CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) are a prioritized subset of IT and OT cybersecurity practices aimed at meaningfully reducing risk to critical infrastructure operations. Aligned with the NIST Cybersecurity Framework, CPGs provide a common set of protections that all critical infrastructure entities should implement. Version 2.0 organizes goals across 8 practice areas.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Account Security
| Code | Title |
|---|---|
| CPG-1.A | Changing Default Passwords |
| CPG-1.B | Minimum Password Strength |
| CPG-1.C | Unique Credentials |
| CPG-1.D | Revoking Credentials for Departing Employees |
| CPG-1.E | Separating User and Privileged Accounts |
| CPG-1.F | Phishing-Resistant MFA |
Account Security
Identity and access management, MFA, and credential protection
| Code | Title |
|---|---|
| CPG-1.A | Changing Default Passwords |
| CPG-1.B | Minimum Password Strength |
| CPG-1.C | Unique Credentials |
| CPG-1.D | Revoking Credentials for Departing Employees |
| CPG-1.E | Separating User and Privileged Accounts |
| CPG-1.F | Phishing-Resistant MFA |
Data Security
| Code | Title |
|---|---|
| CPG-3.A | Log Collection |
| CPG-3.B | Secure Log Storage |
| CPG-3.C | Strong and Agile Encryption |
| CPG-3.D | Secure Sensitive Data |
| DS-1 | Security Safeguards |
| DS-2 | Ensure Inventory of Software Components in Code |
| DS-3 | Breach Response Procedures |
| HUN-10 | Security Obligations |
| HUN-11 | Data Transfer Registry |
Data Security
Data protection, encryption, and information handling
| Code | Title |
|---|---|
| CPG-3.A | Log Collection |
| CPG-3.B | Secure Log Storage |
| CPG-3.C | Strong and Agile Encryption |
| CPG-3.D | Secure Sensitive Data |
| DS-1 | Security Safeguards |
| DS-2 | Ensure Inventory of Software Components in Code |
| DS-3 | Breach Response Procedures |
| HUN-10 | Security Obligations |
| HUN-11 | Data Transfer Registry |
Device Security
| Code | Title |
|---|---|
| CPG-2.A | Asset Inventory |
| CPG-2.B | Prohibit Connection of Unauthorized Devices |
| CPG-2.C | Hardware and Software Approval Process |
| CPG-2.D | Disable Macros by Default |
| CPG-2.E | Document Device Configurations |
| CPG-2.F | No Exploitable Services on the Internet |
| CPG-2.G | Limit OT Connections to Public Internet |
| CPG-2.H | Document Network Topology |
Device Security
Asset management, endpoint protection, and secure configuration
| Code | Title |
|---|---|
| CPG-2.A | Asset Inventory |
| CPG-2.B | Prohibit Connection of Unauthorized Devices |
| CPG-2.C | Hardware and Software Approval Process |
| CPG-2.D | Disable Macros by Default |
| CPG-2.E | Document Device Configurations |
| CPG-2.F | No Exploitable Services on the Internet |
| CPG-2.G | Limit OT Connections to Public Internet |
| CPG-2.H | Document Network Topology |
Governance & Training
| Code | Title |
|---|---|
| CPG-4.A | Organizational Cybersecurity Leadership |
| CPG-4.B | OT Cybersecurity Leadership |
| CPG-4.C | Basic Cybersecurity Training |
Governance and Training
Leadership accountability, cyber risk management, and workforce training
| Code | Title |
|---|---|
| CPG-4.A | Organizational Cybersecurity Leadership |
| CPG-4.B | OT Cybersecurity Leadership |
| CPG-4.C | Basic Cybersecurity Training |
| CPG-4.D | OT-Specific Cybersecurity Training |
Network Segmentation
Network architecture, segmentation, and email security
| Code | Title |
|---|---|
| CPG-8.A | Network Segmentation |
| CPG-8.B | Email Security (DMARC) |
| CPG-8.C | Encrypted DNS |
Response & Recovery
| Code | Title |
|---|---|
| CPG-7.A | Incident Reporting |
| CPG-7.B | Incident Response Plans |
| CPG-7.C | System Backups |
Response and Recovery
Incident response planning, exercises, and business continuity
| Code | Title |
|---|---|
| BMA-12 | Incident Response Plan |
| BMA-13 | Business Continuity and Recovery |
| BMA-14 | Cyber Insurance |
| CPG-7.A | Incident Reporting |
| CPG-7.B | Incident Response Plans |
| CPG-7.C | System Backups |
| CPG-7.D | Incident Response Testing |
Supply Chain
| Code | Title |
|---|---|
| CPG-6.A | Vendor and Supplier Incident Reporting |
Supply Chain and Third Party
Supply chain risk management and vendor security
| Code | Title |
|---|---|
| CPG-6.A | Vendor and Supplier Incident Reporting |
| CPG-6.B | Supply Chain Incident Reporting |
Vulnerability Management
| Code | Title |
|---|---|
| CPG-5.A | Vulnerability Disclosure Program |
| CPG-5.B | Mitigating Known Vulnerabilities |
| CPG-5.C | No Exploitable Services on the Internet |
| CPG-5.D | Vulnerability Disclosure Program |
Vulnerability Management
Vulnerability discovery, patching, and known exploited vulnerability remediation
| Code | Title |
|---|---|
| CPG-5.A | Vulnerability Disclosure Program |
| CPG-5.B | Mitigating Known Vulnerabilities |
| CPG-5.C | No Exploitable Services on the Internet |
| CPG-5.D | Vulnerability Disclosure Program |
Your Compliance Coverage
If you comply with CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, you already cover:
CSA CCM v4
53%
23 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
53%
23 controls mapped
Compare →FAA Cybersecurity Framework for Aviation
49%
21 controls mapped
Compare →+ 659 more: NIS2 Directive Implementing Acts (47%), South Korea ISMS-P (44%)
See all 662 mapped frameworks ↓Maps to 662 other frameworks
Frequently Asked Questions
What is CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0?
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 is a compliance framework from United States with 15 domains and 67 controls. CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) are a prioritized subset of IT and OT cybersecurity practices aimed at meaningfully reducing risk to critical infrastructure operations. Aligned with the NIST Cybersecurity Framework, CPGs provide a common set of protections that all critical infrastructure entities should implement. Version 2.0 organizes goals across 8 practice areas. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 have?
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 has 67 controls organised across 15 domains. The largest domains are Data Security (8 controls), Device Security (8 controls), Response and Recovery (7 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 map to?
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 maps to 662 other compliance frameworks. The top mapping partners are CSA CCM v4 (53% coverage), TISAX — Trusted Information Security Assessment Exchange (53% coverage), FAA Cybersecurity Framework for Aviation (49% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 compliance?
Start your CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 67 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required