Just In Time AI

CIS Controls v8: The MSP's Complete Guide to Implementation and Revenue

CIS Controls v8 gives MSPs 18 prescriptive security controls across 3 Implementation Groups. Start every client with an IG1 assessment, use the gaps as your proposal scope, and build recurring revenue around continuous compliance monitoring.

Dan StoltsApril 27, 20269 min read

CIS Controls v8 is a set of 18 prioritized security controls organized into three Implementation Groups -- IG1 (56 safeguards), IG2 (130 total), and IG3 (153 total) -- that give MSPs a prescriptive, insurance-aligned framework to structure assessments, legitimize proposals, and build recurring revenue around continuous compliance monitoring. Unlike NIST CSF which describes what to achieve, CIS Controls prescribe exactly what to do, mapping directly to service delivery. MSPs that lead with an IG1 gap assessment close more proposals, compete on value instead of price, and create natural upsell paths as clients mature through implementation groups.


Key Takeaways

  • CIS Controls v8 contains 18 controls organized into 3 Implementation Groups with 56, 130, and 153 cumulative safeguards
  • IG1 (essential cyber hygiene) is the baseline every client should meet regardless of size
  • CIS Controls are prescriptive (what to do) unlike NIST CSF which is descriptive (what to achieve)
  • Most cyber insurance carriers reference CIS Controls in underwriting criteria
  • MFA, endpoint protection, and email security (Controls 5, 6, 9, 10) prevent 80% of common breaches
  • Continuous compliance monitoring creates predictable monthly recurring revenue for MSPs
  • AI-powered assessments map client posture to all 56 IG1 safeguards in under 10 minutes

Why This Matters

Every MSP has this conversation eventually: the prospect asks "what framework do you follow?" and the answer determines whether you sound like a credible security partner or another box-pusher. Without a framework, security conversations devolve into feature comparisons and price wars. You end up competing on the cost of endpoint protection instead of the value of a structured security program.

CIS Controls v8 changes the dynamic. It gives you an industry-recognized standard that structures assessments, legitimizes proposals, and creates a natural upsell path from basic hygiene to advanced security operations. Most cyber insurance carriers reference it in their underwriting criteria -- your clients need it whether they know it or not.

18 Controls
Prioritized CIS safeguards covering every major attack vector across all client sizes

What Are CIS Controls v8?

CIS Controls v8 is a prioritized set of 18 cybersecurity controls maintained by the Center for Internet Security, designed to reduce the most common attack vectors through specific, actionable safeguards.

CIS Controls v8 is particularly well-suited for MSPs because the prescriptive structure maps directly to service delivery. Here is why it stands apart:

  • It is prescriptive. Unlike NIST CSF, which tells you what to achieve, CIS Controls tell you what to do -- that maps directly to billable service delivery.
  • It scales with client maturity. Implementation Groups (IG1, IG2, IG3) let you match controls to client size and risk profile without reinventing your methodology.
  • It aligns with cyber insurance. Most carriers reference CIS Controls in their underwriting criteria -- demonstrating IG1 compliance often reduces premiums.
  • It is free. No licensing fees, no certifications required to reference it. You can build your entire practice around it at zero framework cost.

The Three CIS Implementation Groups Explained

Implementation Groups define which safeguards apply based on an organization's size, resources, and risk profile.

Implementation Group Cumulative Safeguards Target Organization Focus
IG1 56 All organizations (essential cyber hygiene) Prevent the most common attacks
IG2 130 Organizations with dedicated IT staff or regulated industries Vulnerability management, monitoring, incident response
IG3 153 Organizations handling sensitive data or facing sophisticated threats Advanced security operations, penetration testing

IG1: Essential Cyber Hygiene (56 Safeguards)

IG1 is the minimum security baseline every client should meet regardless of size or industry.

This is your starting point for every engagement. The 56 safeguards in IG1 prevent the vast majority of common attacks and map directly to services you are likely already delivering. Key controls within IG1 include:

  • Control 1 -- Inventory and Control of Enterprise Assets. You cannot protect what you do not know about. Asset inventory is where every engagement starts.
  • Control 3 -- Data Protection. Classify data, encrypt sensitive information, manage data lifecycle.
  • Control 4 -- Secure Configuration. Harden default configurations on all devices and software.
  • Control 5 -- Account Management. Enforce least privilege, disable dormant accounts, require MFA.
  • Control 6 -- Access Control Management. Role-based access, centralized authentication.
  • Control 8 -- Audit Log Management. Collect, review, and retain logs -- this is where most small businesses fail entirely.
  • Control 9 -- Email and Web Browser Protections. DNS filtering, email authentication (SPF, DKIM, DMARC), attachment sandboxing.
  • Control 10 -- Malware Defenses. Endpoint protection with centralized management.
  • Control 11 -- Data Recovery. Tested backups with defined RPO and RTO.
  • Control 14 -- Security Awareness Training. Regular phishing simulations and security education.
56 Safeguards
IG1 essential hygiene controls every small business client must meet to stop common breaches

IG2: Enterprise Security (130 Total Safeguards)

IG2 adds 74 safeguards for organizations with dedicated IT staff or regulatory compliance requirements.

This layer adds vulnerability management with regular scanning, network monitoring and segmentation, incident response procedures, penetration testing, and application software security. IG2 is your natural upsell path when a client outgrows basic hygiene -- and the framework does the selling for you.

IG3: Advanced Security Operations (153 Total Safeguards)

IG3 adds 23 safeguards for organizations handling highly sensitive data or facing sophisticated threat actors.

Think financial services, healthcare, and defense contractors. Organizations requiring SOC 2 Type II, HIPAA compliance, or CMMC certification typically need IG3-level controls -- making this your premium service tier.


"Without a framework, security conversations devolve into feature comparisons and price wars. CIS Controls v8 changes the dynamic -- it legitimizes every recommendation because you are mapping to an industry standard, not selling your opinion."

How to Turn CIS Controls Into an MSP Service Model

The most effective MSP service models use CIS Controls as both the assessment framework and the recurring revenue structure.

Step 1: Assess Every Client Against IG1

Start every new client relationship with an IG1 assessment. Map their current state against all 56 safeguards and score each as Implemented, Partially Implemented, or Not Implemented. This assessment becomes your proposal -- the gaps are your scope of work.

The framework legitimizes every recommendation. You are not upselling your opinion, you are mapping to a standard that cyber insurance carriers, regulators, and security professionals all reference.

Step 2: Prioritize by Risk and Quick Wins

Not all controls carry equal weight. Prioritize based on impact and client visibility:

  1. Controls that prevent the most common attack vectors first. MFA (Controls 5/6), endpoint protection (Control 10), and email security (Control 9) stop 80% of breaches.
  2. Controls that satisfy cyber insurance requirements. Carriers consistently ask about MFA, backups, and patch management -- check these off early.
  3. Controls that demonstrate visible progress. Clients need to see results early. Quick wins build trust for the longer roadmap.

Step 3: Build Recurring Revenue Around Continuous Compliance

IG1 compliance is not a one-time project -- it requires continuous monitoring, regular reassessment, and ongoing adjustment. That is your managed services contract. Each monthly deliverable maps directly to a CIS safeguard, which means every report reinforces the value of your service.

Monthly Deliverable CIS Control Service Value
Asset inventory updates Control 1 Catch new/unauthorized devices
Patch compliance reports Control 7 Prove systems are current
Backup test results Control 11 Verify recovery capability
Security awareness metrics Control 14 Track training effectiveness
Log review summaries Control 8 Identify suspicious activity

Step 4: Upsell Through Implementation Groups

When a client outgrows IG1 -- through growth, regulatory changes, or cyber insurance requirements -- IG2 is your natural upsell path. The framework conversation sounds like this: "You have achieved IG1 compliance, which covers essential cyber hygiene. Your new contract requires IG2 controls, specifically vulnerability scanning, network segmentation, and incident response procedures -- here is what that looks like."


80% of Breaches
Stopped by MFA, endpoint protection, and email security controls in IG1 alone

Common CIS Controls Implementation Mistakes

The biggest implementation mistakes are treating CIS Controls as a checklist instead of an ongoing program.

Key Insight: The Three Mistakes That Sink CIS Implementations

  • Trying to implement all controls at once. Start with IG1. Get it solid. IG2 comes later -- attempting everything simultaneously creates paralysis and client frustration.
  • Treating it as a checklist instead of a program. Compliance is a continuous state, not a project milestone. Build it into your service delivery model, not a one-time engagement.
  • Ignoring Control 1 (Asset Inventory). Every other control depends on knowing what you are protecting. If the asset inventory is incomplete, everything built on top of it is unreliable.
  • Skipping Control 8 (Audit Logs). Logs are boring until you need them. Most small businesses have zero centralized logging -- this is both a critical security gap and an easy service to deliver.

How AI Helps MSPs Implement CIS Controls at Scale

AI reduces the time to assess a client against CIS Controls v8 from weeks to minutes, making framework-based security delivery economically viable for every client size.

We have seen MSPs spend 20-40 hours per client on manual IG1 assessments. That means the assessment alone costs more in labor than many clients pay per month for managed services. The economics simply do not work at that rate.

Under 10 Minutes
AI-powered assessment maps all 56 IG1 safeguards versus 20-40 hours of manual MSP labor

AI-powered assessment tools like jitCyber change that equation entirely. Here is what the technology delivers:

  • Automated framework mapping. AI maps client responses directly to all 56 IG1 safeguards without manual cross-referencing.
  • Adaptive questioning. Instead of asking 200 generic questions, AI asks the 15-20 questions that reveal the most about actual posture, adapting based on each answer.
  • Instant prioritization. AI generates prioritized remediation plans ranked by risk and effort -- not just a list of findings.
  • Consistent quality. Every assessment applies the same methodology. No analyst variability, no controls accidentally skipped.
  • Scale. One assessment engine handles 100 concurrent evaluations, turning assessments from a cost center into a lead generation tool.
"MSPs use it as a front-door tool -- prospects see their IG1 gaps before the first sales conversation, which means the proposal writes itself."

The AI Challenge Assessment at jitai.co/challenge maps client answers to CIS Controls v8 and delivers a prioritized remediation plan in under 10 minutes. Cyber audits start at $2,500 for businesses with 50 or fewer employees and $5,000 for businesses with up to 500 employees.


Terms and Glossary

Term Full Name What It Actually Means
CIS Center for Internet Security The nonprofit that maintains CIS Controls and CIS Benchmarks -- they write the playbook most of the industry follows.
CIS Controls v8 CIS Critical Security Controls version 8 18 prioritized security controls with 153 total safeguards. The current version released in 2021.
IG1 Implementation Group 1 The 56 essential cyber hygiene safeguards. If a client meets IG1, they are ahead of 90% of small businesses.
IG2 Implementation Group 2 130 cumulative safeguards for organizations with IT staff or regulatory requirements. Vulnerability scanning and incident response live here.
IG3 Implementation Group 3 153 cumulative safeguards for organizations handling sensitive data -- financial services, healthcare, defense.
NIST CSF National Institute of Standards and Technology Cybersecurity Framework Federal framework that describes security outcomes. CIS Controls map to NIST CSF but are more prescriptive.
MFA Multi-Factor Authentication Requiring a second verification beyond passwords. The single highest-impact control you can implement.
EDR Endpoint Detection and Response Real-time threat detection on devices. Replaced traditional antivirus for serious security programs.
SPF Sender Policy Framework Email authentication that prevents domain spoofing. One third of the email security trinity (SPF, DKIM, DMARC).
DKIM DomainKeys Identified Mail Cryptographic email authentication that proves an email was not altered in transit.
DMARC Domain-based Message Authentication, Reporting and Conformance The policy layer that tells receiving servers what to do when SPF or DKIM fails. Without DMARC, SPF and DKIM are suggestions.
RPO Recovery Point Objective How much data loss is acceptable, measured in time between backups.
RTO Recovery Time Objective How quickly systems must be restored after a failure.
SOC 2 Service Organization Control Type 2 An audit framework for service providers that evaluates security, availability, processing integrity, confidentiality, and privacy controls over time.
MSP Managed Service Provider A company that manages IT and security for other businesses on a recurring contract.

Frequently Asked Questions

What is the difference between CIS Controls v8 and NIST CSF?

CIS Controls v8 is prescriptive -- it tells you exactly what to do (e.g., "require MFA on all administrative accounts"). NIST CSF is descriptive -- it tells you what outcomes to achieve (e.g., "manage access permissions"). MSPs typically prefer CIS Controls for service delivery because the prescriptive nature maps directly to implementable actions.

How many CIS Controls do small businesses need to implement?

Small businesses should focus on IG1, which includes 56 safeguards across the 18 controls. IG1 represents essential cyber hygiene and addresses the attack methods used in over 80% of breaches. This is achievable for any organization regardless of size or budget.

Do cyber insurance carriers require CIS Controls compliance?

Most carriers do not require formal CIS certification, but they reference CIS Controls in underwriting questionnaires and risk assessments. Demonstrating IG1 compliance typically strengthens your application and can reduce premiums. Some carriers explicitly ask about specific controls like MFA, backup testing, and endpoint protection.

How long does it take to achieve IG1 compliance?

For a typical small business working with an MSP, achieving IG1 compliance takes 2-6 months depending on the starting point. Quick wins like MFA and endpoint protection can be implemented in days. Controls like comprehensive asset inventory and audit logging take longer to mature.

Can MSPs use CIS Controls as a sales tool?

Absolutely. The assessment-to-proposal pipeline is one of the strongest MSP sales motions. Assess the prospect against IG1, present the gaps as a prioritized remediation roadmap, and scope the managed services contract around continuous compliance monitoring -- the framework removes subjectivity from the conversation.

How often should CIS Controls assessments be repeated?

At minimum annually, but quarterly is better. Continuous compliance monitoring (monthly reports against key controls) is ideal and creates the recurring revenue that sustains MSP growth. Environment changes, new hires, software updates, and evolving threats all affect compliance status.

What is the relationship between CIS Controls and SOC 2?

CIS Controls v8 maps to several SOC 2 Trust Service Criteria, particularly the Security criterion. Implementing CIS Controls provides a strong foundation for SOC 2 readiness. Many organizations pursuing SOC 2 Type II use CIS Controls as their operational control framework.

How does AI change CIS Controls implementation for MSPs?

AI reduces the assessment phase from 20-40 hours of manual work per client to under 10 minutes of self-service evaluation. AI-powered tools map client responses to all 56 IG1 safeguards automatically, generate prioritized remediation plans, and produce consistent results at scale. This makes framework-based security delivery economically viable for clients of every size.


Ready to Map Your Clients to CIS Controls v8?

Not sure where to start with framework-based security delivery? Just In Time AI helps MSPs build CIS Controls-aligned practices powered by AI assessment technology. Take the AI Challenge Assessment at jitai.co/challenge to see how automated CIS Controls mapping works firsthand.

Cyber audits start at $2,500 for businesses with 50 or fewer employees and $5,000 for businesses with up to 500 employees.

Schedule a Free Discovery Call
Share:LinkedInTwitter
D

Dan Stolts

AI

Artificial Intelligence

The simulation of human intelligence processes by computer systems, including learning, reasoning, and self-correction.

LLM

Large Language Model

A machine-learning model trained on large text datasets to generate and understand human language. Examples: GPT-4, Claude, Gemini.

RAG

Retrieval-Augmented Generation

An architecture that augments a language model's response with documents retrieved from an external knowledge base, reducing hallucinations.

MCP

Model Context Protocol

An open protocol by Anthropic that standardises how AI models communicate with external tools, data sources, and services.

MSP

Managed Service Provider

A company that remotely manages a customer's IT infrastructure and end-user systems under a subscription model.

View full dictionary

Loading comments...

Leave a Comment