Available on the NC Cybersecurity Professional Services Contract

CIS Controls IG1 Foundation Program

Built for North Carolina public entities with lean IT teams
Most public entities do not need another tool. They need a documented baseline they can defend to a board, an auditor, and an insurance underwriter. The IG1 Foundation Program is a fixed-scope CIS IG1 assessment and policy engagement that delivers exactly that, built on real engagements with North Carolina community colleges and available under Category A of the NC Cybersecurity Professional Services Contract.
Fixed scope, fixed fee
Low burden on your staff
Vendor-neutral assessment
Purchasable on NC contract
What you get

What the CIS IG1 Assessment Program includes

Every engagement delivers the same seven items at a fixed fee. Nothing is scoped hourly and nothing is left open to interpretation.
  • A CIS IG1 assessment and baseline report, built on CIS Controls v8.1, covering all 15 control categories and 56 safeguards
  • A customized suite of approximately 20–22 security policies tailored to your organization, not a generic template pack
  • A high-level procedural playbook detailing how each safeguard is implemented
  • A prioritized remediation roadmap outlining what to fix first and why
  • One executive or board briefing
  • One consolidated review and revision cycle
  • Six hours of follow-up advisory support
How it works

How it works with what you already have

We do not repeat work you have already paid for.

You have prior findings

National Guard, CSRF, audit, or penetration test

You have no recent assessment

Starting from a clean sheet
EITHER WAY: the deliverable is the same. A documented, leadership-ready program.
Why teams choose it

Fixed scope. Low burden. No product agenda.

Fixed scope, fixed fee
No hourly drift. Pricing available on request.
Low burden on your staff
Interview-driven discovery tailored to a lean IT team.
Vendor-neutral
Our Advisory Services team focuses on assessment, not products.
Purchasable on contract
Scoped as an SOW under the NC Cybersecurity Professional Services Contract.

Frequently Asked Questions

Tego built the IG1 Foundation Program for North Carolina public entities with lean IT teams, such as community colleges, counties, and municipalities. These organizations need a documented security baseline but don't have the staff to build one from scratch. The program fits any organization that faces questions from a board, an auditor, or a cyber insurance underwriter and needs a clear, defensible answer.
A penetration test checks whether an attacker can exploit specific systems at a point in time. The IG1 Foundation Program looks at something different: whether the 56 foundational CIS safeguards are in place, documented, and governed by policy. It then delivers the policies, playbook, and roadmap to close the gaps. The two work well together, and Tego folds recent penetration test findings into the baseline.
Tego uses those findings as inputs rather than repeating the work. The team maps results from a prior National Guard assessment, CSRF review, audit, or penetration test to the IG1 safeguards. It then fills in whatever those reviews didn't cover and builds the policies and roadmap on top. Your earlier investment carries forward instead of being duplicated.
No formal preparation is required, but a few things help:Any prior assessment or audit reportsExisting security policies or proceduresA rough inventory of your systems and cloud servicesThe names of the people who manage IT, HR, and financeDiscovery is interview-driven, so Tego gathers the rest through conversations with your team.
The program identifies and prioritizes gaps, but it does not include hands-on remediation. The remediation roadmap ranks each gap by risk and effort, so your team knows what to fix first and why. You can handle remediation internally, with your current provider, or through a separate Statement of Work with Tego. The six hours of included advisory support can also help answer questions as the work begins.
Yes. IG1 is the foundation that CIS Implementation Groups 2 and 3 build on, so every safeguard, policy, and procedure from the program carries forward. The remediation roadmap and gap data also give your team a starting point for scoping IG2 work. That becomes relevant when your risk profile, data sensitivity, or regulatory obligations call for it.
Don't Panic

Ready to take the next step?

IG1 Foundation Program

See the full IG1 Foundation Program scope and fixed fee.

Buy It on Contract

Scoped as an SOW under the NC Cybersecurity Professional Services Contract.