CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) are a prioritized subset of IT and OT cybersecurity practices aimed at meaningfully reducing risk to critical infrastructure operations. Aligned with the NIST Cybersecurity Framework, CPGs provide a common set of protections that all critical infrastructure owners and operators can implement.
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 is a compliance framework from United States with 8 domains and 35 controls that map to 300 other frameworks. The largest domains are Device Security (8 controls), Account Security (6 controls), Data Security (4 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (8)
Account Security
Identity and access management, MFA, and credential protection
| Code | Title |
|---|---|
| CPG-1.A | Changing Default Passwords |
| CPG-1.B | Minimum Password Strength |
| CPG-1.C | Unique Credentials |
| CPG-1.D | Revoking Credentials for Departing Employees |
| CPG-1.E | Separating User and Privileged Accounts |
| CPG-1.F | Phishing-Resistant MFA |
Data Security
Device Security
| Code | Title |
|---|---|
| CPG-2.A | Asset Inventory |
| CPG-2.B | Prohibit Connection of Unauthorized Devices |
| CPG-2.C | Hardware and Software Approval Process |
| CPG-2.D | Disable Macros by Default |
| CPG-2.E | Document Device Configurations |
| CPG-2.F | No Exploitable Services on the Internet |
| CPG-2.G | Limit OT Connections to Public Internet |
| CPG-2.H | Document Network Topology |
Governance and Training
Leadership accountability, cyber risk management, and workforce training
Network Segmentation
Network architecture, segmentation, and email security
Response & Recovery
Supply Chain and Third Party
Supply chain risk management and vendor security
Vulnerability Management
Vulnerability discovery, patching, and known exploited vulnerability remediation
Your Compliance Coverage
If you comply with CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, you already cover:
ASD Strategies to Mitigate Cyber Security Incidents
37%
13 controls mapped
Compare →AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
37%
13 controls mapped
Compare →TISAX - Trusted Information Security Assessment Exchange
37%
13 controls mapped
Compare →+ 297 more: NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices (37%), NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements (34%)
See all 300 mapped frameworks ↓Maps to 300 other frameworks
What is CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 and who does it apply to?
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 is a compliance framework from United States with 8 domains and 35 controls. CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) are a prioritized subset of IT and OT cybersecurity practices aimed at meaningfully reducing risk to critical infrastructure operations. Aligned with the NIST Cybersecurity Framework, CPGs provide a common set of protections that all critical infrastructure owners and operators can implement. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 actually require?
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 has 35 controls organised across 8 domains. The largest domains are Device Security (8 controls), Account Security (6 controls), Data Security (4 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 do I already cover?
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 maps to 300 other compliance frameworks. The top mapping partners are ASD Strategies to Mitigate Cyber Security Incidents (37% coverage), AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (37% coverage), TISAX - Trusted Information Security Assessment Exchange (37% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0?
Start your CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 35 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required