Choose an Implementation Group as a risk-and-resource decision, not a company-size label. CIS describes IG1 as essential cyber hygiene for every enterprise. IG2 builds on IG1, and IG3 includes all 153 Safeguards in CIS Controls v8 and v8.1.
What Implementation Groups are for
The Center for Internet Security uses Implementation Groups (IGs) to help organizations prioritize implementation of the CIS Critical Security Controls. The groups are based on an enterprise's risk profile and the resources available to implement the Controls.
That framing matters. An IG is a way to organize scope and priority. It is not a certification level, a maturity score, or a conclusion that every risk outside the selected group can wait.

Read each group in context
IG1: the foundation
CIS defines IG1 as essential cyber hygiene and describes it as a foundational set of 56 cyber-defence Safeguards that every enterprise should apply against common attacks. The IG1 profile commonly describes organizations with limited dedicated IT and cybersecurity expertise, lower tolerance for downtime, and data sensitivity principally around employee and financial information.
That description is context, not a permission slip. A small organization may operate a critical service, hold highly sensitive information, face contractual obligations, or have a threat environment that requires additional safeguards.
IG2: additional scope for complexity and sensitivity
IG2 adds 74 Safeguards to IG1, for 130 in total. CIS describes IG2 as relevant to organizations with greater operational complexity, people responsible for managing infrastructure, multiple departments with differing risk profiles, and sensitive client or enterprise information.
Some IG2 Safeguards may depend on enterprise-grade technology or specialist expertise. That does not mean a smaller organization is automatically excluded; it means the organization should make the dependency and operating model explicit.
IG3: the full set and more demanding threat context
IG3 adds 23 Safeguards to the first two groups, totaling all 153 Safeguards in CIS Controls v8 and v8.1. CIS describes IG3 contexts that may involve sensitive functions, specialist cybersecurity expertise, regulatory or compliance oversight, and targeted or sophisticated threats.
Again, the group is not a guarantee. Selecting IG3 does not demonstrate that all 153 Safeguards are implemented, configured correctly or effective in the organization's environment.
Four questions before you choose a scope
ByteDefender's application lens turns the group descriptions into a short decision record. These prompts are practical interpretation, not an official CIS selection questionnaire.
1. What does our context require?
Consider the information and services you protect, potential disruption, operational complexity, threats, available expertise and the resources needed to operate safeguards. Ask what would be harmed by disclosure, unauthorized change or unavailability—not only how many people work in the organization.
2. What will IG1 establish, and what remains open?
Start with IG1 as the foundation CIS recommends for every enterprise. Then identify which additional safeguards your circumstances require. Do not describe IG1 as “enough” solely because the organization is small, and do not treat the starting point as a reason to defer an urgent risk-specific action.
3. What evidence supports the decision?
Record the current implementation state for the safeguards in scope. Evidence may include configuration records, access reviews, restoration tests, incident-exercise results, vulnerability-management records or other artifacts appropriate to the safeguard and its operating context.
For a deferred safeguard, capture the reason for deferral, the residual risk, the accountable decision owner and a review date. “Not yet implemented” and “unknown” are different states and should not be collapsed into one label.
4. What change would trigger a review?
A group decision should remain connected to the environment that produced it. Revisit the rationale when the organization adds an important service, begins processing more sensitive data, changes providers, takes on new obligations, faces a material threat change, or gains or loses the expertise needed to operate safeguards.
| Decision question | Record | Useful evidence |
|---|---|---|
| Why this scope? | Risk profile, services, data sensitivity, threats and resources. | Service map, data inventory, risk assessment and obligations register. |
| What is foundational? | IG1 Safeguards and the outcomes they support. | Implementation status, owner and verification artifact. |
| What is deferred? | Rationale, residual risk, accountable owner and review date. | Approved decision record and follow-up plan. |
| When will we revisit it? | Material-change triggers and next scheduled review. | Change-management event, risk review or leadership checkpoint. |
What selecting a group does not establish
Choosing IG1, IG2 or IG3 is not proof that the relevant Safeguards are implemented, operating effectively or sufficient for every obligation. It does not establish compliance or certification.
Likewise, a resource constraint may affect sequencing, but it does not make a material risk disappear. Document the decision and residual risk so that leadership understands what remains open.
A practical working session
Start with one important service or risk theme. Bring together the accountable leader, the person responsible for security or IT, and the owners of the systems or providers involved.
- List the services, information, systems and providers that matter.
- Describe potential confidentiality, integrity and availability consequences.
- Record the threats, expertise and resources that shape the decision.
- Start with IG1, then identify additional safeguards your context requires.
- Assign owners, capture evidence and document any deferral and residual risk.
- Set the next review date and the material changes that should trigger an earlier review.
The result is not a compliance verdict. It is a defensible scope decision that can guide a control plan, a risk-assessment engagement or a conversation with leadership.
Where to begin
Download the CIS Controls v8.1 materials, begin with the IG1 foundation, and write down why any additional scope is or is not required. Make the decision visible, assign its follow-up, and revisit it when the organization changes.
If the organization cannot explain its chosen group in writing, the next step may be scope clarification or a focused risk assessment—not simply selecting a larger group by instinct.
Primary sources
- Center for Internet Security, CIS Critical Security Controls Implementation Groups.
- CIS Critical Security Controls Version 8.1.
- CIS Implementation Group 1, IG2 and IG3.
Source status checked 9 September 2026. The group descriptions, cumulative structure and Safeguard counts are summarized from CIS pages. The four questions, evidence record and review prompts are ByteDefender's practical interpretation; they are not presented as a complete CIS assessment method.