Control Template Library
Overview
This page lists every control template available for Security Profile. For each one, it shows the framework or standard the template is based on. There are two kinds of templates:
- UpGuard-preset templates, crafted by UpGuard to evaluate against a specific scope. These are informed by industry-standard frameworks but not directly aligned with any particular one.
- Framework-aligned templates, map to a specific framework and use UpGuard’s library of 1000+ checks to allow you to evaluate a vendor against that specific external standard.
💡All templates below are available on all accounts, but some templates need to be enabled before you see them in Security Profile. To enable a template: Settings > Control Templates > toggle on the appropriate template.
UpGuard-preset templates
UpGuard’s preset templates are designed to help you right-size your vendor assessments based on vendor tier and type. These templates have been designed by our experts, with industry standards as their foundation and layered with current best practice security controls.
| Template name | Description |
|
UpGuard Elevated Tier 1 default template |
For your highest-risk, Tier 1 vendors handling privileged data. A full-scope view of security posture that covers and exceeds ISO 27001 and NIST CSF. |
|
UpGuard Core Tier 2 default template |
For significant, Tier 2 vendors handling confidential data. A well-rounded view of security posture, informed by ISO 27001 and NIST CSF. |
|
UpGuard Lite Tier 3 default template |
For low-risk, Tier 3 vendors handling only public data. Verifies basic security hygiene through high-level policies and practices. |
|
UpGuard Attack Surface Un-tiered default template |
For negligible-risk, Tier 4 or 5 vendors with no material business impact. Automated scanning only, no questionnaire. |
|
UpGuard Cloud Service Provider |
For cloud service providers (SaaS, multi-tenant platforms, and IaaS) handling your data. A cloud-focused view of security posture, built on the CSA Cloud Controls Matrix with added depth on tenant isolation, encryption, and sub-processor risk. |
|
UpGuard Cloud Service Provider Lite |
For lower-criticality cloud providers handling non-critical data. Confirms the fundamental cloud controls are in place, without the full Cloud Service Provider template's depth. |
|
UpGuard Core Infrastructure |
For infrastructure providers your systems run on — data centers, colocation, carriers, and DNS/CDN. Focuses on availability, physical, and network integrity. Use Cloud Service Provider for IaaS vendors. |
Framework-based templates
Framework-based templates use UpGuard’s check library to evaluate vendors against specific external standards. Please note, these templates exist to help you assess vendors, they don't guarantee a vendor has achieved compliance.
| Framework | Framework description | Templates available |
|
CIS Controls v8.1 |
Prioritized, maturity-tiered safeguards from the Center for Internet Security. Implementation Group 1 (IG1) covers essential cyber hygiene, IG2 builds on IG1 for organizations handling more sensitive data, and IG3 adds controls for organizations facing advanced threats. |
|
| CSA Cloud Controls Matrix (CCM) v4.1.0 | A cloud-specific framework from the Cloud Security Alliance, covering 197 control specifications across 17 domains. |
|
| ISO 27001:2022 | International standard for building and operating an Information Security Management System (ISMS). Commonly required of vendors that need to demonstrate a certified security program. |
|
| NIST CSF 2.0 | A US framework organized around five functions: Identify, Protect, Detect, Respond, and Recover. It defines outcomes rather than prescriptive controls. |
|
| NIST SP 800-53 Rev. 5 | A US federal-agency-oriented catalogue of security and privacy controls, organized into 20 control families. UpGuard maps to the Low, Moderate, and High baseline variants only — not the full control catalogue. |
|
| UK Cyber Essentials Requirements for IT Infrastructure v3.3 |
UK NCSC-backed baseline covering five technical controls: firewalls, secure configuration, user access control, malware protection, and patch management. |
|