Blog / US compliance
US compliance
NIST CSF 2.0 or CIS Controls IG1: Which One a 30-Person Business Should Start With
Choosing a cybersecurity framework for small business: CIS Controls IG1 for the work, NIST CSF 2.0 for the client conversation, and why you start with IG1.
"Which framework do you follow?"
The principal of a 30-person civil engineering firm in Georgia is filling out a county vendor questionnaire for a stormwater contract. Page three, question nine: "Which cybersecurity framework does your organization follow?" There is a text box.
He types "our IT guy" and deletes it. He types "industry best practices" and deletes that too, because it is the kind of thing he would laugh at on a subcontractor's bid. He calls the IT guy, who says "NIST", the way people say "the government" when they mean something official. The principal downloads the NIST Cybersecurity Framework. It is a description of six things a business should be able to do. It does not tell him what to do on Tuesday.
The county follows up. Procurement would like a self-attestation against a named framework, with a summary of controls, before award. Two weeks.
He does what he would do with a structural question he had not seen before: finds the two standards everyone cites, reads both, and works out what each is actually for. By the end of the afternoon he has an answer that would not embarrass him, and a to-do list for the IT guy that is nine items long.
The firm was not insecure. It was undescribed. Those are different problems, and the second one is fixable in two weeks.
What the heck does this mean
NIST CSF 2.0 is the Cybersecurity Framework from the National Institute of Standards and Technology, updated in 2024. It organizes security into six functions: Govern, Identify, Protect, Detect, Respond and Recover. It is a vocabulary and a structure. It does not contain a list of controls, and it is not a certification.
CIS Controls v8.1 is the list of controls from the Center for Internet Security: 18 controls broken into 153 safeguards, each one a specific thing to do. Keep an inventory of your computers. Remove accounts of people who left. Train staff on phishing.
Implementation Group 1, or IG1, is the subset of 56 safeguards CIS calls essential cyber hygiene: the minimum every business should have, sized for one with no security team.
Here is my position. CSF is what you say to the county. IG1 is what you do on Tuesday. A 30-person business starts with IG1, because it is a to-do list, and then answers the county in CSF's language, because CIS publishes the mapping between them. Starting with CSF alone means spending a month deciding what "Protect" means for you. CIS already decided.
The clients and insurers who ask the question do not care which name is in the box. They care that there is a list, that someone owns it, and that it was done.
The numbers that matter
Implementation Group 1 contains 56 of the 153 safeguards in CIS Controls v8.1, and CIS defines it as essential cyber hygiene for every enterprise, according to the Center for Internet Security's v8.1 documentation published in 2024. Fifty-six specific tasks is a project a 30-person firm can finish.
IG1 safeguards defend against 78% of the ransomware techniques in the MITRE ATT&CK framework, according to the CIS Community Defense Model v2.0, published in 2021. The floor is not a token gesture; it stops most of what actually hits small businesses.
CIS Controls v8.1 maps directly to all six functions of NIST CSF 2.0, including the new Govern function, per CIS's 2024 mapping. Do IG1 and the CSF self-attestation writes itself from the crosswalk.
What to do this week
- Write the asset inventory: every laptop, workstation, server, phone, plotter and cloud application, with an owner and the date it was last updated. This is the first CIS control and the first thing the county's summary needs. (CIS 1 Inventory and Control of Enterprise Assets)
- Pull the user list from every system and compare it to the payroll list. Remove the engineer who left in March, the intern from last summer, and the vendor account nobody recognizes. Then turn on MFA for whatever is left. (CIS 5 Account Management)
- Run a twenty-minute phishing briefing for all 30 people this month, using a real example from the firm's own inbox, and keep the attendance sheet. That sheet is evidence for the Protect function. (CIS 14 Security Awareness and Skills Training)
- Restore one project folder from backup, time it, and write down the result. If the restore fails or nobody knows how, you have found the most important item on the list. (CIS 11 Data Recovery)
- Name the owner of security in writing, even if it is the principal, and put the IG1 review on the calendar quarterly. That single sentence covers most of what CSF's Govern function asks. (CIS 14 Security Awareness and Skills Training)
- Answer the county with the IG1 safeguards you have completed, grouped under CSF's six functions using the CIS crosswalk, with the date beside each one. Two pages. Honest gaps with dates beat a clean page with nothing behind it. (CIS 1 Inventory and Control of Enterprise Assets)
Where AccuSights fits
Our assessment is built on CIS Controls v8.1, and our reports are written in the language the county, the insurer or the hospital client is asking for, because we keep the mapping so you do not have to. Our team implements the safeguards at a reasonable rate, from the asset inventory and account cleanup to data loss prevention, scanning and protection of the machines the engineers draw on. Take the three-minute Cyber Hygiene Test to see roughly where you sit against IG1, then spend 15 minutes with an engineer on the nine-item list.
Questions people ask
Is NIST CSF mandatory? Not for a private business. It is voluntary guidance from a federal standards agency, which is exactly why clients, insurers and county procurement offices like to ask about it: it is neutral, free and everyone has heard of it. Contracts can make it mandatory for you, and federal agencies and some regulated sectors are required to use it, but the 30-person engineering firm adopts it because a customer asked, not because a law did.
How many CIS Controls are there? Eighteen controls in version 8.1, broken into 153 specific safeguards. The safeguards are grouped into three implementation groups by how much capability a business has. Implementation Group 1 is 56 safeguards and is defined by CIS as essential cyber hygiene, the floor for every organization. IG2 and IG3 add the rest for businesses with more data, more staff or more regulatory exposure.
Can a small business get certified against NIST CSF? No. There is no NIST certification, no NIST auditor and no NIST badge, and anyone selling one is selling something else. What you can do is produce a written self-assessment against the six functions with evidence behind it, and hand that to whoever asked. If a client needs an outside opinion, that is what SOC 2 and ISO 27001 are for, and both map back to the same controls you built for IG1.
Pick the list you will actually finish. A framework you can describe to a county is worth something; fifty-six things you have actually done is worth a contract.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
The NYDFS Annual Certification: What to Have Ready in March So the 15 April Filing Takes an Afternoon
The NYDFS annual certification is due 15 April. The evidence a covered entity should collect in March for Part 500, from asset inventory to MFA and logs.
US complianceNine Terminals, Five Stores, One Holiday Peak: PCI DSS 4.0.1 for Atlanta Retail
PCI DSS for multi-location retail in Atlanta: what 4.0.1 asks of nine terminals across five stores, and the six checks to finish before the holiday peak.
US complianceISO 27001 vs SOC 2: Which One Your Customers Are Actually Asking For
ISO 27001 vs SOC 2 for a small software company: what each one proves, who asks for which, what the certificate costs you in time, and how to do the work once.
