What category of guidance this is
The CIS Critical Security Controls (CIS Controls) are a prioritized set of Safeguards to defend against prevalent attacks against systems and networks. The Version 8.1 page says they are mapped to and referenced by multiple legal, regulatory, and policy frameworks. Implementation Groups (IGs) are recommended guidance for which Safeguards to implement first. The official IG page bases that choice on an enterprise risk profile and the resources available to implement the Controls.
Who it commonly frames: builders and defenders who already speak CIS hygiene language, Foundations readers who met an IG1 mindset only as a slogan, and buyers who treat a CIS aligned slide as a certificate. This is an industry prioritization discipline. It is not a U.S. statute.
What security people most often confuse: they fold IG1, a CSF Govern outcome, an SP 800-53B baseline, and an ISO/IEC 27001 certificate into one badge. This page keeps those objects apart. The Reference card at /reference/frameworks/cis-controls-8-1/ remains the framework summary. This explainer complements that card. It does not replace it, and it does not list Safeguards.
Edition pin
CIS Controls Version 8.1 is an iterative update to Version 8. The Center for Internet Security announced the release in a press release dated 2024-06-25. The Version 8.1 white paper was published 2024-06-24. The Version 8.1 page still presents Version 8.1 as the current Controls version as of this review (2026-09-26), and it points readers to earlier versions. If a newer version appears, update this pin and treat the older claim as UNKNOWN.
Highlights on those pages, at slogan depth: NIST CSF 2.0 security-function mapping realignment, including the Govern function; revised asset classes; clarifications to some Safeguard descriptions; expanded glossary definitions for reserved words; and design principles of context, coexistence, and consistency. This page does not reprint Safeguard text. The Atlas Reference string is CIS Controls v8.1.
IG1, then IG2, then IG3
IG1 is essential cyber hygiene. The official IG page calls it the foundational set of cyber defense Safeguards that every enterprise should apply to guard against the most common attacks. IG2 builds upon IG1. IG3 builds upon IG1 and IG2. The same page says IG3 is comprised of all the Controls and Safeguards (the full set). Which group is the current target depends on risk profile and available resources.
Count literacy, one line: CIS states there is a total of 153 Safeguards in Version 8 and Version 8.1. IG1 is a starting subset. IG2 and IG3 are cumulative, because each later group builds on the earlier group, and IG3 is the full set. This page does not list Safeguard identifiers, and it does not reprint Safeguard text. Per-Control counts by Implementation Group stay on the official IG page. They are not homework here. Treat a count you remember from a slide as UNKNOWN until you re-open that page.
The ladder below is literacy only. It does not assign a group to a real enterprise, and it does not name which Safeguards sit in which group.
A starting discipline, not a trophy
Every enterprise should start with IG1. Implementation is iterative. Environments, threats, and business objectives change, so a group chosen once is not a finish line.
IG progress is a prioritization discipline. Attackers do not automatically honor that discipline as a safe harbor, and finishing a starting set does not mean an attack will skip the enterprise. The 2024-06-25 press release says the Controls have been included in state cybersecurity safe harbor statutes in Ohio, Utah, Connecticut, and Iowa. Whether a named statute treats an IG1 program as a defense, and on what terms, is UNKNOWN on this page. Ask counsel. A vendor "aligned" claim is still not a certificate.
What this card is not
Not a Safeguard encyclopedia. Not a second full Controls card replacing the Reference card at /reference/frameworks/cis-controls-8-1/. Not a do-it-yourself gap-assessment form. Not a reprint of Safeguard text (that text is copyrighted). Not proof that attackers will skip you. Not an Atlas attestation of CIS alignment.
Not a CSF 2.0 profile. Version 8.1 realigns mappings toward the CSF 2.0 Govern function, and a mapping is not the same thing as finishing Govern. Outcomes live on /learn/topics/outcomes-then-controls/ and on /reference/frameworks/nist-csf-2-0/. Not an SP 800-53B baseline. Catalog literacy is /learn/explainers/sp-800-53/, and the catalog card is /reference/frameworks/nist-sp-800-53-r5/. Not an ISO/IEC 27001 certificate. That lane is /learn/explainers/iso-27001/. The six-map comparison is /reference/frameworks/compare/. A row there is not this ladder.
Rewrite the one-line claim
Replace "we are CIS, IG1, CSF, and ISO compliant" with a reading sentence. We use CIS Controls Version 8.1 Implementation Groups as a starting hygiene prioritization discipline (IG1, then IG2, then IG3). That is different from an ISO/IEC 27001 scoped certificate, from CSF 2.0 outcomes, and from an SP 800-53 baseline.
When a slide says "CIS aligned," privately ask which Implementation Group is the current target, and what evidence shows a Safeguard actually runs. Do not paste proprietary CIS PDF text into Atlas.
IG1 is not a certificate, not CSF Govern, not an 800-53 baseline, and not an ISO certificate
Teaching table only. It does not assign a certificate, a CSF profile, a baseline, an alignment, or a finding that a Safeguard is in place.
| Phrase people say | Literacy correction |
|---|---|
| We finished IG1, so we are certified / safe harbor | CIS Implementation Groups are not a formal certification scheme. A vendor aligned claim is not a certificate. Reference card: /reference/frameworks/cis-controls-8-1/. |
| IG1 = CSF Govern done | CSF Govern is outcomes language. IG1 is a CIS hygiene starting set. Related mappings exist in Version 8.1. Do not collapse them. Atlas card: /reference/frameworks/nist-csf-2-0/. Lesson: /learn/topics/outcomes-then-controls/. |
| IG1 = 800-53 baseline | SP 800-53B baselines are a different catalog companion. Do not equate them. Atlas card: /learn/explainers/sp-800-53/. Reference card: /reference/frameworks/nist-sp-800-53-r5/. |
| IG1 = ISO certificate | ISO/IEC 27001 is an ISMS requirements and certification lane. Different object. Atlas card: /learn/explainers/iso-27001/. |
| CIS done means CSF / ISO / 800-53 done | The Reference comparison already names this misuse: claiming CIS is done, so CSF or ISO is done. Keep that separation. Six-map comparison: /reference/frameworks/compare/. |
Claims to retire
Finishing IG1 means the enterprise is certified, holds a safe harbor, and attackers will skip it.
Implementation Groups are not a formal certification scheme. Finishing IG1 is not a certificate from this page, and it is not proof an attack will fail. Whether a named state statute treats an IG1 program as a defense is UNKNOWN here. Ask counsel.
CIS aligned, an ISO certificate, CSF done, and an 800-53 baseline are the same badge.
They are different objects. IG1 is a CIS hygiene starting set. An ISO/IEC 27001 certificate is a scoped ISMS assurance lane. CSF 2.0 is outcomes language. An SP 800-53B baseline is a catalog companion. A mapping does not finish the others.
This page replaces the Reference CIS framework card.
The card at /reference/frameworks/cis-controls-8-1/ stays the framework summary. This page is Implementation Group literacy beside that card.
Atlas can attest that an organization is CIS aligned.
Atlas does not issue CIS aligned seals or CIS IG1 compliant badges. Completing this lesson is not aligned and not certified.
Safeguard text should be pasted into Atlas lessons.
Safeguard text is copyrighted. This page does not reprint it, and it does not list Safeguard identifiers. Read the official Controls download instead.
IG1, then IG2, then IG3
Static ladder from the CIS Implementation Groups page. Literacy only. It does not list Safeguard identifiers, and it does not reprint Safeguard text.
| Group | Literacy | Boundary |
|---|---|---|
| IG1 | Essential cyber hygiene. The foundational starting set every enterprise should apply to guard against the most common attacks | A starting subset of the 153 Safeguards. Not the full set, and not a certificate. |
| IG2 | Builds upon IG1. The group that fits still depends on risk profile and available resources | Cumulative with IG1. Not a separate catalog, and not a certificate. |
| IG3 | Builds upon IG1 and IG2. The IG page says this group is comprised of all the Controls and Safeguards (the full set) | The full set. Not proof an attacker will skip the enterprise. |
CHECK THE CATEGORY
Which sentence matches this page?
Glossary and nearby pages
- CIS Controls Reference card (framework summary, not replaced by this page)
- Compare the six maps (a row is not this ladder)
- Outcomes first, then controls (F8a)
- ISO/IEC 27001 explainer (scoped certificate, different object)
- SP 800-53 explainer (catalog and baselines, not an Implementation Group)
- NIST SP 800-53 Reference card (catalog summary)
- NIST CSF 2.0 framework card (outcomes, including Govern)
- GRC practice path
- Privacy is not a CIA checkbox
Use the agency page in the sources for the authoritative text. This page has no figure.