Skip to main content

CIS Benchmark CLI

Professional command-line tool for downloading and managing CIS security benchmarks from CIS WorkBench

PyPI version Python Version CI Code style: ruff License


What is CIS Benchmark CLI?

cis-bench downloads CIS security benchmarks from CIS WorkBench and exports them to multiple formats, including NIST XCCDF for use with SCAP compliance scanners like OpenSCAP, SCC, and Nessus.

Use Cases:

  • Discover - Search 1,300+ CIS benchmarks with platform filtering
  • Download - Fetch benchmarks with browser-based authentication
  • Convert - Export to YAML, CSV, Markdown, or NIST XCCDF
  • Comply - Generate DISA STIG-compatible XCCDF for DoD environments
  • Analyze - Extract 19 fields including CIS Controls, MITRE ATT&CK, NIST mappings

Quick Start

# 1. Install (choose one)
pipx install cis-bench    # Recommended - isolated environment, no PATH issues
uv tool install cis-bench # Alternative - fast, modern
pip install cis-bench     # Not recommended - may have PATH issues

# 2. Login (one-time)
cis-bench auth login --browser chrome

# 3. Build catalog (one-time, ~2 minutes)
cis-bench catalog refresh

# 4. Get a benchmark
cis-bench get "ubuntu 22.04" --format xccdf --style cis

# Done! You have a SCAP-compliant XCCDF file

Get Started Guide for detailed setup


Key Features

Session-Based Authentication

Login once, use everywhere. No more passing --browser on every command.

cis-bench auth login --browser chrome
cis-bench download 23598 # Uses saved session

Searchable Catalog

Fast local search of 1,300+ benchmarks with FTS5 full-text search and platform taxonomy.

cis-bench search "oracle" --platform-type cloud
cis-bench search --platform-type database --latest

Unified Get Command

Search + download + export in one step.

cis-bench get "ubuntu 22" --format xccdf --style cis

Database Caching

Downloaded benchmarks cached in SQLite for instant re-export.

cis-bench export 23598 --format xccdf # Instant (from cache)

Multiple Export Formats

  • YAML - Human-readable structured data
  • CSV - Spreadsheet import
  • Markdown - Documentation
  • JSON - Machine-readable
  • XCCDF - SCAP compliance (DISA STIG or CIS native)

Platform Filtering

Two-level taxonomy: category (cloud/os/database) + specific platform (aws/ubuntu/oracle).

cis-bench search --platform-type cloud # All cloud benchmarks
cis-bench search --platform ubuntu # All Ubuntu versions

Scriptable and Automatable

All commands support JSON output for piping to jq, scripting, CI/CD.

cis-bench search oracle --output-format json | jq -r '.[].benchmark_id'

Performance

  • Parallel catalog scraping (~2 min for 1,300+ benchmarks)
  • Retry logic with exponential backoff
  • Progress bars on long operations

Documentation

📚 Full documentation: https://mitre.github.io/cis-bench/

For Users

For Developers

Technical Reference


Example Workflows

Export AlmaLinux 10 for OpenSCAP Scanning

cis-bench auth login --browser chrome
cis-bench search "almalinux 10"
# Shows: Benchmark ID 23598

cis-bench download 23598
cis-bench export 23598 --format xccdf --style cis -o almalinux10-cis.xml

# Use with OpenSCAP
oscap xccdf eval --profile Level_1 almalinux10-cis.xml

Batch Export All Cloud Benchmarks

# Search and download all cloud benchmarks
cis-bench search --platform-type cloud --output-format json | \
jq -r '.[].benchmark_id' | \
head -5 | \
xargs -I {} cis-bench download {}

# Export all to DISA STIG format
cis-bench list --output-format json | \
jq -r '.[].file' | \
xargs -I {} cis-bench export {} --format xccdf --style disa

Create Compliance Spreadsheet

cis-bench download 24008 # Oracle Cloud Infrastructure
cis-bench export 24008 --format csv -o oci-compliance.csv

# Open in Excel/Numbers for tracking
open oci-compliance.csv

More examples in User Guide


XCCDF Export

Generate NIST XCCDF 1.2 format compatible with SCAP compliance tools:

Two Styles Available:

DISA STIG Style (For DoD/Government)

cis-bench export 23598 --format xccdf --style disa

Features:

  • XCCDF 1.1.4 (DISA standard)
  • CCI mappings (2,161 DoD Control Correlation Identifiers)
  • VulnDiscussion elements
  • STIG-compatible structure

CIS Native Style (For Full Metadata)

cis-bench export 23598 --format xccdf --style cis

Features:

  • XCCDF 1.2 (latest standard)
  • Full CIS Controls v8 metadata (318 controls)
  • MITRE ATT&CK techniques (296 mappings)
  • Enhanced namespace for custom fields

XCCDF Styles Comparison for detailed differences


Architecture

Design Principles

Config-Driven - XCCDF field mappings defined in YAML, not hard-coded Extensible - Strategy pattern for HTML changes, Factory pattern for exporters Validated - xsdata-generated models from NIST XSD schemas Tested - 1,100+ tests with 96% coverage

Component Overview

CIS WorkBench HTML
 (WorkbenchScraper + Strategy Pattern)
Pydantic Models (19 fields)
 (MappingEngine + YAML Config)
xsdata XCCDF Models
 (XML Serialization)
NIST XCCDF Output

Architecture Documentation for complete system design


Project Status

Version: 0.4.0 (Beta) Tests: 1,100+ tests with 96% coverage Python: 3.12+ License: Apache 2.0

Current Features:

  • Session-based authentication
  • Searchable catalog with 1,300+ benchmarks
  • Platform taxonomy (cloud/os/database/container/application)
  • Unified get command
  • Database caching
  • Multiple export formats
  • Batch export (multiple benchmarks at once)
  • XCCDF export (both DISA and CIS styles)
  • Parallel catalog scraping
  • Output formats for scripting (json/csv/yaml)

Future Features:

  • Offline mode
  • Benchmark comparison/diff
  • Recommendation search across benchmarks

Future Features for roadmap


Installation

From PyPI (Recommended)

Per Python Packaging Authority guidelines, CLI tools should be installed with pipx or uv tool, not pip directly.

# RECOMMENDED: pipx (isolated environment, correct PATH)
pipx install cis-bench

# ALTERNATIVE: uv tool (fast, modern)
uv tool install cis-bench

# Verify
cis-bench --version

Why not pip? pip install installs to a directory that may not be in your PATH, causing "command not found" errors. pipx and uv tool handle this correctly.

Using pip anyway? (click to expand)
pip install cis-bench

If you get cis-bench: command not found:

# Option 1: Use module syntax (always works)
python -m cis_bench --version

# Option 2: Add pip's bin to PATH
export PATH="$HOME/.local/bin:$PATH"  # Add to ~/.bashrc or ~/.zshrc

From Source

git clone https://github.com/mitre/cis-bench.git
cd cis-bench

# Install for development
pipx install -e .
# Or: uv tool install -e .

# Verify
cis-bench --version

Development Install

# Clone and install with dev dependencies
git clone https://github.com/mitre/cis-bench.git
cd cis-bench
pip install -e ".[dev]"

# Install pre-commit hooks
pre-commit install

# Run tests
pytest tests/ -v

Getting Started for detailed installation


Requirements

Runtime:

  • Python 3.12+
  • CIS WorkBench account (free registration at workbench.cisecurity.org)
  • Supported browser (Chrome, Firefox, Edge, or Safari)

Development:

  • All runtime requirements
  • pytest, ruff, bandit, pre-commit (installed via [dev] extras)

Support and Contributing

Found a bug? Open an issue at GitHub Issues

Want to contribute? See Contributing Guide

Questions? Check Documentation or open a discussion


License

Apache License 2.0 - See LICENSE for details

Acknowledgments:

  • Based on proof-of-concept by m-ghonim (Mohamed Ghoneam)
  • CIS WorkBench for providing benchmark data
  • NIST for XCCDF schema specifications
  • DISA for STIG formatting conventions

Quick Links

User Documentation:

Developer Documentation:

Need Help?

Metadata

Release files for cis-bench 0.5.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cis-bench 0.5.2
File Size Uploaded
cis_bench-0.5.2.tar.gz 182.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for cis-bench 0.5.2
File Interpreter ABI Platform
cis_bench-0.5.2-py3-none-any.whl Python 3 none any Details

Total release size: 388.6 kB

Release files / cis_bench-0.5.2.tar.gz

Download URL cis_bench-0.5.2.tar.gz
Size 182.3 kB
Tags Source
SHA-256 checksum
How to use checksums
ff8d5330fde150a1e62dcef17f18f7baa38e80b883099cba9a43f68f74488508
BLAKE2b-256 checksum
How to use checksums
c5dfaa75a8b8fd3ee351685ace796a43cc051867ac388dbf56f285cf83412df2
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 19, 2026.

Transparency log

Release files / cis_bench-0.5.2-py3-none-any.whl

Download URL cis_bench-0.5.2-py3-none-any.whl
Size 206.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
81fa79bb96d62a595291e9506f89d4e7da24e60640f4e202191024e79199eb18
BLAKE2b-256 checksum
How to use checksums
09d896b43bec7799c210ec681a8cb676cd68599bdd46a39a7f4198f3f54e0b39
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.12

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Apr 19, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.5.2 This release

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page