CIS Controls v8.1 for Small Business: How Canadian SMBs Can Build a Real Cybersecurity Program (2026)

Tags:

Written by Mike Pearlstein, CISSP, CEO of Fusion Computing Limited. Helping Canadian businesses build and manage secure IT infrastructure since 2012 across Toronto, Hamilton, and Metro Vancouver.

Most Canadian SMBs do not need a new security framework. They need an opinionated checklist they can finish. CIS Controls v8.1, published by the Center for Internet Security, is that checklist: 18 Controls, 153 Safeguards, and three Implementation Groups that decide which Safeguards apply to a business your size.

It is free, it gives the PIPEDA safeguards principle something auditable to point at, and it answers most of a 2026 cyber insurance renewal. Firms wanting a federally recognized badge can layer CyberSecure Canada certification on top, because its control areas overlap heavily with IG1. This playbook covers what to adopt, in what order, and what evidence to keep.

Key Takeaways

  • CIS Controls v8.1 defines 18 Controls and 153 Safeguards. The Safeguards, not the Controls, are what get assigned to Implementation Groups.
  • IG1 is 56 Safeguards drawn from 15 of the 18 Controls. Controls 13, 16 and 18 contribute no IG1 Safeguards at all.
  • Implementation Groups are cumulative: IG2 brings the running total to 130 Safeguards, and IG3 covers all 153.
  • The Canadian anchor is the federal Baseline Cyber Security Controls for Small and Medium Organizations, scoped to organizations under 500 employees, which lands in the same territory as IG1.
  • Bill C-8 received Royal Assent on June 15, 2026, enacting the Critical Cyber Systems Protection Act for designated federally regulated operators.

Book a Free IT Business Consultation

What are CIS Controls v8.1, and why do Canadian SMBs adopt them?

CIS Controls v8.1 gives Canadian SMBs a prioritized security checklist: 18 Controls broken into 153 Safeguards, sorted into three Implementation Groups, with the 56 Safeguards of IG1 as the practical starting point. Fusion Computing deploys IG1 as a managed package over roughly 90 days, producing the evidence that cyber insurers, acquirers and PIPEDA reviews ask for.

CIS Controls v8.1 is the 2024 refresh of the Controls published by the Center for Internet Security (2024). CIS describes the release as adding the Govern security function from NIST CSF 2.0, revising asset classes, and rewriting Safeguard descriptions. The count of Controls and Safeguards did not change from v8.

Canadian SMBs adopt v8.1 because it is prescriptive where NIST CSF 2.0 (2024) is descriptive. CSF tells leadership which outcomes to govern. CIS tells the engineer what to configure on Monday morning. Most of our clients report upward in CSF language while operating in CIS Safeguards.

The 18 CIS Controls grouped into Implementation Groups (IG1, IG2, IG3)

According to the CIS Controls Navigator (2024), every one of the 18 Controls can be filtered by Implementation Group. Controls 1 and 11 carry 5 Safeguards each; Control 16 carries 14. That spread is why counting Controls tells you nothing useful about scope, and counting Safeguards inside your chosen Implementation Group tells you everything.

Implementation Groups scope the framework to organizational risk. IG1 is what CIS calls essential cyber hygiene, aimed at smaller organizations with limited security expertise. IG2 suits organizations with staff dedicated to managing risk. IG3 is for those employing security specialists across disciplines.

# CIS Control (official name) IG1 Safeguards? IG2 IG3
1 Inventory and Control of Enterprise Assets Yes Yes Yes
2 Inventory and Control of Software Assets Yes Yes Yes
3 Data Protection Yes Yes Yes
4 Secure Configuration of Enterprise Assets and Software Yes Yes Yes
5 Account Management Yes Yes Yes
6 Access Control Management Yes Yes Yes
7 Continuous Vulnerability Management Yes Yes Yes
8 Audit Log Management Yes Yes Yes
9 Email and Web Browser Protections Yes Yes Yes
10 Malware Defenses Yes Yes Yes
11 Data Recovery Yes Yes Yes
12 Network Infrastructure Management Yes Yes Yes
13 Network Monitoring and Defense None Yes Yes
14 Security Awareness and Skills Training Yes Yes Yes
15 Service Provider Management Yes Yes Yes
16 Application Software Security None Yes Yes
17 Incident Response Management Yes Yes Yes
18 Penetration Testing None Yes Yes

Read that table as coverage, not effort. Because the groups are cumulative, all 18 Controls appear at IG2 and IG3; what changes is how many Safeguards inside each Control you owe. The three with no IG1 Safeguards are 13, 16 and 18, the correct deferral for an SMB with no 24/7 monitoring desk, no in-house developers, and no annual pentest budget.

What is a CIS Safeguard? Control vs Safeguard vs Implementation Group

A CIS Control is a theme, such as Data Recovery. A CIS Safeguard is one specific, testable action inside that theme, such as establishing and maintaining a data recovery process. An Implementation Group is a difficulty tier applied to Safeguards. Getting this wrong is the single most common error I see in vendor marketing, and it makes scope conversations impossible.

The practical consequence is simple. Nobody implements a Control. You implement Safeguards, you document Safeguards, and an insurer scores Safeguards. A proposal promising the 18 Controls with no Safeguard count and no Implementation Group named has not been scoped.

Cumulative CIS Controls v8.1 Safeguard counts by Implementation Group. IG1 covers 56 Safeguards, IG2 covers 130 Safeguards cumulatively, and IG3 covers all 153 Safeguards. Safeguards in scope, cumulative (v8.1) IG1 56 IG2 130 IG3 153 Source: Center for Internet Security, CIS Controls v8.1.

Why most Canadian SMBs target IG1 first

The Canadian Centre for Cyber Security (2020) publishes Baseline Cyber Security Controls for Small and Medium Organizations, a 13-control document scoped to organizations with fewer than 500 employees. It is deliberately an 80/20 baseline, and it lands in the same territory as CIS IG1: inventory, patching, MFA, backups, training and incident response.

IG1 is the realistic floor and the right starting line. It lines up with the federal baseline above, it closes most of a 2026 cyber insurance questionnaire, and my team can operate it end to end without a dedicated security analyst on the client payroll.

[CONTRARIAN THESIS] Where the two documents differ. The federal baseline is shorter and older than CIS IG1, and it is not a Safeguard-for-Safeguard match. IG1 goes further on data classification, service provider management and audit logging. Treat the baseline as the floor a Canadian regulator or grant program will recognise, and IG1 as the operating standard that satisfies it.

IG2 makes operational sense once a Canadian SMB crosses three thresholds: a vCISO relationship, centralized logging that somebody reads, and a documented annual penetration testing cadence. Below those thresholds, IG2 spend produces shelfware. Above them, it produces a defensible audit trail.

IG3 is rarely the right scope below 500 users. The exception is a smaller business serving critical infrastructure or holding regulated data at scale, where contractual terms force the deeper Safeguards regardless of headcount. If you are unsure which tier your contracts actually oblige, have us read the security schedule with you.

The 6 highest-impact CIS controls for Canadian SMBs

According to the Canadian Centre for Cyber Security (2025), ransomware is the top cybercrime threat facing Canadian critical infrastructure, incidents grew an average of 26 percent year over year between 2021 and 2024, and the average ransom paid in Canada in 2023 reached CA$1.13 million. The six Controls below are the ones that break that specific chain.

Inside IG1, six Controls carry most of the load. They close the bulk of an insurance questionnaire, they interrupt the credential-theft and encryption path ransomware actually uses, and they produce the cleanest artifacts when a regulator asks.

CIS Control What we deploy Effort Evidence it produces
1. Inventory and Control of Enterprise Assets Managed monitoring agent and network discovery 2 weeks Live device register with unmanaged exceptions flagged
5. Account Management Microsoft Entra ID joiner, mover, leaver workflow 2 weeks Dormant and orphaned account report
6. Access Control Management Entra ID Conditional Access and Intune compliance 3 weeks MFA coverage percentage by account type
10. Malware Defenses Managed endpoint detection and response, monitored 24/7 2 weeks Endpoint coverage report and detection timeline
11. Data Recovery Immutable backup with scheduled restore tests 3 weeks Dated restore-test results, not backup job logs
14. Security Awareness and Skills Training Monthly module and quarterly phishing simulation Ongoing Completion rates and phish-prone trend by department

[ORIGINAL DATA] Fusion Computing benchmark. Across our 60+ Canadian SMB security engagements, we measured which IG1 Safeguard fails first at intake. Asset inventory failed in the clear majority of environments, and restore testing failed almost as often. Backups existed nearly everywhere; a dated restore test almost nowhere. Underwriters increasingly ask for the second artifact, not the first.

Mapping CIS Controls to what PIPEDA, Bill C-8, OSFI E-21 and cyber insurance require

According to PIPEDA (2000), organizations must protect personal information with safeguards appropriate to its sensitivity. The statute never names a technology. CIS turns that principle into line items an auditor can test, which is why the mapping below is what underwriters and privacy officers actually ask to see.

Regulator or instrument Core requirement Mapped CIS Controls
PIPEDA Safeguards proportional to sensitivity, breach reporting 3, 6, 8, 11, 17
CCSPA (from Bill C-8) Cyber program, incident reporting, supplier risk (designated operators) 1, 5, 6, 8, 15, 17
OSFI Guideline E-21 Operational resilience, third-party risk, recovery (federally regulated financial institutions) 11, 15, 17
Cyber insurance (2026 renewals) MFA, EDR, immutable backup, IR plan, training 5, 6, 9, 10, 11, 14, 17
Federal SMB baseline Federal baseline for organizations under 500 employees Most of IG1

Bill C-8 (2026) received Royal Assent on June 15, 2026 and is now Statutes of Canada 2026, chapter 9. It enacts the Critical Cyber Systems Protection Act. The Telecommunications Act amendments took effect on assent, while the CCSPA duties on designated operators come into force by order in council.

That distinction matters for scoping. No coming-into-force order had been made as of late July 2026, and the schedule listing designated operator classes was still empty. Very few SMBs will be designated operators. Most will feel the Act second-hand, through supplier questionnaires that regulated clients send down the chain.

OSFI Guideline E-21 (2024) on Operational Risk Management and Resilience binds federally regulated financial institutions, not a typical SMB. It reaches SMBs indirectly, as a third-party expectation flowed down from a bank or insurer client.

The 90-day CIS IG1 rollout plan: steps, owners, and evidence

An IG1 rollout for a 50 to 150 user Canadian SMB takes 90 to 120 days when an experienced MSP runs it. Sequence is close to non-negotiable: inventory before tooling, identity before endpoints, and a verified restore before any other recovery work. Every phase below has to end in an artifact, because an unevidenced Safeguard scores zero with an underwriter.

Phase CIS Controls Duration Owner
1. Asset and software inventory 1, 2, 15 Weeks 1 to 3 MSP plus owner
2. Identity hardening 5, 6 Weeks 3 to 6 MSP
3. Endpoint and email defenses 9, 10, 12 Weeks 5 to 8 MSP
4. Patch and configuration baseline 4, 7 Weeks 6 to 10 MSP
5. Backup and tested restore 3, 11 Weeks 8 to 12 MSP
6. Training, IR plan, tabletop 14, 17 Weeks 10 to 13 MSP plus leadership

The blocker I hit most often is not technical. It is the Phase 1 data classification workshop that establishes where regulated data actually lives. Skip it and Phases 5 and 6 protect the wrong files with real diligence.

Tools FC deploys per CIS control

Our toolset is deliberately narrow, because operational overhead has to stay predictable across dozens of client tenants. We describe it here by capability rather than by product name, since the Safeguard is what gets audited and the vendor behind it is an implementation detail we reserve the right to change.

Stack at a glance. Identity and device compliance: Microsoft Entra ID with Microsoft Intune, which carries Controls 4, 5 and 6. Endpoint: managed detection and response for Control 10.

Asset, software and patch: a managed monitoring and management platform, which owns Controls 1, 2 and 7. Data classification: Microsoft Purview for Control 3. Backup: an immutable platform with tested restore, which satisfies Control 11. Network edge and awareness training round out Controls 12 and 14.

Each capability maps to named Safeguards so audit evidence falls out of the tooling rather than a hand-maintained spreadsheet. That is the design goal. When an underwriter asks for MFA coverage, our engineers found it faster to export a live figure from Entra ID than to reconstruct one at renewal.

“The question I get asked is which product we install. The question that decides a renewal is which Safeguard the client can evidence on demand. I have watched a clean 56-Safeguard IG1 posture with dated artifacts beat a far more expensive stack that nobody could produce a report from.”

Mike Pearlstein, CISSP, CEO, Fusion Computing

Packaged this way, managed cybersecurity sits at CA$180 to CA$250+ per user per month for most Canadian SMBs, on top of managed IT from CA$180 per user per month. Regulatory load and data sensitivity decide where a client lands in that band. These are term agreements, because a 90-day IG1 rollout cannot be delivered inside a 30-day commitment. Ask us to scope your IG1 gap before you budget a number.

For the same stack described by capability rather than by control number, see the software and tools behind Fusion’s managed IT.

Common CIS adoption mistakes

Three mistakes sink CIS programs faster than budget pressure does: buying tools before the inventory is finished, treating Control 8 logging as IG1-depth work, and writing an incident response plan that never gets rehearsed. Each one is cheap to avoid at the planning stage and expensive to unwind at month four of a rollout.

The first is buying before counting. Endpoint detection on an unknown endpoint is theatre, and unmanaged laptops are still the most common gap I find at intake.

The second is over-reading Control 8. IG1 asks for basic, collected audit logs. Chasing SIEM-grade central logging without the IG2 staffing model to read it produces alert fatigue and a line item you cannot defend at budget time. Defer Control 8 depth to the IG2 phase.

Third, skipping the tabletop. Control 17 is an exercise, not a document. A plan never walked through with leadership produces false confidence at the worst possible moment. I run the tabletop annually and again after any meaningful change in the leadership team.

Get a CIS-Aligned IT Business Consultation

Free download

The Network Security Controls Checklist (2026)

You have just read the six IG1 Controls that carry a renewal questionnaire and the 90-day order they go in. This checklist turns that sequence into verifiable yes/no lines covering inventory, identity, endpoint, patching, backup, and tabletop, so you can score your own network before an underwriter does.

No sales call required. Want your IG1 gaps scored against your live environment by a CISSP-led team? Book a consultation.

Frequently asked questions

Is CIS Controls v8.1 free to use?

Yes. The Center for Internet Security publishes CIS Controls v8.1 at no charge under a Creative Commons licence. The download includes all 18 Controls, the 153 Safeguards, the Implementation Group mappings, and the CIS Controls Self Assessment Tool. Cost for tooling, MSP delivery and staff time is separate.

How is CIS v8.1 different from CIS v8?

v8.1 (2024) refines v8 (2021) rather than replacing it. The 18 Controls, the 153 Safeguards and the three Implementation Groups are unchanged. v8.1 adds the Govern security function from NIST CSF 2.0, revises asset classes, and rewrites Safeguard descriptions. SMBs on v8 refresh mapping documents rather than re-implementing.

What is the difference between a CIS Control and a CIS Safeguard?

A Control is one of 18 thematic groupings, such as Control 11 Data Recovery. A Safeguard is a specific testable action inside it, and there are 153 of them. Implementation Groups apply to Safeguards, not Controls, which is why IG1 is described as 56 Safeguards rather than as a number of Controls.

Does CIS v8.1 satisfy PIPEDA?

CIS IG1 covers the technical and procedural safeguard portion of PIPEDA when paired with a written privacy policy and a breach response procedure. PIPEDA also requires consent management, accountability and access-request handling, which sit outside CIS scope. Treat IG1 as the security half.

How long does an IG1 deployment take?

Typical IG1 deployments for Canadian SMBs run 90 to 120 days with an experienced MSP. Faster is possible when asset and identity inventory is already clean. Slower happens when legacy infrastructure needs migration before the 56 Safeguards can attach to anything.

Do I need a vCISO if I implement CIS IG1?

For most SMBs under 150 users on IG1, a vCISO is optional and mainly useful for board reporting and insurance renewal narratives. IG2 makes one functionally required, because of the audit, incident response and penetration testing programs that enter scope at that tier.

Can my existing MSP run CIS v8.1?

Some can and many cannot. Ask for three artifacts: a redacted CIS Controls Self Assessment Tool output, a written split of which Safeguards they own versus which you own, and the cadence at which they re-score posture. If those do not exist, the program is not running.

Will my cyber insurer accept CIS v8.1 as evidence?

Canadian carriers do not certify against CIS. They do accept CIS posture documentation as supporting evidence on renewal questionnaires. The strongest renewal package is a CIS Self Assessment export, a current asset inventory, an MFA coverage report, an endpoint coverage report, and the most recent tabletop after-action report.

What about CIS Benchmarks vs CIS Controls?

Different artifacts from the same publisher. CIS Controls v8.1 are the program framework covering what to do. CIS Benchmarks are configuration baselines for specific products, covering how to harden Windows Server or Microsoft 365. A CIS-aligned program uses Controls as the program and Benchmarks as the standard for Control 4.

Does Bill C-8 require CIS Controls?

No. Bill C-8 received Royal Assent on June 15, 2026 and enacts the Critical Cyber Systems Protection Act, but names no framework. It obligates designated operators to run a documented cyber program, report incidents and manage supplier risk. CIS IG1 or IG2, mapped to NIST CSF 2.0, meets that expectation for most in-scope SMB suppliers.

Related Resources

Fusion Computing has provided managed IT, cybersecurity, and AI consulting to Canadian businesses since 2012. Fusion’s CISSP-led team supports organizations with 15 to 200+ users across Toronto, Hamilton, and Metro Vancouver.

93% of issues resolved on the first call. Named one of Canada’s 50 Best Managed IT Companies two years running.

100 King Street West, Suite 5700
Toronto, ON M5X 1C7
(416) 566-2845
1 888 541 1611