CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Account Security
Change all default manufacturer or vendor-supplied passwords on hardware, software, and firmware before deployment to production.
- Hardening checklist with default-password step
- Pre-deployment build records
- Asset inventory flagging default-credential status
- Procurement acceptance test results
- IoT and OT devices left on factory defaults
- Service accounts on appliances never rotated
- No verification step before go-live
Enforce a minimum password length of 15 characters or use phrase-based passwords for all human user accounts.
- Password policy GPO or IdP screenshot
- Test account creation showing enforcement
- Exception register for legacy systems
- Legacy LDAP or local accounts excluded
- Service accounts not covered by policy
Each user and service account uses unique credentials; shared accounts are prohibited except where technically unavoidable and compensated.
- Account inventory with owner mapping
- Shared-account exception register with compensating controls
- PAM vault records
- Shared break-glass accounts undocumented
- OT operator stations using shared logins
Disable accounts and revoke access for departing personnel within a defined time, typically same business day.
- Leaver tickets with timestamps
- HRIS to IdP deprovisioning logs
- Quarterly orphan-account review
- Contractor and third-party offboarding gaps
- SaaS apps outside SSO not deprovisioned
Privileged users must use separate accounts for administrative tasks and not for daily activities like email or browsing.
- Admin account naming convention
- PAM vault membership
- Audit of admin login activity
- Domain admins reading email from admin account
- Helpdesk staff using personal account for admin tasks
Enable phishing-resistant MFA (FIDO2, PIV) for all IT accounts; at minimum, MFA for all internet-facing and privileged accounts.
- MFA coverage report by app and user
- FIDO key issuance log
- Sign-in logs showing MFA method
- SMS or voice MFA still permitted for admins
- Legacy auth protocols not blocked
Data Security
Collect security-relevant logs from IT and OT assets and retain for at least 30 days, ideally 180.
- SIEM source inventory
- Retention policy
- Coverage gap analysis
- OT logs not forwarded
- SaaS audit logs not ingested
Logs are stored in a tamper-resistant location separate from the source system.
- WORM or immutable storage config
- Access control list for log store
- Integrity check evidence
- Local-only log retention on Windows servers
Use strong, current encryption algorithms for data in transit and at rest, with capability to update as standards evolve.
- Approved algorithm policy
- TLS configuration scan results
- Key rotation records
- Legacy TLS 1.0 or 1.1 still enabled
- Self-managed keys without rotation
Identify and protect sensitive data (PII, PHI, financial, intellectual property) using classification and access controls.
- Data classification policy
- DLP policy and incidents
- Access review of sensitive repositories
- Unclassified sensitive data on file shares
Device Security
Maintain an inventory of IT and OT assets including ownership, location, and criticality; review at least annually.
- CMDB extract
- Reconciliation report between discovery and CMDB
- Inventory review minutes
- OT assets tracked in spreadsheets only
- Cloud and SaaS assets missing
Prevent unauthorized devices from connecting to the network using NAC, 802.1X, port security, or equivalent.
- NAC policy and enforcement reports
- Quarantine VLAN evidence
- Rogue device detection logs
- Guest Wi-Fi bridging to corporate
- OT segments with no NAC
Establish and enforce an approval process before hardware or software is deployed or installed.
- Approved software list
- Change tickets approving new hardware
- Application allowlist policy
- Shadow IT SaaS subscriptions
- Local admin rights enabling unapproved installs
Disable Office macros by default and only allow signed or approved macros.
- GPO or Intune policy screenshot
- Macro signing certificate inventory
- User exception register
- Finance teams granted blanket macro exceptions
Maintain documented baseline configurations for assets and detect deviation.
- CIS Benchmark or vendor baseline
- Drift detection reports
- Configuration backup repository
- No baseline for network devices
- Cloud workloads not benchmarked
Do not expose services such as RDP, SMB, Telnet, or databases directly to the internet.
- External attack surface scan results
- Firewall rule review
- Shodan or equivalent monitoring report
- Cloud test environments with public DB ports
- Legacy RDP jump hosts internet-facing
OT assets should not be directly accessible from the public internet; use jump hosts and DMZs.
- OT network diagram
- Firewall rules between IT, DMZ, OT
- Jump host access logs
- Vendor remote access bypasses DMZ
- Cellular modems on PLCs
Maintain accurate, current network topology diagrams for IT and OT environments.
- Current IT and OT topology diagrams
- Diagram review and approval records
- Asset to zone mapping
- Diagrams out of date
- OT segments missing from IT-led diagrams
Governance and Training
Designate a named, accountable cybersecurity leader empowered to make risk decisions.
- CISO appointment letter
- Reporting line diagram
- Board reporting cadence
- Security leadership multiple layers below CIO
Designate a leader specifically accountable for OT cybersecurity outcomes.
- OT security role description
- Joint IT-OT governance charter
- OT security informally owned by plant engineers
All personnel receive basic cybersecurity training at onboarding and at least annually.
- LMS completion report
- Training content review
- Phishing simulation results
- Contractors and OT staff excluded
Provide specialized cybersecurity training for OT personnel addressing OT-specific threats, secure operations, and incident response.
- VDP policy
- Vulnerability scan report
- OT training records
- Attack surface inventory
- No VDP
- Internet exposed services
- OT staff not trained
Network Segmentation
Implement network segmentation between IT and OT networks. Use firewalls and access controls to limit lateral movement.
- Segmentation diagram
- DMARC reject record
- Encrypted DNS policy
- Firewall rule review
- Flat network
- No DMARC enforcement
- Plain DNS
Implement DMARC with a policy of reject for all organizational email domains. Publish SPF and DKIM records.
- Segmentation diagram
- DMARC reject record
- Encrypted DNS policy
- Firewall rule review
- Flat network
- No DMARC enforcement
- Plain DNS
Use encrypted DNS (DoH or DoT) for all organizational DNS queries where operationally feasible.
- Segmentation diagram
- DMARC reject record
- Encrypted DNS policy
- Firewall rule review
- Flat network
- No DMARC enforcement
- Plain DNS
Response & Recovery
Establish processes to report cybersecurity incidents to CISA and other authorities as required.
- IR plan with reporting matrix
- Tabletop showing reporting step
- Past notification records
- No CIRCIA readiness plan
Maintain and exercise written incident response plans covering IT and OT scenarios.
- IR plan document
- Annual tabletop after-action report
- OT-specific playbooks
- OT IR scenarios untested
Maintain regular, tested, offline or immutable backups of critical systems and data.
- Backup schedule
- Restore test results
- Immutability or air-gap configuration
- Backups reachable from production credentials
- Restore never tested
Conduct tabletop exercises or functional tests of incident response plans at least annually. Include key stakeholders and leadership.
- Incident response plan and playbooks
- Tabletop exercise reports
- Incident ticket history with timelines
- Forensic toolkit and chain-of-custody log
- Post-incident review minutes
- Playbooks untested for major scenarios
- Unclear escalation thresholds
- Forensic readiness lacking outside core systems
- Lessons learned never closed out
Supply Chain and Third Party
Require vendors and suppliers to notify of incidents that may affect the organization.
- Vendor contract clauses
- TPRM register with notification timeframes
- Sample vendor incident notifications
- Notification requirements not in legacy contracts
Establish procedures for supply chain partners to report cybersecurity incidents. Define communication channels and response timelines.
- IR plan
- BC plan
- Tabletop exercise report
- Cyber insurance policy
- No tested IR plan
- BC plan untested
- Coverage gaps
Vulnerability Management
Maintain a public vulnerability disclosure policy for external researchers.
- Published VDP
- Intake mailbox and triage records
- Hall of fame or acknowledgements
- No published contact
- Legal threats to researchers
Remediate CISA KEV catalog vulnerabilities within timeframes defined in BOD 22-01 or applicable policy.
- KEV remediation tracker
- Patch SLA report
- Compensating control register
- OT assets exempted without compensating controls
Minimize the internet attack surface. Disable or remove unnecessary internet-facing services and ports.
- VDP policy
- Vulnerability scan report
- OT training records
- Attack surface inventory
- No VDP
- Internet exposed services
- OT staff not trained
Establish a vulnerability disclosure policy (VDP) allowing external researchers to report security vulnerabilities. Maintain a security.txt file.
- VDP policy
- Vulnerability scan report
- OT training records
- Attack surface inventory
- No VDP
- Internet exposed services
- OT staff not trained
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.