Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

CIS Controls implementation explained

CIS Controls Implementation: The Essential 6-Step IG1 Plan (2026)

CIS Controls implementation starts with a decision CIS makes for you: every enterprise should start with Implementation Group 1. IG1 is 56 of the 153 Safeguards in CIS Controls v8.1, drawn from 15 of the 18 Controls — Controls 13 Network Monitoring and Defense, 16 Application Software Security and 18 Penetration Testing have no IG1 Safeguards at all — and CIS defines it as essential cyber hygiene, the foundational defences against the most common attacks.

The Controls are ordered, so the plan is largely written already: inventory first, because nothing downstream can be secured if it is unknown; data, configuration, accounts and access next; vulnerability management, logging, malware and recovery after that; awareness, service providers and incident response last, running alongside. This guide sets out a six-step CIS Controls implementation plan for IG1, with the Safeguards in each step, the documents and tooling each needs, a realistic timeline for a small or mid-size organisation, the point at which IG2 starts, and the errors that stall the programme.

CIS Controls implementation: the six-step IG1 plan
1 Assess and scope (CSAT, boundary, owners) · 2 Know what you have (Controls 1, 2, 5.1, 15.1) · 3 Protect the foundation (3, 4, 5, 6) · 4 Keep it patched, logged, clean and recoverable (7, 8, 9, 10, 11, 12) · 5 People and response (14, 17) · 6 Measure and move to IG2 — 3–6 months for 56 Safeguards.

Before the six steps: what IG1 contains

Control IG1 Safeguards What they require
1 Enterprise assets 1.1, 1.2 Detailed inventory reviewed bi-annually; process for unauthorised assets weekly
2 Software assets 2.1, 2.2, 2.3 Software inventory reviewed bi-annually; only supported software authorised, reviewed monthly; unauthorised software removed or excepted monthly
3 Data protection 3.1–3.6 Data management process; data inventory; access control lists; retention with minimum and maximum; secure disposal; encryption on end-user devices
4 Secure configuration 4.1–4.7 Secure configuration processes for assets and network devices; session lock (15 min / 2 min mobile); firewalls on servers and end-user devices; secure management protocols; default accounts managed
5 Account management 5.1–5.4 Account inventory; unique passwords; dormant accounts disabled after 45 days; administrator privileges on dedicated accounts
6 Access control 6.1–6.5 Access granting and revoking processes; MFA for externally exposed applications, remote network access and administrative access
7 Vulnerability management 7.1–7.4 Vulnerability management and remediation processes; automated OS and application patching monthly or more often
8 Audit logs 8.1–8.3 Log management process; logs collected; adequate storage
9 Email and browser 9.1, 9.2 Only supported browsers and email clients; DNS filtering
10 Malware 10.1–10.3 Anti-malware deployed; automatic signature updates; autorun and autoplay disabled
11 Data recovery 11.1–11.4 Recovery process; automated backups; protected recovery data; isolated instance of recovery data
12 Network infrastructure 12.1 Infrastructure kept up to date
14 Awareness 14.1–14.8 Programme plus training on social engineering, authentication, data handling, unintentional exposure, incident recognition and reporting, missing updates, insecure networks
15 Service providers 15.1 Inventory of service providers
17 Incident response 17.1–17.3 Designated incident personnel; contact information for reporting; enterprise reporting process

Our guide to the CIS Controls v8.1 covers the full 18 and the three groups.

The six CIS Controls implementation steps

Step 1: assess and scope (weeks 1–2)

Set up CIS CSAT against v8.1 and IG1, define the enterprise boundary — every site, network and cloud tenancy — and assign an owner to each Control. Score honestly, with evidence; the result is the gap list the rest of the plan works through. Our guide to CIS Controls assessment covers the four scoring dimensions.

Step 2: know what you have (weeks 2–6)

Safeguards 1.1, 1.2, 2.1, 2.2, 2.3, 5.1 and 15.1: the enterprise asset inventory with its required fields, the software inventory with support status, the account inventory and the service provider inventory. Use the discovery you already have — MDM, EDR, directory, cloud consoles — and record owners. This step finds the unmanaged devices, the unsupported software and the dormant accounts that every later Safeguard depends on knowing about. Our guide to the asset inventory covers Controls 1 and 2 in depth.

Step 3: protect the foundation (weeks 4–10)

Controls 3, 4, 5 and 6 — 22 Safeguards. Write the data management process and inventory, set access control lists and retention, encrypt end-user devices; establish secure configuration processes and apply the CIS Benchmark baselines, session lock, host firewalls, secure management protocols and default-account handling; enforce unique passwords, disable dormant accounts at 45 days, separate administrator accounts; document access granting and revoking and turn on MFA for external applications, remote access and administration. Most of this is configuration on platforms already licensed; the documents are the policy-defined dimension.

Step 4: keep it patched, logged, clean and recoverable (weeks 8–14)

Controls 7 to 12 — 17 Safeguards. Vulnerability and remediation processes with monthly automated OS and application patching; a log management process with collection and adequate storage; supported browsers and clients with DNS filtering; anti-malware with automatic updates and autorun disabled; a recovery process with automated, protected and isolated backups; network infrastructure kept current. The isolated backup instance (11.4) and DNS filtering (9.2) are the two most commonly missing at assessment.

Step 5: people and response (weeks 10–16)

Controls 14 and 17 — 11 Safeguards. A security awareness programme covering the seven IG1 topics, and incident response basics: a designated person and backup, contact information for reporting to authorities and partners, and an enterprise process for staff to report incidents. Both run in parallel with steps 3 and 4 because they belong to different people.

Step 6: measure and move on (week 16 onward)

Reassess in CSAT, validate the evidence independently, and set the recurring calendar the Safeguards’ frequencies require. Then decide on IG2: if the organisation has dedicated IT staff supporting multiple departments, IG2’s 74 additional Safeguards are the next plan — starting with Control 8 log centralisation and retention, Control 7 scanning, Control 13 network monitoring and Control 16 application security, which are where IG2 adds most.

CIS Controls implementation timeline and effort

Organisation IG1 duration (our estimate) Internal effort What dominates
Small (25–100 users), managed cloud suite already in place 3–4 months 40–60 staff days Documentation, MFA rollout, backup isolation, awareness
Small, unmanaged endpoints 4–6 months 60–100 staff days Inventory, MDM or EDR deployment, configuration baselines
Mid-size (100–1,000 users) 6–9 months 150–300 staff days Scale of inventory and configuration; multiple sites; IG2 planning in parallel

Our guide to CIS Controls implementation cost covers what the effort and tooling cost.

Documents the IG1 Safeguards require

Safeguard Document Note
3.1 Data management process Sensitivity, owners, handling, retention, disposal; reviewed annually
4.1, 4.2 Secure configuration processes for enterprise assets and for network infrastructure Reviewed annually
6.1, 6.2 Access granting and access revoking processes Preferably automated
7.1, 7.2 Vulnerability management process; remediation process Risk-based remediation; reviewed annually
8.1 Audit log management process Collection, review, retention; reviewed annually
11.1 Data recovery process Scope, prioritisation, protection, isolation; reviewed annually
14.1 Security awareness programme Onboarding and at least annual training; reviewed annually
17.3 Enterprise incident reporting process Reporting to the designated personnel; reviewed annually
1.1, 2.1, 3.2, 5.1, 15.1 The five inventories Assets, software, data, accounts, service providers

Errors that stall CIS Controls implementation

  • Starting at IG2 or IG3. The tooling arrives before the inventory and the processes; the score improves in the Controls that matter least first.
  • Skipping the inventories. Controls 1, 2 and 5 are unglamorous and everything else silently depends on them.
  • Implementing without documenting. A Safeguard with no process document scores zero on the policy dimension and will not survive staff turnover.
  • Ignoring the frequencies. A monthly review that happens once is not a Safeguard; put the cycles in a calendar with owners.
  • Treating awareness as a video. Safeguards 14.2 to 14.8 name seven topics; a generic annual course does not cover them.
  • Forgetting isolation and DNS filtering. 11.4 and 9.2 are the two IG1 Safeguards most often found missing because they need a deliberate decision rather than a default.

Frequently asked questions

Where should CIS Controls implementation start?
With Implementation Group 1 — CIS states every enterprise should start there — and, inside IG1, with Controls 1, 2, 5 and 15: the inventories of assets, software, accounts and service providers that every later Safeguard depends on.

How many Safeguards are in IG1?
56 of the 153 in v8.1, drawn from 15 Controls. Controls 13, 16 and 18 have no IG1 Safeguards; Control 14 has the most with eight.

How long does IG1 take?
Our estimate: 3–4 months and 40–60 staff days for a small organisation already on a managed cloud suite, 4–6 months with unmanaged endpoints, and 6–9 months for a mid-size organisation with multiple sites.

Do we need new tools for IG1?
Usually little: MFA, endpoint encryption, patching and basic logging are in mainstream platforms; the common additions are a backup solution with an isolated copy, DNS filtering and an awareness training platform.

When should we move to IG2?
When IG1 is complete and evidenced in CSAT, and the organisation has dedicated IT staff supporting multiple departments — IG2’s definition. Start IG2 with logging, vulnerability scanning, network monitoring and application security.

Where this leaves you

Run CIS Controls implementation in the order the Controls are numbered: assess and scope, build the five inventories, protect the foundation in Controls 3–6, keep it patched, logged, clean and recoverable in 7–12, run awareness and incident response alongside, then measure and decide on IG2 — because IG1’s 56 Safeguards are mostly process and configuration, and the plan fails only when someone buys the IG2 tools first.

References

More on the CIS Controls

The IG1 project plan, the eight process documents and five inventory templates the Safeguards require, the 18 Control policies and the Safeguard-level tracker are in the CIS Controls v8.1 Toolkit, or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.