Skip to content

Evidence request lists

CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0

Evidence request list. 35 controls, 35 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Account Security

CPG-1.A
Changing Default Passwords

Change all default manufacturer or vendor-supplied passwords on hardware, software, and firmware before deployment to production.

Artefacts an auditor will ask for
  • Hardening checklist with default-password step
  • Pre-deployment build records
  • Asset inventory flagging default-credential status
  • Procurement acceptance test results
Where this commonly fails
  • IoT and OT devices left on factory defaults
  • Service accounts on appliances never rotated
  • No verification step before go-live
CPG-1.B
Minimum Password Strength

Enforce a minimum password length of 15 characters or use phrase-based passwords for all human user accounts.

Artefacts an auditor will ask for
  • Password policy GPO or IdP screenshot
  • Test account creation showing enforcement
  • Exception register for legacy systems
Where this commonly fails
  • Legacy LDAP or local accounts excluded
  • Service accounts not covered by policy
CPG-1.C
Unique Credentials

Each user and service account uses unique credentials; shared accounts are prohibited except where technically unavoidable and compensated.

Artefacts an auditor will ask for
  • Account inventory with owner mapping
  • Shared-account exception register with compensating controls
  • PAM vault records
Where this commonly fails
  • Shared break-glass accounts undocumented
  • OT operator stations using shared logins
CPG-1.D
Revoking Credentials for Departing Employees

Disable accounts and revoke access for departing personnel within a defined time, typically same business day.

Artefacts an auditor will ask for
  • Leaver tickets with timestamps
  • HRIS to IdP deprovisioning logs
  • Quarterly orphan-account review
Where this commonly fails
  • Contractor and third-party offboarding gaps
  • SaaS apps outside SSO not deprovisioned
CPG-1.E
Separating User and Privileged Accounts

Privileged users must use separate accounts for administrative tasks and not for daily activities like email or browsing.

Artefacts an auditor will ask for
  • Admin account naming convention
  • PAM vault membership
  • Audit of admin login activity
Where this commonly fails
  • Domain admins reading email from admin account
  • Helpdesk staff using personal account for admin tasks
CPG-1.F
Phishing-Resistant MFA

Enable phishing-resistant MFA (FIDO2, PIV) for all IT accounts; at minimum, MFA for all internet-facing and privileged accounts.

Artefacts an auditor will ask for
  • MFA coverage report by app and user
  • FIDO key issuance log
  • Sign-in logs showing MFA method
Where this commonly fails
  • SMS or voice MFA still permitted for admins
  • Legacy auth protocols not blocked

Data Security

CPG-3.A
Log Collection

Collect security-relevant logs from IT and OT assets and retain for at least 30 days, ideally 180.

Artefacts an auditor will ask for
  • SIEM source inventory
  • Retention policy
  • Coverage gap analysis
Where this commonly fails
  • OT logs not forwarded
  • SaaS audit logs not ingested
CPG-3.B
Secure Log Storage

Logs are stored in a tamper-resistant location separate from the source system.

Artefacts an auditor will ask for
  • WORM or immutable storage config
  • Access control list for log store
  • Integrity check evidence
Where this commonly fails
  • Local-only log retention on Windows servers
CPG-3.C
Strong and Agile Encryption

Use strong, current encryption algorithms for data in transit and at rest, with capability to update as standards evolve.

Artefacts an auditor will ask for
  • Approved algorithm policy
  • TLS configuration scan results
  • Key rotation records
Where this commonly fails
  • Legacy TLS 1.0 or 1.1 still enabled
  • Self-managed keys without rotation
CPG-3.D
Secure Sensitive Data

Identify and protect sensitive data (PII, PHI, financial, intellectual property) using classification and access controls.

Artefacts an auditor will ask for
  • Data classification policy
  • DLP policy and incidents
  • Access review of sensitive repositories
Where this commonly fails
  • Unclassified sensitive data on file shares

Device Security

CPG-2.A
Asset Inventory

Maintain an inventory of IT and OT assets including ownership, location, and criticality; review at least annually.

Artefacts an auditor will ask for
  • CMDB extract
  • Reconciliation report between discovery and CMDB
  • Inventory review minutes
Where this commonly fails
  • OT assets tracked in spreadsheets only
  • Cloud and SaaS assets missing
CPG-2.B
Prohibit Connection of Unauthorized Devices

Prevent unauthorized devices from connecting to the network using NAC, 802.1X, port security, or equivalent.

Artefacts an auditor will ask for
  • NAC policy and enforcement reports
  • Quarantine VLAN evidence
  • Rogue device detection logs
Where this commonly fails
  • Guest Wi-Fi bridging to corporate
  • OT segments with no NAC
CPG-2.C
Hardware and Software Approval Process

Establish and enforce an approval process before hardware or software is deployed or installed.

Artefacts an auditor will ask for
  • Approved software list
  • Change tickets approving new hardware
  • Application allowlist policy
Where this commonly fails
  • Shadow IT SaaS subscriptions
  • Local admin rights enabling unapproved installs
CPG-2.D
Disable Macros by Default

Disable Office macros by default and only allow signed or approved macros.

Artefacts an auditor will ask for
  • GPO or Intune policy screenshot
  • Macro signing certificate inventory
  • User exception register
Where this commonly fails
  • Finance teams granted blanket macro exceptions
CPG-2.E
Document Device Configurations

Maintain documented baseline configurations for assets and detect deviation.

Artefacts an auditor will ask for
  • CIS Benchmark or vendor baseline
  • Drift detection reports
  • Configuration backup repository
Where this commonly fails
  • No baseline for network devices
  • Cloud workloads not benchmarked
CPG-2.F
No Exploitable Services on the Internet

Do not expose services such as RDP, SMB, Telnet, or databases directly to the internet.

Artefacts an auditor will ask for
  • External attack surface scan results
  • Firewall rule review
  • Shodan or equivalent monitoring report
Where this commonly fails
  • Cloud test environments with public DB ports
  • Legacy RDP jump hosts internet-facing
CPG-2.G
Limit OT Connections to Public Internet

OT assets should not be directly accessible from the public internet; use jump hosts and DMZs.

Artefacts an auditor will ask for
  • OT network diagram
  • Firewall rules between IT, DMZ, OT
  • Jump host access logs
Where this commonly fails
  • Vendor remote access bypasses DMZ
  • Cellular modems on PLCs
CPG-2.H
Document Network Topology

Maintain accurate, current network topology diagrams for IT and OT environments.

Artefacts an auditor will ask for
  • Current IT and OT topology diagrams
  • Diagram review and approval records
  • Asset to zone mapping
Where this commonly fails
  • Diagrams out of date
  • OT segments missing from IT-led diagrams

Governance and Training

CPG-4.A
Organizational Cybersecurity Leadership

Designate a named, accountable cybersecurity leader empowered to make risk decisions.

Artefacts an auditor will ask for
  • CISO appointment letter
  • Reporting line diagram
  • Board reporting cadence
Where this commonly fails
  • Security leadership multiple layers below CIO
CPG-4.B
OT Cybersecurity Leadership

Designate a leader specifically accountable for OT cybersecurity outcomes.

Artefacts an auditor will ask for
  • OT security role description
  • Joint IT-OT governance charter
Where this commonly fails
  • OT security informally owned by plant engineers
CPG-4.C
Basic Cybersecurity Training

All personnel receive basic cybersecurity training at onboarding and at least annually.

Artefacts an auditor will ask for
  • LMS completion report
  • Training content review
  • Phishing simulation results
Where this commonly fails
  • Contractors and OT staff excluded
CPG-4.D
OT-Specific Cybersecurity Training

Provide specialized cybersecurity training for OT personnel addressing OT-specific threats, secure operations, and incident response.

Artefacts an auditor will ask for
  • VDP policy
  • Vulnerability scan report
  • OT training records
  • Attack surface inventory
Where this commonly fails
  • No VDP
  • Internet exposed services
  • OT staff not trained

Network Segmentation

CPG-8.A
Network Segmentation

Implement network segmentation between IT and OT networks. Use firewalls and access controls to limit lateral movement.

Artefacts an auditor will ask for
  • Segmentation diagram
  • DMARC reject record
  • Encrypted DNS policy
  • Firewall rule review
Where this commonly fails
  • Flat network
  • No DMARC enforcement
  • Plain DNS
CPG-8.B
Email Security (DMARC)

Implement DMARC with a policy of reject for all organizational email domains. Publish SPF and DKIM records.

Artefacts an auditor will ask for
  • Segmentation diagram
  • DMARC reject record
  • Encrypted DNS policy
  • Firewall rule review
Where this commonly fails
  • Flat network
  • No DMARC enforcement
  • Plain DNS
CPG-8.C
Encrypted DNS

Use encrypted DNS (DoH or DoT) for all organizational DNS queries where operationally feasible.

Artefacts an auditor will ask for
  • Segmentation diagram
  • DMARC reject record
  • Encrypted DNS policy
  • Firewall rule review
Where this commonly fails
  • Flat network
  • No DMARC enforcement
  • Plain DNS

Response & Recovery

CPG-7.A
Incident Reporting

Establish processes to report cybersecurity incidents to CISA and other authorities as required.

Artefacts an auditor will ask for
  • IR plan with reporting matrix
  • Tabletop showing reporting step
  • Past notification records
Where this commonly fails
  • No CIRCIA readiness plan
CPG-7.B
Incident Response Plans

Maintain and exercise written incident response plans covering IT and OT scenarios.

Artefacts an auditor will ask for
  • IR plan document
  • Annual tabletop after-action report
  • OT-specific playbooks
Where this commonly fails
  • OT IR scenarios untested
CPG-7.C
System Backups

Maintain regular, tested, offline or immutable backups of critical systems and data.

Artefacts an auditor will ask for
  • Backup schedule
  • Restore test results
  • Immutability or air-gap configuration
Where this commonly fails
  • Backups reachable from production credentials
  • Restore never tested
CPG-7.D
Incident Response Testing

Conduct tabletop exercises or functional tests of incident response plans at least annually. Include key stakeholders and leadership.

Artefacts an auditor will ask for
  • Incident response plan and playbooks
  • Tabletop exercise reports
  • Incident ticket history with timelines
  • Forensic toolkit and chain-of-custody log
  • Post-incident review minutes
Where this commonly fails
  • Playbooks untested for major scenarios
  • Unclear escalation thresholds
  • Forensic readiness lacking outside core systems
  • Lessons learned never closed out

Supply Chain and Third Party

CPG-6.A
Vendor and Supplier Incident Reporting

Require vendors and suppliers to notify of incidents that may affect the organization.

Artefacts an auditor will ask for
  • Vendor contract clauses
  • TPRM register with notification timeframes
  • Sample vendor incident notifications
Where this commonly fails
  • Notification requirements not in legacy contracts
CPG-6.B
Supply Chain Incident Reporting

Establish procedures for supply chain partners to report cybersecurity incidents. Define communication channels and response timelines.

Artefacts an auditor will ask for
  • IR plan
  • BC plan
  • Tabletop exercise report
  • Cyber insurance policy
Where this commonly fails
  • No tested IR plan
  • BC plan untested
  • Coverage gaps

Vulnerability Management

CPG-5.A
Vulnerability Disclosure Program

Maintain a public vulnerability disclosure policy for external researchers.

Artefacts an auditor will ask for
  • Published VDP
  • Intake mailbox and triage records
  • Hall of fame or acknowledgements
Where this commonly fails
  • No published contact
  • Legal threats to researchers
CPG-5.B
Mitigating Known Vulnerabilities

Remediate CISA KEV catalog vulnerabilities within timeframes defined in BOD 22-01 or applicable policy.

Artefacts an auditor will ask for
  • KEV remediation tracker
  • Patch SLA report
  • Compensating control register
Where this commonly fails
  • OT assets exempted without compensating controls
CPG-5.C
No Exploitable Services on the Internet

Minimize the internet attack surface. Disable or remove unnecessary internet-facing services and ports.

Artefacts an auditor will ask for
  • VDP policy
  • Vulnerability scan report
  • OT training records
  • Attack surface inventory
Where this commonly fails
  • No VDP
  • Internet exposed services
  • OT staff not trained
CPG-5.D
Vulnerability Disclosure Program

Establish a vulnerability disclosure policy (VDP) allowing external researchers to report security vulnerabilities. Maintain a security.txt file.

Artefacts an auditor will ask for
  • VDP policy
  • Vulnerability scan report
  • OT training records
  • Attack surface inventory
Where this commonly fails
  • No VDP
  • Internet exposed services
  • OT staff not trained
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.