CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) are a prioritized subset of IT and OT cybersecurity practices aimed at meaningfully reducing risk to critical infrastructure operations. Aligned with the NIST Cybersecurity Framework, CPGs provide a common set of protections that all critical infrastructure entities should implement. Version 2.0 organizes goals across 8 practice areas.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Account Security
Identity and access management, MFA, and credential protection
| Code | Title |
|---|---|
| CPG-1.A | Default Password Change |
| CPG-1.B | Minimum Password Strength |
| CPG-1.C | Multi-Factor Authentication for Privileged Users |
| CPG-1.D | Multi-Factor Authentication for Remote Access |
| CPG-1.E | Unique Credentials |
| CPG-1.F | Revoke Credentials for Departing Employees |
Data Security
Data protection, encryption, and information handling
| Code | Title |
|---|---|
| CPG-3.A | Encrypt Sensitive Data at Rest |
| CPG-3.B | Encrypt Sensitive Data in Transit |
| CPG-3.C | Secure Sensitive Data Collection |
| DS-1 | Security Safeguards |
| DS-2 | Third-Party Data Sharing Controls |
| DS-3 | Breach Response Procedures |
| HUN-10 | Security Obligations |
| HUN-11 | Data Transfer Registry |
Device Security
Asset management, endpoint protection, and secure configuration
| Code | Title |
|---|---|
| CPG-2.A | Asset Inventory (Hardware) |
| CPG-2.B | Asset Inventory (Software) |
| CPG-2.C | Disable Macros by Default |
| CPG-2.D | Approved Software and Hardware Only |
| CPG-2.E | Prohibit Internet-Connected OT Assets |
| CPG-2.F | Log Collection and Centralization |
Governance and Training
Leadership accountability, cyber risk management, and workforce training
| Code | Title |
|---|---|
| CPG-4.A | Organizational Cybersecurity Leadership |
| CPG-4.B | OT Cybersecurity Leadership |
| CPG-4.C | Cybersecurity Awareness Training |
| CPG-4.D | OT-Specific Cybersecurity Training |
Network Segmentation
Network architecture, segmentation, and email security
| Code | Title |
|---|---|
| CPG-8.A | Network Segmentation |
| CPG-8.B | Email Security (DMARC) |
| CPG-8.C | Encrypted DNS |
Response and Recovery
Incident response planning, exercises, and business continuity
| Code | Title |
|---|---|
| BMA-12 | Incident Response Plan |
| BMA-13 | Business Continuity and Recovery |
| BMA-14 | Cyber Insurance |
| CPG-7.A | Incident Response Plan |
| CPG-7.B | Incident Reporting to CISA |
| CPG-7.C | System Backups |
| CPG-7.D | Incident Response Testing |
Supply Chain and Third Party
Supply chain risk management and vendor security
| Code | Title |
|---|---|
| CPG-6.A | Vendor/Supplier Cybersecurity Requirements |
| CPG-6.B | Supply Chain Incident Reporting |
Vulnerability Management
Vulnerability discovery, patching, and known exploited vulnerability remediation
| Code | Title |
|---|---|
| CPG-5.A | Known Exploited Vulnerability Remediation |
| CPG-5.B | Deploy Security Updates |
| CPG-5.C | No Exploitable Services on the Internet |
| CPG-5.D | Vulnerability Disclosure Program |
Maps to 638 other frameworks
Frequently Asked Questions
What is CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0?
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 is a compliance framework from United States with 8 domains and 40 controls. CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) are a prioritized subset of IT and OT cybersecurity practices aimed at meaningfully reducing risk to critical infrastructure operations. Aligned with the NIST Cybersecurity Framework, CPGs provide a common set of protections that all critical infrastructure entities should implement. Version 2.0 organizes goals across 8 practice areas. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 have?
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 has 40 controls organised across 8 domains. The largest domains are Data Security (8 controls), Response and Recovery (7 controls), Account Security (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 map to?
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 maps to 638 other compliance frameworks. The top mapping partners are CSA CCM v4 (57% coverage), TISAX — Trusted Information Security Assessment Exchange (57% coverage), FAA Cybersecurity Framework for Aviation (53% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 compliance?
Start your CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 40 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 692 frameworks.
Get Started Free →Free forever — no credit card required