The CIS Controls v8 are a prioritized set of 18 security controls, broken into 153 safeguards, published by the Center for Internet Security to give an organization a defensible order of operations rather than a wish list. For a small firm the practical entry point is Implementation Group 1, a subset of 56 safeguards that CIS defines as basic cyber hygiene and the minimum an enterprise should carry. Version 8 consolidated the earlier 20 controls down to 18 and rewrote them around cloud, mobile, and remote work instead of the office perimeter. Version 8.1, released in June 2024, kept the same 18 controls and 153 safeguards while adding alignment to NIST CSF 2.0 and a Govern function. The framework is clear. The rollouts we get called into are usually not.
The Five Things Small Firms Need to Know First
Before you open the control list, five points decide whether this becomes a security program or a spreadsheet nobody updates. We work these through with owner-operated firms and 50 to 500 employee companies almost every week, usually after a cyber insurance renewal or a customer questionnaire forces the issue.
- IG1 is a floor, not a starter kit. Those 56 safeguards are the baseline CIS says every organization should carry, including yours, at any headcount.
- The numbering is not the sequence. Control 1 comes first on paper, but it is also the control most likely to stall you for a quarter if you treat it as a prerequisite for everything else.
- You are probably already doing 20 to 30 safeguards. Most firms we assess have real coverage they cannot evidence, which reads as a failure on a questionnaire.
- Version drift is a real scoping problem. A team working from v8 documentation while an auditor scores against v8.1 will argue about mappings instead of fixing anything.
- Evidence is a build decision, not a reporting task. If you capture proof at the moment you implement a safeguard, assessment is a review. If you capture it later, it is an excavation.
That framing sits inside a wider pattern we see across compliance work. Our team walks through the same sequencing question in our guide to building a cybersecurity compliance framework, and the failure mode is identical no matter which framework is on the whiteboard.
Why a CIS Controls v8 Guide Stalls Before Control 3
A CIS Controls v8 guide stalls inside small firms because the first two controls demand ownership of data nobody currently owns, and the program cannot show progress until that ownership exists. Here is the pattern we see in the wild: a firm commits to IG1, assigns the work to whoever handles IT, and six weeks later the only artifact is a partial asset list in a spreadsheet with three tabs and no owner. The technical work was never the obstacle.
Gap 1: Nobody Owns the Asset and Software Inventory
Control 1 and Control 2 fail on ownership rather than tooling, because an inventory that no named person maintains goes stale in about thirty days. The case for treating inventory as the true first step is strong. You cannot patch, configure, or monitor an asset you do not know exists, and every downstream safeguard inherits that blind spot. The case against treating it as a gate is equally strong. Firms that refuse to move past Control 1 until the inventory is perfect spend a quarter counting laptops while unmanaged local administrator accounts sit wide open. Both are true at once, which is why we assign a named owner to the inventory, accept 90 percent coverage as a working baseline, and start Control 4 and Control 5 in parallel rather than in sequence. The inventory then improves as a habit instead of a project.
Gap 2: IG1 Gets Read as an Introductory Tier
Implementation Group 1 is frequently mistaken for a beginner tier that a growing firm graduates out of, when CIS positions it as the minimum standard of enterprise information security. Read generously, the graduation instinct makes sense. IG1 is scoped for an organization with limited IT and security expertise and a low tolerance for downtime, so a firm adding a security analyst reasonably asks what comes next. Read strictly, the instinct is a trap, because IG2 and IG3 safeguards layer on top of IG1 rather than replacing it, and a firm chasing IG2 with IG1 half-covered has built the second floor before the first. We hold both positions in the same conversation: plan for IG2 where your risk profile or a contract genuinely demands it, and refuse to score IG2 work as progress while IG1 safeguards remain open.
Gap 3: Version 8 and Version 8.1 Get Mixed in One Program
Version 8.1 did not renumber the controls or change the safeguard count, so teams assume the two documents are interchangeable, and then lose weeks reconciling them. The interchangeable view has merit. The 18 controls and 153 safeguards carried forward, and a safeguard implemented against v8 is not invalidated by v8.1. The opposing view carries the practical risk, because v8.1 added the Govern function and NIST CSF 2.0 alignment, which is exactly the language an insurer or a prime contractor now uses in a questionnaire. Our position is to build against v8.1 and document the version on every artifact. A firm that cannot state which version it scored against will have that argument at the worst possible moment, in the middle of an assessment. If you want the broader hygiene view first, our overview of cybersecurity best practices for SMBs covers the same ground without the framework vocabulary.
How Implementation Groups Change What You Actually Owe
Implementation groups exist so that a 40 person firm and a 4,000 person firm can use the same control set without pretending they carry the same obligation, and misreading them is the fastest way to overspend. This is where scoping conversations either get honest or get expensive. Our cybersecurity compliance services engagements almost always open by re-cutting a scope somebody already drew too wide.
Gap 4: Safeguards Get Pulled Forward From IG2 Without a Reason
IG2 safeguards get adopted early because they look mature, not because a risk assessment called for them, and the cost lands on a team that has not finished IG1. The argument for pulling them forward is real. Certain IG2 safeguards, network segmentation and centralized log management among them, deliver outsized value once a firm holds sensitive customer or patient data, and waiting for a perfect IG1 score to start them is its own risk. The argument against is budget honesty, since IG2 assumes dedicated security staff and IG3 assumes a security team with specialized expertise, and a firm without either buys tooling it cannot operate. We resolve it with a written trigger for every pulled-forward safeguard: the contract, the data type, or the assessed risk that justifies it. No trigger, no early adoption.
Gap 5: Safeguards Are Worked in Numeric Order
Working the safeguards in numeric order feels disciplined and quietly deprioritizes the controls that stop the intrusions we actually respond to. In defense of numeric order, it is auditable, easy to delegate, and nobody loses their place. Against it, the numbers are a reference structure, not a risk ranking, and account management and access control revocation sit at Control 5 and Control 6 while asset and software work at Control 1 and Control 2 can absorb a full quarter. In practice we sequence IG1 by attack path: identity and access first, secure configuration next, then logging, with inventory running continuously underneath as an owned habit. Our field notes on the controls that stop real intrusions track closely to that order, and our managed security services team runs the logging and monitoring safeguards for firms that cannot staff a watch.
Where a CIS Controls v8 Guide Meets Your Other Obligations
A CIS Controls v8 guide rarely lives alone inside a small firm, because the same company is usually answering to an insurer, a customer questionnaire, and sometimes a federal contract clause at the same time. Treating those as separate programs is how a 40 person company ends up with three overlapping projects and one exhausted IT lead.
Gap 6: The Same Control Gets Implemented Three Times
Overlapping frameworks cause duplicate implementation because each program is scoped by its own document rather than by the underlying control. The separation argument has a legitimate basis. Frameworks differ in evidence expectations and assessor language, and a defense contractor cannot simply hand a CIS spreadsheet to a CMMC assessor and call it done. The consolidation argument is stronger for a small firm, since multifactor authentication implemented once satisfies a CIS safeguard, a NIST SP 800-171 requirement, and an insurance attestation simultaneously. We build one control set and map it outward. For firms in the defense supply chain, our CMMC services team runs that mapping directly, and our breakdown of identification and authentication controls under CMMC shows how a single identity control satisfies several masters at once.
Gap 7: Evidence Is Collected After the Fact
Evidence gets treated as a reporting step at the end rather than an artifact captured during implementation, which turns every assessment into archaeology. There is a defensible case for deferring it. Documentation slows delivery, and a firm racing a renewal deadline reasonably prioritizes working controls over screenshots. The counter-case is what we watch happen six months later, when the engineer who hardened the firewall has moved on and nobody can prove when the change was made or who approved it. We capture evidence at the moment of implementation: the configuration export, the policy signature date, the ticket that carried the change. A security assessment then becomes a review of what exists rather than a reconstruction of what happened.
How We Sequence the First 90 Days
Our team runs the first 90 days of an IG1 rollout in three overlapping tracks, so that ownership, risk reduction, and evidence all move at once instead of queuing behind a spreadsheet.
- Days 1 to 15. Name one owner for the asset and software inventory. Pull what your existing endpoint tooling already knows rather than starting a manual count. Record the version you are scoring against, v8.1 in almost every case.
- Days 10 to 45. Work identity first. Enforce multifactor authentication on email, remote access, and administrative accounts. Inventory and remove standing local administrator rights. Document a revocation step in your offboarding process and test it once.
- Days 30 to 60. Move to secure configuration. Apply a hardening baseline to workstations and servers, close default and unused services, and confirm your backup restores rather than assuming the job status is truthful.
- Days 45 to 90. Stand up centralized logging with a retention window you can defend, and write the incident response contact list before you need it. Score IG1 honestly, marking partial coverage as partial.
- Continuous. Capture evidence as you go, one folder per control, with dates and named approvers.
That plan is deliberately unglamorous. The firms that finish IG1 are not the ones with the best tooling, they are the ones who assigned the inventory to a person with a name.
Frequently Asked Questions
How many controls and safeguards are in CIS Controls v8?
CIS Controls v8 contains 18 controls broken into 153 safeguards, and version 8.1 retains the same counts. Version 8 consolidated the previous 20 controls down to 18 and reorganized them around cloud, mobile, and remote work rather than a network perimeter. The safeguards are then segmented into three implementation groups so an organization can scope to its own size and risk.
Is IG1 enough for a small business?
IG1 is the minimum standard CIS defines for every enterprise, and for many small firms with no regulated data it is a defensible target for the first year. Its 56 safeguards are scoped for an organization with limited IT and security expertise. Firms holding patient records, cardholder data, or federal contract information usually need selected IG2 safeguards on top, driven by that specific obligation.
How long does a CIS Controls v8 rollout take for a 100 person firm?
Most 100 person firms we work with reach credible IG1 coverage in four to six months, with the first meaningful risk reduction inside 60 days. The variable is rarely the technology. It is whether one named person owns the asset and software inventory and whether evidence is captured during implementation instead of afterward.
Should we use CIS Controls v8 or NIST CSF?
The two are complementary rather than competing, since CIS Controls v8.1 maps to NIST CSF 2.0 and gives you prioritized safeguards where CSF gives you outcome categories. Small firms generally get moving faster with CIS because the safeguards are specific and ordered. If a customer or regulator names CSF, build the CIS safeguards and map them upward.
Do we need new tooling to implement CIS Controls v8?
Most IG1 safeguards are configuration and process work inside systems a firm already pays for, particularly identity, endpoint management, and backup. New spend usually appears at centralized logging and continuous vulnerability management. We recommend scoring your current coverage before any purchase, because firms routinely own the capability and have never turned it on.
Get Your CIS Controls v8 Rollout Moving
The gap between a firm that reads a CIS Controls v8 guide and one that finishes IG1 is almost never budget or expertise. It is ownership, sequencing, and the discipline to capture evidence while the work is fresh. If your program has been sitting at Control 1 for a quarter, or a renewal questionnaire just told you that coverage you genuinely have cannot be proven, that is a fixable position and a common one. Our team will score your current safeguard coverage, cut the scope to what your risk and contracts actually require, and hand you a 90 day sequence with a named owner against every line. Book a free strategy call and bring whatever inventory you have, however incomplete. We would rather start from your real state than a tidy one.

