Cybersecurity
DETAIL

CISA Cybersecurity Performance Goals (CPG)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

Overview

CISACybersecurity Performance Goals (CPG) is a set of voluntarycybersecurity objectives that help organizations identify andprioritize minimum essential practices for managing cybersecurityrisk. The framework offers concrete guidance on implementing baselinesecurity measures critical to defending against common threats andreducing potential impact from cyber incidents.

Developed by theCybersecurity and Infrastructure Security Agency (CISA), the CPGsprovide actionable recommendations for critical infrastructureoperators, public sector entities, and private organizations of allsizes. The framework focuses on core areas including networksecurity, access control, vulnerability management, incidentresponse, and supply chain risk.

Organizationsimplement the CPGs by integrating performance goals into theircybersecurity programs, performing risk assessments, and regularlymonitoring progress against these goals. The framework supportscompliance initiatives, complements standards like NIST CybersecurityFramework and CIS Controls, and strengthens overall risk managementand operational resilience.

Why it Matters

CISACybersecurity Performance Goals help organizations focus on essentialsecurity practices to mitigate cyber risks and bolster overallresilience.

Key benefitsinclude:

•  Strengthen cybersecurity governance

Enableorganizations to establish clear security objectives, roles, andpriorities that enhance program accountability and strategicdirection.

•  Enhance operational resilience

Reduce thelikelihood and impact of cyber incidents by establishing reliablebaseline controls for critical assets and services.

•  Improve regulatory and standards alignment

Facilitatealignment with industry-recognized frameworks and support ongoingcompliance with regulatory and contractual cybersecurity obligations.

•  Support continuous risk management

Encourageregular risk assessments and progress reviews to adapt controls basedon evolving threats and organizational needs.

•  Increase audit readiness

Document clearcyber objectives and measurable progress, making it easier todemonstrate security program effectiveness during internal andexternal assessments.

How it Works

The CISACybersecurity Performance Goals (CPG) framework establishes a set ofprioritized cybersecurity practices structured around key securityobjectives and cross-industry requirements. It organizes thesepractices into essential security controls and technical safeguardsmapped to critical governance domains, risk management principles,and regulatory expectations. The framework is designed to beactionable and measurable, providing a baseline of cybersecurityperformance applicable across industries, with controls grouped inareas such as identity protection, device management, protectivetechnology, and incident response.

In practice,organizations utilize the CISA CPGs by implementing the recommendedsecurity controls within their operational environments. They conductrisk assessments to identify gaps, monitor compliance withperformance goals, strengthen governance, and enhance their overallsecurity posture. Frequent evaluations and ongoing monitoring helptrack progress toward achieving the CPGs, while periodic assessmentssupport regulatory compliance and continuous improvement of securitypractices.

SmartSuiteenables organizations to operationalize the CISA CPGs throughpre-built control libraries, integrated risk registers, policygovernance tools, and evidence collection features. Compliancetracking modules and remediation workflows streamline management ofcorrective actions, while reporting dashboards provide real-timevisibility into performance against security goals and regulatoryobligations.

Key Elements

•  Network Security Safeguards

Definesprotections for network infrastructure, covering segmentation,perimeter defenses, and secure communications.

•  Access Management Principles

Describes thefoundational requirements for controlling user and system privilegesand authentication mechanisms.

•  Vulnerability Management Processes

Specifiesmethods for identifying, assessing, and addressing security flaws andexposures.

•  Incident Response Capabilities

Outlinesstructured approaches to preparing for and managing cybersecurityincidents and breaches.

•  Supply Chain Risk Oversight

Establishescriteria for evaluating third-party risks and ensuring vendorsecurity practices.

•  Performance Monitoring Metrics

Organizesmeasurement and review mechanisms for tracking progress againstcybersecurity goals.

•  Governance and Policy Integration

Structuresoversight functions and policy development within the cybersecurityprogram.

Framework Scope

CISACybersecurity Performance Goals (CPG) is adopted by criticalinfrastructure operators, public entities, and private sectororganizations responsible for safeguarding key information systemsand industrial control environments. It is typically integratedduring initiatives to enhance baseline security postures, guide riskmanagement, and support compliance assessments within evolving threatlandscapes.

Framework Objectives

CISACybersecurity Performance Goals (CPG) provides foundationalobjectives to guide organizations in managing cybersecurity risk andstrengthening security posture.

•  Strengthen governance and oversight of cybersecurity and riskmanagement processes

•  Enhance protection of critical data and information systems fromcyber threats

•  Support compliance with regulatory requirements and industrysecurity standards

•  Improve operational resilience to minimize the impact ofpotential cyber incidents

•  Enable effective risk management and measurement through definedsecurity controls

•  Promote continuous improvement in data protection and incidentresponse capabilities CISA Cybersecurity Performance Goals (CPG)align with and map to existing frameworks such as the NISTCybersecurity Framework, CIS Critical Security Controls, NIST SP800-53 and NIST SP 800-207 (Zero Trust), offering prioritizedobjectives. Organizations adopt CPGs for regulatory alignment,governance, risk reduction, and to drive operational securityimprovements or federal compliance efforts.

Common Framework Mappings

Organizationsmap CISA Cybersecurity Performance Goals (CPG) to establishedframeworks to ensure consistent controls, streamline audits, enableregulatory alignment, and leverage existing mappings and threat andcontrol taxonomies for risk management.

Mappedframeworks include:

CIS CriticalSecurity Controls

ISO/IEC 27001

MITRE ATT&CK

NISTCybersecurity Framework

NIST SP 800-171

NIST SP 800-207

NIST SP 800-53

SOC 2

At a Glance
CISA Cybersecurity Performance Goals (CPG) v1.0
  • checklist
    Classicifation
    Category
    info
    Cybersecurity
    Domain
    info
    Cybersecurity
    Framework Family
    info
    Other
  • info
    Regulatory Context
    Type
    info
    Framework
    Legal Instrument
    info
    Guideline
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    North America
    Region Detail
    info
    United States
    Publisher
    info
    Cybersecurity and Infrastructure Security Agency (CISA)
  • published_with_changes
    Versioning
    Version
    info
    CISA Cybersecurity Performance Goals (2022)
    Effective Date
    info
    June 2024
    Issue Date
    info
    December 2023
  • graph_3
    Adoption
    Adoption Model
    info
    Security Baseline
    Implementation Complexity
    info
    Low
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The CISA Cybersecurity Performance Goals are published by CISA and are publicly available through official CISA resources.

Official Resources
CISA Cross-Sector Cybersecurity Performance Goals
Provides a comprehensive set of voluntary goals to enhance national cybersecurity resilience.
chevron_forward
CISA Cybersecurity Performance Goals Implementation Guidance
Offers detailed guidance on integrating performance goals within organizational cybersecurity strategies.
chevron_forward
CISA Cybersecurity Performance Goals Overview
Outlines the objectives and core areas covered by the CPGs.
chevron_forward
SMARTSUITE

How SmartSuite Supports US CISA CPG v2022

Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.

Baseline Goal Library

Organize CPG objectives with owners, scope, and implementation status.

Gap Assessment and Prioritization

Assess current posture against goals and prioritize the highest-impact gaps.

Gap-to-Project Conversion

Convert gaps into projects and tasks with deadlines, owners, and clear accountability.

Evidence and Verification

Attach proof (policies, configs, scan results) to each goal for audit-ready traceability.

Recurring Security Hygiene Checks

Schedule recurring checks for patching, access, backups, and logging to prevent drift.

Executive Reporting

Report goal coverage, open gaps, and progress by function, team, and asset group.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
MITRE ATT&CK

MITRE ATT&CK is a knowledge framework documenting adversary tactics and techniques to help organizations detect, analyze, and respond to attacks.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-171 Rev.2

NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

Learn More
arrow_forward
NIST 800-207 ZTA

NIST SP 800-207 defines principles for implementing zero trust security to minimize unauthorized access and protect critical assets.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For CISA Cybersecurity Performance Goals (CPG)

What is the CISA Cybersecurity Performance Goals (CPG) framework used for?

The CISA CPG framework is designed to help organizations prioritize and implement essential cybersecurity practices that reduce risk from common threats and cyber incidents. It serves as a baseline for building or enhancing an organization's cybersecurity posture, particularly within critical infrastructure sectors and both public and private organizations.

Are CISA Cybersecurity Performance Goals mandatory or certifiable?

CISA Cybersecurity Performance Goals are voluntary and not part of a formal certification process. While they are not required by law, implementing the CPGs is highly recommended and can support regulatory compliance by aligning with recognized cybersecurity best practices.

Who should use the CISA Cybersecurity Performance Goals framework?

The CISA CPGs are applicable to critical infrastructure operators, government entities, and private sector organizations of all sizes. The framework is especially relevant for organizations seeking to strengthen their baseline cybersecurity controls and align with federal guidance.

What are the key concepts or artifacts required by the CISA CPG framework?

Key concepts include performance goals structured around essential security controls, such as network defense, identity management, incident response, and supply chain risk management. Organizations should maintain documentation such as risk assessments, control implementation records, and ongoing progress monitoring artifacts.

How does implementation of CISA Cybersecurity Performance Goals work in practice?

Implementation involves assessing the organization’s current security posture, identifying gaps against CPG requirements, and integrating priority controls into existing cybersecurity programs. Regular reviews and progress tracking are essential for maintaining alignment with the goals.

How do CISA Cybersecurity Performance Goals interact with other frameworks like NIST CSF or CIS Controls?

CISA CPGs are mapped to and complement other recognized frameworks such as the NIST Cybersecurity Framework and CIS Controls. Organizations can use the CPGs alongside these standards to ensure comprehensive coverage of essential security controls while supporting overall risk management.

What are the ongoing compliance and monitoring requirements for CISA CPGs?

Ongoing compliance involves continuous monitoring of control effectiveness, periodic risk assessments, and updating cybersecurity practices in response to evolving threats. Regular documentation and review of progress against performance goals support regulatory audits and drive continual improvement.

How would SmartSuite support CISA Cybersecurity Performance Goals?

SmartSuite streamlines CPG adoption through pre-built control libraries, integrated risk registers, and evidence collection capabilities. It facilitates compliance tracking and remediation workflows, helps maintain audit readiness, and provides real-time reporting dashboards to monitor progress against CISA CPG implementation and regulatory requirements.

NEXT STEP

Put CRI Profile into action with SmartSuite

Map controls, collect evidence, run assessments, manage remediation, and report readiness - all from a single connected system.

Explore in SmartSuite
chevron_forward
View all Frameworks
chevron_forward