Cybersecurity
DETAIL

CISA Cybersecurity Performance Goals (CPG)

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
Framework text may require a separate license unless explicitly provided.

arrow_back
arrow_forward

Why it Matters

CISA Cybersecurity Performance Goals help organizations focus onessential security practices to mitigate cyber risks and bolsteroverall resilience.

Key benefits include:

  • Strengthen cybersecurity governance

Enableorganizations to establish clear security objectives, roles, andpriorities that enhance program accountability and strategicdirection.

  • Enhance operational resilience

Reduce thelikelihood and impact of cyber incidents by establishing reliablebaseline controls for critical assets and services.

  • Improve regulatory and standards alignment

Facilitatealignment with industry-recognized frameworks and support ongoingcompliance with regulatory and contractual cybersecurity obligations.

  • Support continuous risk management

Encourage regularrisk assessments and progress reviews to adapt controls based onevolving threats and organizational needs.

  • Increase audit readiness

Document clearcyber objectives and measurable progress, making it easier todemonstrate security program effectiveness during internal andexternal assessments.

How it Works

The CISA Cybersecurity Performance Goals (CPG) framework establishesa set of prioritized cybersecurity practices structured around keysecurity objectives and cross-industry requirements. It organizesthese practices into essential security controls and technicalsafeguards mapped to critical governance domains, risk managementprinciples, and regulatory expectations. The framework is designed tobe actionable and measurable, providing a baseline of cybersecurityperformance applicable across industries, with controls grouped inareas such as identity protection, device management, protectivetechnology, and incident response.

In practice, organizations utilize the CISA CPGs by implementing therecommended security controls within their operational environments.They conduct risk assessments to identify gaps, monitor compliancewith performance goals, strengthen governance, and enhance theiroverall security posture. Frequent evaluations and ongoing monitoringhelp track progress toward achieving the CPGs, while periodicassessments support regulatory compliance and continuous improvementof security practices.

SmartSuite enables organizations to operationalize the CISA CPGsthrough pre-built control libraries, integrated risk registers,policy governance tools, and evidence collection features. Compliancetracking modules and remediation workflows streamline management ofcorrective actions, while reporting dashboards provide real-timevisibility into performance against security goals and regulatoryobligations.

Key Elements

  • Network Security Safeguards

Definesprotections for network infrastructure, covering segmentation,perimeter defenses, and secure communications.

  • Access Management Principles

Describes thefoundational requirements for controlling user and system privilegesand authentication mechanisms.

  • Vulnerability Management Processes

Specifies methodsfor identifying, assessing, and addressing security flaws andexposures.

  • Incident Response Capabilities

Outlinesstructured approaches to preparing for and managing cybersecurityincidents and breaches.

  • Supply Chain Risk Oversight

Establishescriteria for evaluating third-party risks and ensuring vendorsecurity practices.

  • Performance Monitoring Metrics

Organizesmeasurement and review mechanisms for tracking progress againstcybersecurity goals.

  • Governance and Policy Integration

Structuresoversight functions and policy development within the cybersecurityprogram.

Framework Scope

CISA Cybersecurity Performance Goals (CPG) is adopted by criticalinfrastructure operators, public entities, and private sectororganizations responsible for safeguarding key information systemsand industrial control environments. It is typically integratedduring initiatives to enhance baseline security postures, guide riskmanagement, and support compliance assessments within evolving threatlandscapes.

Framework Objectives

CISA Cybersecurity Performance Goals (CPG) provides foundationalobjectives to guide organizations in managing cybersecurity risk andstrengthening security posture.

Strengthen governance and oversight of cybersecurity and riskmanagement processes

Enhance protection of critical data and information systems fromcyber threats

Support compliance with regulatory requirements and industry securitystandards

Improve operational resilience to minimize the impact of potentialcyber incidents

Enable effective risk management and measurement through definedsecurity controls

Promote continuous improvement in data protection and incidentresponse capabilities CISA Cybersecurity Performance Goals (CPG)align with and map to existing frameworks such as the NISTCybersecurity Framework, CIS Critical Security Controls, NIST SP800-53 and NIST SP 800-207 (Zero Trust), offering prioritizedobjectives. Organizations adopt CPGs for regulatory alignment,governance, risk reduction, and to drive operational securityimprovements or federal compliance efforts.

Common Framework Mappings

Organizations map CISA Cybersecurity Performance Goals (CPG) toestablished frameworks to ensure consistent controls, streamlineaudits, enable regulatory alignment, and leverage existing mappingsand threat and control taxonomies for risk management.

Mapped frameworks include:

CIS Critical Security Controls

ISO/IEC 27001

MITRE ATT&CK

NIST Cybersecurity Framework

NIST SP 800-171

NIST SP 800-207

NIST SP 800-53

SOC 2

At a Glance
CISA Cybersecurity Performance Goals (CPG) v1.0
  • checklist
    Classification
    Category
    info
    Cybersecurity
    Domain
    info
    Cybersecurity
    Framework Family
    info
    Other
  • info
    Regulatory Context
    Type
    info
    Framework
    Legal Instrument
    info
    Guideline
    Sector
    info
    Cross-Sector
    Industry
    info
    Cross-Industry
  • arrow_upload_ready
    Region / Publisher
    Region
    info
    North America
    Region Detail
    info
    United States
    Publisher
    info
    Cybersecurity and Infrastructure Security Agency (CISA)
  • published_with_changes
    Versioning
    Version
    info
    CISA Cybersecurity Performance Goals (2022)
    Effective Date
    info
    June 2024
    Issue Date
    info
    December 2023
  • graph_3
    Adoption
    Adoption Model
    info
    Security Baseline
    Implementation Complexity
    info
    Low
  • captive_portal
    Official Reference
License Information

License included / downloadable: Yes

The CISA Cybersecurity Performance Goals are published by CISA and are publicly available through official CISA resources.

Official Resources
CISA Cross-Sector Cybersecurity Performance Goals
Provides a comprehensive set of voluntary goals to enhance national cybersecurity resilience.
chevron_forward
CISA Cybersecurity Performance Goals Implementation Guidance
Offers detailed guidance on integrating performance goals within organizational cybersecurity strategies.
chevron_forward
CISA Cybersecurity Performance Goals Overview
Outlines the objectives and core areas covered by the CPGs.
chevron_forward
SMARTSUITE

How SmartSuite Supports US CISA CPG v2022

Centralize controls, evidence, and audit workflows to stay continuously SOC 2–ready.

Baseline Goal Library

Organize CPG objectives with owners, scope, and implementation status.

Gap Assessment and Prioritization

Assess current posture against goals and prioritize the highest-impact gaps.

Gap-to-Project Conversion

Convert gaps into projects and tasks with deadlines, owners, and clear accountability.

Evidence and Verification

Attach proof (policies, configs, scan results) to each goal for audit-ready traceability.

Recurring Security Hygiene Checks

Schedule recurring checks for patching, access, backups, and logging to prevent drift.

Executive Reporting

Report goal coverage, open gaps, and progress by function, team, and asset group.

Related frameworks

CIS Controls v8.1

CIS Controls v8.1 provides prioritized, practical security actions to help organizations mitigate common cyber threats and strengthen defenses.

Learn More
arrow_forward
ISO 27001:2022

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.

Learn More
arrow_forward
MITRE ATT&CK

MITRE ATT&CK is a knowledge framework documenting adversary tactics and techniques to help organizations detect, analyze, and respond to attacks.

Learn More
arrow_forward
NIST CSF 2.0

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

Learn More
arrow_forward
NIST 800-171 Rev.2

NIST SP 800-171 defines security requirements for protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations.

Learn More
arrow_forward
NIST 800-207 ZTA

NIST SP 800-207 defines principles for implementing zero trust security to minimize unauthorized access and protect critical assets.

Learn More
arrow_forward
NIST 800-53 Rev.5

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

Learn More
arrow_forward
SOC 2

SOC 2 assesses and reports on a service organization's controls for security, availability, processing integrity, confidentiality, and privacy.

Learn More
arrow_forward
ONBOARDING FAQS

Frequently Asked Questions For CISA Cybersecurity Performance Goals (CPG)

What is the CISA Cybersecurity Performance Goals (CPG) framework used for?

The CISA CPG framework is designed to help organizations prioritize and implement essential cybersecurity practices that reduce risk from common threats and cyber incidents. It serves as a baseline for building or enhancing an organization's cybersecurity posture, particularly within critical infrastructure sectors and both public and private organizations.

Are CISA Cybersecurity Performance Goals mandatory or certifiable?

CISA Cybersecurity Performance Goals are voluntary and not part of a formal certification process. While they are not required by law, implementing the CPGs is highly recommended and can support regulatory compliance by aligning with recognized cybersecurity best practices.

Who should use the CISA Cybersecurity Performance Goals framework?

The CISA CPGs are applicable to critical infrastructure operators, government entities, and private sector organizations of all sizes. The framework is especially relevant for organizations seeking to strengthen their baseline cybersecurity controls and align with federal guidance.

What are the key concepts or artifacts required by the CISA CPG framework?

Key concepts include performance goals structured around essential security controls, such as network defense, identity management, incident response, and supply chain risk management. Organizations should maintain documentation such as risk assessments, control implementation records, and ongoing progress monitoring artifacts.

How does implementation of CISA Cybersecurity Performance Goals work in practice?

Implementation involves assessing the organization’s current security posture, identifying gaps against CPG requirements, and integrating priority controls into existing cybersecurity programs. Regular reviews and progress tracking are essential for maintaining alignment with the goals.

How do CISA Cybersecurity Performance Goals interact with other frameworks like NIST CSF or CIS Controls?

CISA CPGs are mapped to and complement other recognized frameworks such as the NIST Cybersecurity Framework and CIS Controls. Organizations can use the CPGs alongside these standards to ensure comprehensive coverage of essential security controls while supporting overall risk management.

What are the ongoing compliance and monitoring requirements for CISA CPGs?

Ongoing compliance involves continuous monitoring of control effectiveness, periodic risk assessments, and updating cybersecurity practices in response to evolving threats. Regular documentation and review of progress against performance goals support regulatory audits and drive continual improvement.

How would SmartSuite support CISA Cybersecurity Performance Goals?

SmartSuite streamlines CPG adoption through pre-built control libraries, integrated risk registers, and evidence collection capabilities. It facilitates compliance tracking and remediation workflows, helps maintain audit readiness, and provides real-time reporting dashboards to monitor progress against CISA CPG implementation and regulatory requirements.

Operationalize CISA CPG with Connected Workflows

Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.

Schedule a Demo
chevron_forward
Demo Library
chevron_forward