Skip to content
  • There are no suggestions because the search field is empty.

Control Template Library

Overview

This page lists every control template available for Security Profile. For each one, it shows the framework or standard the template is based on. There are two kinds of templates:

  • UpGuard-preset templates, crafted by UpGuard to evaluate against a specific scope. These are informed by industry-standard frameworks but not directly aligned with any particular one.
  • Framework-aligned templates, map to a specific framework and use UpGuard’s library of 1000+ checks to allow you to evaluate a vendor against that specific external standard.

💡All templates below are available on all accounts, but some templates need to be enabled before you see them in Security Profile. To enable a template: Settings > Control Templates > toggle on the appropriate template. 

UpGuard-preset templates

UpGuard’s preset templates are designed to help you right-size your vendor assessments based on vendor tier and type. These templates have been designed by our experts, with industry standards as their foundation and layered with current best practice security controls. 

Template name Description

UpGuard Elevated

Tier 1 default template

For your highest-risk, Tier 1 vendors handling privileged data. A full-scope view of security posture that covers and exceeds ISO 27001 and NIST CSF.

UpGuard Core

Tier 2 default template

For significant, Tier 2 vendors handling confidential data. A well-rounded view of security posture, informed by ISO 27001 and NIST CSF.

UpGuard Lite

Tier 3 default template

For low-risk, Tier 3 vendors handling only public data. Verifies basic security hygiene through high-level policies and practices.

UpGuard Attack Surface

Un-tiered default template

For negligible-risk, Tier 4 or 5 vendors with no material business impact. Automated scanning only, no questionnaire.

UpGuard Cloud Service Provider

For cloud service providers (SaaS, multi-tenant platforms, and IaaS) handling your data. A cloud-focused view of security posture, built on the CSA Cloud Controls Matrix with added depth on tenant isolation, encryption, and sub-processor risk.

UpGuard Cloud Service Provider Lite

For lower-criticality cloud providers handling non-critical data. Confirms the fundamental cloud controls are in place, without the full Cloud Service Provider template's depth.

UpGuard Core Infrastructure

For infrastructure providers your systems run on — data centers, colocation, carriers, and DNS/CDN. Focuses on availability, physical, and network integrity. Use Cloud Service Provider for IaaS vendors.

Framework-based templates

Framework-based templates use UpGuard’s check library to evaluate vendors against specific external standards. Please note, these templates exist to help you assess vendors, they don't guarantee a vendor has achieved compliance.


Framework Framework description Templates available

CIS Controls v8.1 

Prioritized, maturity-tiered safeguards from the Center for Internet Security. Implementation Group 1 (IG1) covers essential cyber hygiene, IG2 builds on IG1 for organizations handling more sensitive data, and IG3 adds controls for organizations facing advanced threats.

  • IG1 (basic hygiene)
  • IG2 (more sensitive data)
  • IG3 (advanced threats)
CSA Cloud Controls Matrix (CCM) v4.1.0 A cloud-specific framework from the Cloud Security Alliance, covering 197 control specifications across 17 domains. 

  • CCM v4.1.0 (all 17 CCM domains)
  • CCM v4.1.0 (Lite) (key subset of domains, for lower-criticality cloud providers)
ISO 27001:2022  International standard for building and operating an Information Security Management System (ISMS). Commonly required of vendors that need to demonstrate a certified security program.
  • ISO 27001:2022
NIST CSF 2.0 A US framework organized around five functions: Identify, Protect, Detect, Respond, and Recover. It defines outcomes rather than prescriptive controls.

  • NIST CSF 2.0
NIST SP 800-53 Rev. 5  A US federal-agency-oriented catalogue of security and privacy controls, organized into 20 control families. UpGuard maps to the Low, Moderate, and High baseline variants only — not the full control catalogue.
  • Low
  • Moderate
  • High
UK Cyber Essentials
Requirements for IT Infrastructure v3.3
UK NCSC-backed baseline covering five technical controls: firewalls, secure configuration, user access control, malware protection, and patch management. 
  • UK Cyber Essentials