
CIS 18 and NIS2 are not alternatives. They complement each other.
- CIS 18 is a practical framework
- NIS2 is legislation
- CIS 18 helps you do the right thing
- NIS2 requires that you can document this.
A good rule of thumb:
CIS 18 shows the way – NIS2 requires you to follow it.
How do CIS 18 and NIS2 relate to each other in practice?
Many of NIS2's requirements can be directly supported by CIS 18 controls, e.g.:
- Risk Management → CIS 18: Risk Management
- Awareness and training → CIS 18 control 14
- Incident Management → Incident Response
- Access Control → Identity & Access Management
This means that companies that already work in a structured manner in accordance with CIS 18 are often significantly stronger in terms of NIS2 compliance.
SecureFirst brings this together in one solution via:
- Awareness training: https://securefirst.dk/awareness-traening/
- Phishing simulation: https://securefirst.dk/phishing-simulation/
- Monitoring of data breaches: https://securefirst.dk/monitorering-af-databrud/
Common mistakes companies make
A classic mistake is to focus solely on NIS2 because it is mandatory – without having an operational foundation.
The result is often:
- Policies without practice
- Documentation without real security
- Stress leading up to audits and insurance checks
CIS 18 provides the structure that makes NIS2 manageable.
How SecureFirst helps
SecureFirst is built for precisely this reality:
- A single overview of compliance
- Training and phishing tests that can be documented
- Ongoing monitoring of risks
- Clear reporting to management, board of directors, and insurance companies
See how it works in practice:
https://securefirst.dk/
Calculate price and level:
https://securefirst.dk/prisberegner/
FAQ – frequently asked questions
Is CIS 18 mandatory?
No. CIS 18 is a voluntary framework, but is often used as best practice and a reference by both authorities and cyber insurance companies.
Is NIS2 relevant for all companies?
No. NIS2 applies to selected sectors and company sizes, but many SMEs are indirectly affected via customers, suppliers, or insurance requirements.
Can you be NIS2 compliant without CIS 18?
Yes, in theory. In practice, CIS 18 is one of the most effective ways to ensure that NIS2 requirements are also complied with operationally.
Where do you start if you are unsure?
Start with overview and awareness. Most breakages are caused by human error – not technology alone.





