Available on the NC Cybersecurity Professional Services Contract
CIS Controls IG1 Foundation Program
Built for North Carolina public entities with lean IT teams
Most public entities do not need another tool. They need a documented baseline they can defend to a board, an auditor, and an insurance underwriter. The IG1 Foundation Program is a fixed-scope CIS IG1 assessment and policy engagement that delivers exactly that, built on real engagements with North Carolina community colleges and available under Category A of the NC Cybersecurity Professional Services Contract.
Fixed scope, fixed fee
Low burden on your staff
Vendor-neutral assessment
Purchasable on NC contract
What you get
What the CIS IG1 Assessment Program includes
Every engagement delivers the same seven items at a fixed fee. Nothing is scoped hourly and nothing is left open to interpretation.
- A CIS IG1 assessment and baseline report, built on CIS Controls v8.1, covering all 15 control categories and 56 safeguards
- A customized suite of approximately 20–22 security policies tailored to your organization, not a generic template pack
- A high-level procedural playbook detailing how each safeguard is implemented
- A prioritized remediation roadmap outlining what to fix first and why
- One executive or board briefing
- One consolidated review and revision cycle
- Six hours of follow-up advisory support
How it works
How it works with what you already have
We do not repeat work you have already paid for.
You have prior findings
National Guard, CSRF, audit, or penetration test
- We ingest those findings rather than duplicating them
- Results are mapped to the 56 IG1 safeguards
- Your earlier investment carries forward
You have no recent assessment
Starting from a clean sheet
- We establish the baseline from scratch
- Discovery is interview-driven and built for a lean IT team
- No prior documentation required to begin
EITHER WAY: the deliverable is the same. A documented, leadership-ready program.
Why teams choose it
Fixed scope. Low burden. No product agenda.
Fixed scope, fixed fee
No hourly drift. Pricing available on request.
Low burden on your staff
Interview-driven discovery tailored to a lean IT team.
Vendor-neutral
Our Advisory Services team focuses on assessment, not products.
Purchasable on contract
Scoped as an SOW under the NC Cybersecurity Professional Services Contract.
Frequently Asked Questions
Tego built the IG1 Foundation Program for North Carolina public entities with lean IT teams, such as community colleges, counties, and municipalities. These organizations need a documented security baseline but don't have the staff to build one from scratch. The program fits any organization that faces questions from a board, an auditor, or a cyber insurance underwriter and needs a clear, defensible answer.
A penetration test checks whether an attacker can exploit specific systems at a point in time. The IG1 Foundation Program looks at something different: whether the 56 foundational CIS safeguards are in place, documented, and governed by policy. It then delivers the policies, playbook, and roadmap to close the gaps. The two work well together, and Tego folds recent penetration test findings into the baseline.
Tego uses those findings as inputs rather than repeating the work. The team maps results from a prior National Guard assessment, CSRF review, audit, or penetration test to the IG1 safeguards. It then fills in whatever those reviews didn't cover and builds the policies and roadmap on top. Your earlier investment carries forward instead of being duplicated.
No formal preparation is required, but a few things help:Any prior assessment or audit reportsExisting security policies or proceduresA rough inventory of your systems and cloud servicesThe names of the people who manage IT, HR, and financeDiscovery is interview-driven, so Tego gathers the rest through conversations with your team.
The program identifies and prioritizes gaps, but it does not include hands-on remediation. The remediation roadmap ranks each gap by risk and effort, so your team knows what to fix first and why. You can handle remediation internally, with your current provider, or through a separate Statement of Work with Tego. The six hours of included advisory support can also help answer questions as the work begins.
Yes. IG1 is the foundation that CIS Implementation Groups 2 and 3 build on, so every safeguard, policy, and procedure from the program carries forward. The remediation roadmap and gap data also give your team a starting point for scoping IG2 work. That becomes relevant when your risk profile, data sensitivity, or regulatory obligations call for it.
Don't Panic
Ready to take the next step?
IG1 Foundation Program
See the full IG1 Foundation Program scope and fixed fee.
Buy It on Contract
Scoped as an SOW under the NC Cybersecurity Professional Services Contract.