Risk & Leadership

Which CIS Implementation Group Fits Your Organization?

Start with IG1, then decide what additional scope your risk, resources, data, services and threat environment require. Organization size alone is not the decision.

Part of the seriesSecurity Guidance, Applied

Choose an Implementation Group as a risk-and-resource decision, not a company-size label. CIS describes IG1 as essential cyber hygiene for every enterprise. IG2 builds on IG1, and IG3 includes all 153 Safeguards in CIS Controls v8 and v8.1.

What Implementation Groups are for

The Center for Internet Security uses Implementation Groups (IGs) to help organizations prioritize implementation of the CIS Critical Security Controls. The groups are based on an enterprise's risk profile and the resources available to implement the Controls.

That framing matters. An IG is a way to organize scope and priority. It is not a certification level, a maturity score, or a conclusion that every risk outside the selected group can wait.

The cumulative structure
IG1 · 56 SafeguardsCIS describes IG1 as essential cyber hygiene and the foundation every enterprise should start with.
IG2 · 130 totalIG2 adds 74 Safeguards to IG1 for greater operational complexity and additional sensitivity.
IG3 · 153 totalIG3 adds 23 more Safeguards and includes all Safeguards in the CIS Controls.
The groups are cumulative. The IG2 total is 56 + 74; IG3 is 56 + 74 + 23.
The LinkedIn visual for this edition
ByteDefender portrait infographic titled Which CIS Implementation Group Fits? It identifies the Center for Internet Security and CIS Controls v8.1, shows the cumulative groups IG1 with 56 Safeguards, IG2 with 130 total, and IG3 with 153 total, and presents four practical questions about context, foundation, evidence and review. An amber note says a group is not proof of implementation, effectiveness or compliance.
The companion visual separates the CIS source summary from ByteDefender's practical application prompts.

Read each group in context

IG1: the foundation

CIS defines IG1 as essential cyber hygiene and describes it as a foundational set of 56 cyber-defence Safeguards that every enterprise should apply against common attacks. The IG1 profile commonly describes organizations with limited dedicated IT and cybersecurity expertise, lower tolerance for downtime, and data sensitivity principally around employee and financial information.

That description is context, not a permission slip. A small organization may operate a critical service, hold highly sensitive information, face contractual obligations, or have a threat environment that requires additional safeguards.

IG2: additional scope for complexity and sensitivity

IG2 adds 74 Safeguards to IG1, for 130 in total. CIS describes IG2 as relevant to organizations with greater operational complexity, people responsible for managing infrastructure, multiple departments with differing risk profiles, and sensitive client or enterprise information.

Some IG2 Safeguards may depend on enterprise-grade technology or specialist expertise. That does not mean a smaller organization is automatically excluded; it means the organization should make the dependency and operating model explicit.

IG3: the full set and more demanding threat context

IG3 adds 23 Safeguards to the first two groups, totaling all 153 Safeguards in CIS Controls v8 and v8.1. CIS describes IG3 contexts that may involve sensitive functions, specialist cybersecurity expertise, regulatory or compliance oversight, and targeted or sophisticated threats.

Again, the group is not a guarantee. Selecting IG3 does not demonstrate that all 153 Safeguards are implemented, configured correctly or effective in the organization's environment.

Four questions before you choose a scope

ByteDefender's application lens turns the group descriptions into a short decision record. These prompts are practical interpretation, not an official CIS selection questionnaire.

1. What does our context require?

Consider the information and services you protect, potential disruption, operational complexity, threats, available expertise and the resources needed to operate safeguards. Ask what would be harmed by disclosure, unauthorized change or unavailability—not only how many people work in the organization.

2. What will IG1 establish, and what remains open?

Start with IG1 as the foundation CIS recommends for every enterprise. Then identify which additional safeguards your circumstances require. Do not describe IG1 as “enough” solely because the organization is small, and do not treat the starting point as a reason to defer an urgent risk-specific action.

3. What evidence supports the decision?

Record the current implementation state for the safeguards in scope. Evidence may include configuration records, access reviews, restoration tests, incident-exercise results, vulnerability-management records or other artifacts appropriate to the safeguard and its operating context.

For a deferred safeguard, capture the reason for deferral, the residual risk, the accountable decision owner and a review date. “Not yet implemented” and “unknown” are different states and should not be collapsed into one label.

4. What change would trigger a review?

A group decision should remain connected to the environment that produced it. Revisit the rationale when the organization adds an important service, begins processing more sensitive data, changes providers, takes on new obligations, faces a material threat change, or gains or loses the expertise needed to operate safeguards.

A compact record for an Implementation Group decision
Decision questionRecordUseful evidence
Why this scope?Risk profile, services, data sensitivity, threats and resources.Service map, data inventory, risk assessment and obligations register.
What is foundational?IG1 Safeguards and the outcomes they support.Implementation status, owner and verification artifact.
What is deferred?Rationale, residual risk, accountable owner and review date.Approved decision record and follow-up plan.
When will we revisit it?Material-change triggers and next scheduled review.Change-management event, risk review or leadership checkpoint.

What selecting a group does not establish

Choosing IG1, IG2 or IG3 is not proof that the relevant Safeguards are implemented, operating effectively or sufficient for every obligation. It does not establish compliance or certification.

Likewise, a resource constraint may affect sequencing, but it does not make a material risk disappear. Document the decision and residual risk so that leadership understands what remains open.

A practical working session

Start with one important service or risk theme. Bring together the accountable leader, the person responsible for security or IT, and the owners of the systems or providers involved.

  1. List the services, information, systems and providers that matter.
  2. Describe potential confidentiality, integrity and availability consequences.
  3. Record the threats, expertise and resources that shape the decision.
  4. Start with IG1, then identify additional safeguards your context requires.
  5. Assign owners, capture evidence and document any deferral and residual risk.
  6. Set the next review date and the material changes that should trigger an earlier review.

The result is not a compliance verdict. It is a defensible scope decision that can guide a control plan, a risk-assessment engagement or a conversation with leadership.

Where to begin

Download the CIS Controls v8.1 materials, begin with the IG1 foundation, and write down why any additional scope is or is not required. Make the decision visible, assign its follow-up, and revisit it when the organization changes.

If the organization cannot explain its chosen group in writing, the next step may be scope clarification or a focused risk assessment—not simply selecting a larger group by instinct.

Primary sources

  1. Center for Internet Security, CIS Critical Security Controls Implementation Groups.
  2. CIS Critical Security Controls Version 8.1.
  3. CIS Implementation Group 1, IG2 and IG3.

Source status checked 9 September 2026. The group descriptions, cumulative structure and Safeguard counts are summarized from CIS pages. The four questions, evidence record and review prompts are ByteDefender's practical interpretation; they are not presented as a complete CIS assessment method.

Need help choosing and sequencing safeguards?

ByteDefender can help define scope, examine risk and resources, verify current evidence, and turn open gaps into an owned improvement plan.

Explore risk assessment