New CIS Benchmark aids organizations in safely linking AI assistants and agents to data, applications, and online services
The Center for Internet Security, Inc. (CIS®) has unveiled the CIS MCP Server Benchmark v1.0.0 today. This consensus-driven set of guidelines is designed for the secure configuration of Model Context Protocol (MCP) servers, which facilitate the connection of AI assistants and agents to data, applications, and other digital tools.
With the growing deployment of AI-powered assistants and agents across organizations, securing the systems that manage these connections has become increasingly critical. The CIS MCP Server Benchmark offers a vendor-neutral framework to help protect sensitive data, manage access to resources, and mitigate security risks.
Created in alignment with the current MCP specification, the Benchmark covers both local and remote MCP setups, including gateway and proxy technologies that are frequently used to secure and manage the links between AI systems and external resources.
CIS Benchmarks are globally acknowledged, consensus-developed best practices for the secure configuration of technologies and systems. The CIS MCP Server Benchmark includes 55 prescriptive recommendations spanning 10 security domains:
1. Governance and Versioning
2. Transport and Connectivity
3. Authentication and Authorization
4. Client (Host) Configuration
5. Server Configuration
6. Data Protection and Privacy
7. Observability and Audit
8. Supply Chain Security
9. Isolation and Execution Safety
10. Resource Limits and Caching
Every recommendation comes with a rationale, audit procedure, and remediation steps to aid in implementation and evaluation.
“As organizations continue to adopt AI agents, securing the systems that connect them to enterprise resources is essential,” stated Erin Haggerty, Director of the Cloud Team at CIS. “The CIS MCP Server Benchmark provides clear, actionable guidance to help organizations deploy MCP securely and reduce risk.”
MCP is increasingly utilized to link AI systems with databases, file systems, cloud services, browsers, and other business resources. Since MCP servers often have access to sensitive systems and data, misconfigurations can lead to unauthorized access, data exposure, tool manipulation, and the execution of untrusted code.
The CIS MCP Server Benchmark offers specific, testable recommendations that organizations can use to assess, audit, and enhance the security of their MCP server deployments. The CIS MCP Server Benchmark v1.0.0 is available for free download.
For more information, to download the Benchmark, or to get involved in future Benchmark development, visit CISecurity.org/Benchmarks.
###
About CIS:
The Center for Internet Security, Inc. (CIS®) works to make the connected world a safer place for individuals, businesses, and governments through collaboration and innovation. As a community-driven nonprofit, CIS is responsible for the CIS Critical Security Controls® and CIS Benchmarks®, globally recognized best practices for securing IT systems and data. We lead a global community of IT professionals to continually evolve these standards and provide products and services to safeguard against emerging threats. Our CIS Hardened Images® offer secure, on-demand, scalable computing environments in the cloud. CIS is also home to the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), a trusted resource for cyber threat prevention, protection, response, and recovery for U.S. State, Local, Tribal, and Territorial governments, and the Elections Infrastructure Information Sharing and Analysis Center® (EI-ISAC®), which addresses the evolving cybersecurity needs of U.S. election offices. To learn more, visit or follow us on X: @CISecurity.
Kelly Wyland
Center for Internet Security
email us here
Visit us on social media:
LinkedIn
Instagram
Facebook
YouTube
X





