CISA CPG

Also known as: Cross-Sector Cybersecurity Performance Goals, CPG, CPGs, Cross-Sector CPGs

CISA Cross-Sector Cybersecurity Performance Goals — CISA (US Department of Homeland Security)

The short, voluntary baseline CISA wrote for critical-infrastructure owners too small or too specialised to adopt a full framework: a prioritised set of practices chosen for their effect against known attacker techniques, each mapped to the NIST Cybersecurity Framework and costed for a small operator. Sector risk management agencies and insurers increasingly quote it as the floor, which is what turns a voluntary list into a question an auditor asks.

Subscribe to CISA CPG (RSS)

Timeline

No changes recorded yet — we are watching, and nothing has been published.

Monitoring

Watched by 1 official source. Watching since 20 September 2026.