January 6, 2026

CIS 18 vs. NIS2 – what is the difference, and what does it mean for your business?

Cybersecurity has evolved from a technical issue to a management responsibility, which is why many companies are quickly coming into contact with CIS 18 and NIS 2. CIS 18 is a practical framework with specific…

Cybersecurity has moved from being a technical issue to a management responsibility. Many companies are therefore quickly encountering concepts such as CIS 18 and NIS2 – but what is the difference between them, and how do they relate to each other in practice?

This guide provides you with a clear overview, without buzzwords, and shows you how to work with both in a structured way.

What is CIS 18?

CIS 18 is an internationally recognized cybersecurity framework developed by the Center for Internet Security.
The framework consists of 18 specific security controls that together cover the most common and critical cyber risks.

CIS 18 focuses on action:

  • What controls should be in place?
  • How do we reduce risk in practice?
  • How do we work systematically with safety in everyday life?

The framework is widely used by SMEs, larger companies, and cyber insurance companies as a benchmark for an "acceptable" level of security.

Read more about CIS 18 here:
https://securefirst.dk/cis18-compliance/

What is NIS2?

NIS2 is an EU directive adopted by the European Union that sets out mandatory cybersecurity requirements for selected companies and organizations.

NIS2 primarily concerns:

  • Management responsibility and governance
  • Risk management
  • Documentation and reporting
  • Handling and reporting of security incidents

Where CIS 18 describes how to work with security, NIS2 focuses on responsibilities, requirements, and consequences.

Read more about NIS2 here:
https://securefirst.dk/nis2-compliance/

CIS 18 vs. NIS2 – the brief difference

CIS 18 and NIS2 are not alternatives. They complement each other.

  • CIS 18 is a practical framework
  • NIS2 is legislation
  • CIS 18 helps you do the right thing
  • NIS2 requires that you can document this.

A good rule of thumb:

CIS 18 shows the way – NIS2 requires you to follow it.

How do CIS 18 and NIS2 relate to each other in practice?

Many of NIS2's requirements can be directly supported by CIS 18 controls, e.g.:

  • Risk Management → CIS 18: Risk Management
  • Awareness and training → CIS 18 control 14
  • Incident Management → Incident Response
  • Access Control → Identity & Access Management

This means that companies that already work in a structured manner in accordance with CIS 18 are often significantly stronger in terms of NIS2 compliance.

SecureFirst brings this together in one solution via:

Common mistakes companies make

A classic mistake is to focus solely on NIS2 because it is mandatory – without having an operational foundation.

The result is often:

  • Policies without practice
  • Documentation without real security
  • Stress leading up to audits and insurance checks

CIS 18 provides the structure that makes NIS2 manageable.

How SecureFirst helps

SecureFirst is built for precisely this reality:

  • A single overview of compliance
  • Training and phishing tests that can be documented
  • Ongoing monitoring of risks
  • Clear reporting to management, board of directors, and insurance companies

See how it works in practice:
https://securefirst.dk/
Calculate price and level:
https://securefirst.dk/prisberegner/

FAQ – frequently asked questions

Is CIS 18 mandatory?

No. CIS 18 is a voluntary framework, but is often used as best practice and a reference by both authorities and cyber insurance companies.

Is NIS2 relevant for all companies?

No. NIS2 applies to selected sectors and company sizes, but many SMEs are indirectly affected via customers, suppliers, or insurance requirements.

Can you be NIS2 compliant without CIS 18?

Yes, in theory. In practice, CIS 18 is one of the most effective ways to ensure that NIS2 requirements are also complied with operationally.

Where do you start if you are unsure?

Start with overview and awareness. Most breakages are caused by human error – not technology alone.

https://securefirst.dk/awareness-traening/

Dion Grydell

Introductory Meeting – SecureFirst

Questions?

Should you have any questions, please do not hesitate to contact us by phone or email.  

What is ransomware, and why do companies choose to pay millions to cybercriminals?

What is ransomware, and why do companies choose to pay millions to cybercriminals?

Ransomware has become one of the most serious cyber threats facing modern businesses. These attacks are no longer just about locking files; they increasingly involve extortion, data theft, and threats to a company’s operations and reputation. When the consequences become severe enough, even well-protected organizations may find themselves in a situation where paying a ransom becomes a real consideration.

But why does this happen, and what can companies do to reduce the risk?

How phishing training works

How phishing training works

Phishing remains one of the most common ways for cybercriminals to gain access to businesses. Even though spam filters, firewalls, and security systems are getting better, fake...