Skip to main content
Audience: MSP staff with Playbooks management permission and active billing. Read access lets you inspect the catalog; import permission is separate.

Find the product and version

Open Settings > Compliance > Playbooks > Security Frameworks > CIS Benchmarks. Search for the product family, or browse the operating-system, cloud, infrastructure and browser sections. Review the displayed version and available variants. A family may offer L1, L2 or a Full entry; use the entries actually shown.
MSP example: one product family with separate L1 and L2 entries. Imported indicates an existing copy, not a completed assessment.

MSP example: one product family with separate L1 and L2 entries. Imported indicates an existing copy, not a completed assessment.

L1 and L2 are CIS Benchmark configuration profiles. They are not Implementation Groups IG1 and IG2. Level 1 aims for a usable baseline; Level 2 adds stricter security requirements with potentially greater operational impact. Review the applicable benchmark and test configuration changes before rollout. See the CIS Benchmarks FAQ and CIS Controls Implementation Groups.

Review the selected checks

Use the eye control beside the intended variant to inspect details and the check list. Review its product, profile and version before selecting it. Do not assume an L2 catalog entry contains every L1 check: inspect the actual lists when deciding which variants you need. Close details after review. The details Copy action performs an immediate copy; use Add on the variant if you need the import-mapping dialog.

Import with the correct mapping

  1. Click Add for one variant, or select the intended variants and choose Add to Tenant in the header.
  2. Review every Folder destination in Add Playbooks to Tenant.
  3. Choose a Status list for each selected playbook.
  4. For Device checks, inspect the suggested Device types. Selected types receive the imported group association; remove types you do not intend to target.
  5. Review the duplicate warning if a variant is already imported. Importing again creates another copy rather than updating the previous one.
  6. Click Add to Tenant to import. Wait for the result, then inspect the destination folder under Settings > Compliance > Checks and its new group under Groups.
Do not repeat a multi-variant import solely because the final operation failed. Some earlier variants may already have been copied; inspect the library first.

Prepare an assessment

Review the imported checks, guidance and status list. Configure the applicable groups, runs and company/device scope through Compliance settings. Import does not harden an operating system or mark a company compliant. Keep a record of the chosen benchmark version. Compare future catalog changes with your tenant copies; a new import does not silently merge into existing customized checks.

Troubleshooting

If the product is absent, clear the search and inspect the current catalog; do not substitute a different product/version merely because its name is similar. If Add is unavailable, check management permission and billing. If no status list is selected, choose one before submitting. If imported checks are missing from an assessment, inspect the folder/group and the assessment assignment separately.

FAQs

No. L1/L2 are CIS Benchmark profiles; IG1/IG2/IG3 organize CIS Controls implementation priorities.
Do not assume that. Review the check lists for the actual variants you plan to import.
No. It imports check content and group associations; assessment and endpoint configuration are separate work.
A repeated import can create another group and check copies. Review existing content before importing again.
Selected device types receive the imported check-group association. Review suggested selections before submitting.
Inspect the displayed folder in Settings > Compliance > Checks and the imported group in Groups, then configure the intended assessment.