Skip to content

CIS Controls

CIS Controls v8 Implementation Checklist (IG1–IG3)

A Safeguard-oriented checklist to implement CIS Controls v8 by Implementation Group, from IG1 hygiene through IG3 enterprise.

Estimated time
3–9 Months
Audience
IT Teams Building a Foundational Cyber Program
Last updated

Operational reference for CIS Controls v8. CIS does not certify organizations; this is a self-assessment aid.

Progress0% Completed

Progress is saved in this browser only. Nothing is sent to a server.

Phase 1: IG1 Foundational Hygiene

Phase 2: Email, Malware & Recovery

Phase 3: IG2 Service Provider & Application

Phase 4: Measure & Govern

FAQ

What is an Implementation Group?+

IG1 is essential cyber hygiene for all enterprises. IG2 and IG3 add Safeguards for more complex risk.

Does CIS certify companies?+

No. CIS Controls are a prioritized set of Safeguards. Some tools map to CIS, but there is no CIS certificate of the company.

How does CIS map to NIST CSF?+

CIS publishes mappings. Teams often use CIS as the technical worklist and CSF as the board narrative.

Is Control 18 pentesting required for IG1?+

No. Penetration testing is an IG2/IG3 Safeguard.

Related field notes

The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer