United States

CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0

35 controls. 300 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

35 controls 300 frameworks share controls with it United States verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

CISA Cross-Sector Cybersecurity Performance Goals 2.0 Evidence & Implementation Kit

35 controls is the documentation set somebody has to write. This is that set, already written: an adopt-ready artifact for every control in policy and procedure text you edit rather than draft, and the evidence checklist an auditor asks for against each.

See what is in it, $249

The same set every buyer of this kit receives. Nothing here is produced on request.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CPG-1.AChanging Default Passwords82
CPG-1.BMinimum Password Strength0
CPG-1.CUnique Credentials110
CPG-1.DRevoking Credentials for Departing Employees63
CPG-1.ESeparating User and Privileged Accounts0
CPG-1.FPhishing-Resistant MFA0
CPG-2.AAsset Inventory26
CPG-2.BProhibit Connection of Unauthorized Devices26
CPG-2.CHardware and Software Approval Process0
CPG-2.DDisable Macros by Default0
CPG-2.EDocument Device Configurations0
CPG-2.FNo Exploitable Services on the Internet0
CPG-2.GLimit OT Connections to Public Internet0
CPG-2.HDocument Network Topology0
CPG-3.ALog Collection132
CPG-3.BSecure Log Storage132
CPG-3.CStrong and Agile Encryption102
CPG-3.DSecure Sensitive Data0
CPG-4.AOrganizational Cybersecurity Leadership0
CPG-4.BOT Cybersecurity Leadership9
CPG-4.CBasic Cybersecurity Training94
CPG-4.DOT-Specific Cybersecurity Training0
CPG-5.AVulnerability Disclosure Program72
CPG-5.BMitigating Known Vulnerabilities0
CPG-5.CNo Exploitable Services on the Internet0
CPG-5.DVulnerability Disclosure Program0
CPG-6.AVendor and Supplier Incident Reporting68
CPG-6.BSupply Chain Incident Reporting196
CPG-7.AIncident Reporting14
CPG-7.BIncident Response Plans6
CPG-7.CSystem Backups5
CPG-7.DIncident Response Testing14
CPG-8.ANetwork Segmentation146
CPG-8.BEmail Security (DMARC)0
CPG-8.CEncrypted DNS119

Tell me when CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What an auditor will ask you to produce

The artefacts named on the failure modes this framework speaks to.

  • Segmentation diagram
  • DMARC reject record
  • Encrypted DNS policy
  • Firewall rule review
  • Network segmentation diagram
  • Network segmentation (VPC/subnets/security groups)
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log

How programmes fail on this

Failure modes named by this framework and others. Each opens the full record.

What this page is

A control-level reference for CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition