CISA Cybersecurity Performance Goals (CPG)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Why it Matters
CISA Cybersecurity Performance Goals help organizations focus onessential security practices to mitigate cyber risks and bolsteroverall resilience.
Key benefits include:
- Strengthen cybersecurity governance
Enableorganizations to establish clear security objectives, roles, andpriorities that enhance program accountability and strategicdirection.
- Enhance operational resilience
Reduce thelikelihood and impact of cyber incidents by establishing reliablebaseline controls for critical assets and services.
- Improve regulatory and standards alignment
Facilitatealignment with industry-recognized frameworks and support ongoingcompliance with regulatory and contractual cybersecurity obligations.
- Support continuous risk management
Encourage regularrisk assessments and progress reviews to adapt controls based onevolving threats and organizational needs.
- Increase audit readiness
Document clearcyber objectives and measurable progress, making it easier todemonstrate security program effectiveness during internal andexternal assessments.
How it Works
The CISA Cybersecurity Performance Goals (CPG) framework establishesa set of prioritized cybersecurity practices structured around keysecurity objectives and cross-industry requirements. It organizesthese practices into essential security controls and technicalsafeguards mapped to critical governance domains, risk managementprinciples, and regulatory expectations. The framework is designed tobe actionable and measurable, providing a baseline of cybersecurityperformance applicable across industries, with controls grouped inareas such as identity protection, device management, protectivetechnology, and incident response.
In practice, organizations utilize the CISA CPGs by implementing therecommended security controls within their operational environments.They conduct risk assessments to identify gaps, monitor compliancewith performance goals, strengthen governance, and enhance theiroverall security posture. Frequent evaluations and ongoing monitoringhelp track progress toward achieving the CPGs, while periodicassessments support regulatory compliance and continuous improvementof security practices.
SmartSuite enables organizations to operationalize the CISA CPGsthrough pre-built control libraries, integrated risk registers,policy governance tools, and evidence collection features. Compliancetracking modules and remediation workflows streamline management ofcorrective actions, while reporting dashboards provide real-timevisibility into performance against security goals and regulatoryobligations.
Key Elements
- Network Security Safeguards
Definesprotections for network infrastructure, covering segmentation,perimeter defenses, and secure communications.
- Access Management Principles
Describes thefoundational requirements for controlling user and system privilegesand authentication mechanisms.
- Vulnerability Management Processes
Specifies methodsfor identifying, assessing, and addressing security flaws andexposures.
- Incident Response Capabilities
Outlinesstructured approaches to preparing for and managing cybersecurityincidents and breaches.
- Supply Chain Risk Oversight
Establishescriteria for evaluating third-party risks and ensuring vendorsecurity practices.
- Performance Monitoring Metrics
Organizesmeasurement and review mechanisms for tracking progress againstcybersecurity goals.
- Governance and Policy Integration
Structuresoversight functions and policy development within the cybersecurityprogram.
Framework Scope
CISA Cybersecurity Performance Goals (CPG) is adopted by criticalinfrastructure operators, public entities, and private sectororganizations responsible for safeguarding key information systemsand industrial control environments. It is typically integratedduring initiatives to enhance baseline security postures, guide riskmanagement, and support compliance assessments within evolving threatlandscapes.
Framework Objectives
CISA Cybersecurity Performance Goals (CPG) provides foundationalobjectives to guide organizations in managing cybersecurity risk andstrengthening security posture.
Strengthen governance and oversight of cybersecurity and riskmanagement processes
Enhance protection of critical data and information systems fromcyber threats
Support compliance with regulatory requirements and industry securitystandards
Improve operational resilience to minimize the impact of potentialcyber incidents
Enable effective risk management and measurement through definedsecurity controls
Promote continuous improvement in data protection and incidentresponse capabilities CISA Cybersecurity Performance Goals (CPG)align with and map to existing frameworks such as the NISTCybersecurity Framework, CIS Critical Security Controls, NIST SP800-53 and NIST SP 800-207 (Zero Trust), offering prioritizedobjectives. Organizations adopt CPGs for regulatory alignment,governance, risk reduction, and to drive operational securityimprovements or federal compliance efforts.
Common Framework Mappings
Organizations map CISA Cybersecurity Performance Goals (CPG) toestablished frameworks to ensure consistent controls, streamlineaudits, enable regulatory alignment, and leverage existing mappingsand threat and control taxonomies for risk management.
Mapped frameworks include:
CIS Critical Security Controls
ISO/IEC 27001
MITRE ATT&CK
NIST Cybersecurity Framework
NIST SP 800-171
NIST SP 800-207
NIST SP 800-53
SOC 2
- ClassificationCategoryCybersecurityDomainCybersecurityFramework FamilyOther
- Regulatory ContextTypeFrameworkLegal InstrumentGuidelineSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionNorth AmericaRegion DetailUnited StatesPublisherCybersecurity and Infrastructure Security Agency (CISA)
- VersioningVersionCISA Cybersecurity Performance Goals (2022)Effective DateJune 2024Issue DateDecember 2023
- AdoptionAdoption ModelSecurity BaselineImplementation ComplexityLow
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
The CISA Cybersecurity Performance Goals are published by CISA and are publicly available through official CISA resources.
How SmartSuite Supports US CISA CPG v2022
Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.
Baseline Goal Library
Organize CPG objectives with owners, scope, and implementation status.
Gap Assessment and Prioritization
Assess current posture against goals and prioritize the highest-impact gaps.
Gap-to-Project Conversion
Convert gaps into projects and tasks with deadlines, owners, and clear accountability.
Evidence and Verification
Attach proof (policies, configs, scan results) to each goal for audit-ready traceability.
Recurring Security Hygiene Checks
Schedule recurring checks for patching, access, backups, and logging to prevent drift.
Executive Reporting
Report goal coverage, open gaps, and progress by function, team, and asset group.
Related frameworks

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

MITRE ATT&CK is a knowledge framework documenting adversary tactics and techniques to help organizations detect, analyze, and respond to attacks.

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

NIST SP 800-207 defines principles for implementing zero trust security to minimize unauthorized access and protect critical assets.
Frequently Asked Questions For CISA Cybersecurity Performance Goals (CPG)
The CISA CPG framework is designed to help organizations prioritize and implement essential cybersecurity practices that reduce risk from common threats and cyber incidents. It serves as a baseline for building or enhancing an organization's cybersecurity posture, particularly within critical infrastructure sectors and both public and private organizations.
CISA Cybersecurity Performance Goals are voluntary and not part of a formal certification process. While they are not required by law, implementing the CPGs is highly recommended and can support regulatory compliance by aligning with recognized cybersecurity best practices.
The CISA CPGs are applicable to critical infrastructure operators, government entities, and private sector organizations of all sizes. The framework is especially relevant for organizations seeking to strengthen their baseline cybersecurity controls and align with federal guidance.
Key concepts include performance goals structured around essential security controls, such as network defense, identity management, incident response, and supply chain risk management. Organizations should maintain documentation such as risk assessments, control implementation records, and ongoing progress monitoring artifacts.
Implementation involves assessing the organization’s current security posture, identifying gaps against CPG requirements, and integrating priority controls into existing cybersecurity programs. Regular reviews and progress tracking are essential for maintaining alignment with the goals.
CISA CPGs are mapped to and complement other recognized frameworks such as the NIST Cybersecurity Framework and CIS Controls. Organizations can use the CPGs alongside these standards to ensure comprehensive coverage of essential security controls while supporting overall risk management.
Ongoing compliance involves continuous monitoring of control effectiveness, periodic risk assessments, and updating cybersecurity practices in response to evolving threats. Regular documentation and review of progress against performance goals support regulatory audits and drive continual improvement.
SmartSuite streamlines CPG adoption through pre-built control libraries, integrated risk registers, and evidence collection capabilities. It facilitates compliance tracking and remediation workflows, helps maintain audit readiness, and provides real-time reporting dashboards to monitor progress against CISA CPG implementation and regulatory requirements.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
