Information SecurityUnited States
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) are a prioritized subset of IT and OT cybersecurity practices aimed at meaningfully reducing risk to critical infrastructure operations. Aligned with the NIST Cybersecurity Framework, CPGs provide a common set of protections that all critical infrastructure owners and operators can implement..
How CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 maps to other frameworks
All 35 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →Domains
Response & Recovery
Supply Chain
Vulnerability Management
Governance & Training
Data Security
Compare CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 vs ISO 27001:2022View comparison →CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 vs SOC 2View comparison →CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 vs NIST CSF 2.0View comparison →CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 vs GDPRView comparison →CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 vs HIPAAView comparison →CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 vs PCI DSS 4.0View comparison →
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 by Industry
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Healthcare→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Financial Services→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Technology→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Government→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Manufacturing→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Energy→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Retail→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Education→
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 by Role
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for CISOs→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Compliance Officers→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Risk Managers→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for IT Directors→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for DPOs→CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0 for Auditors→
Frequently Asked Questions
What is CISA Cross-Sector Cybersecurity Performance Goals?
CISA's Cross-Sector Cybersecurity Performance Goals (CPGs) are a prioritized subset of IT and OT cybersecurity practices aimed at meaningfully reducing risk to critical infrastructure operations. Aligned with the NIST Cybersecurity Framework, CPGs provide a common set of protections that all critical infrastructure owners and operators can implement..
How many controls does CISA Cross-Sector Cybersecurity Performance Goals have?
CISA Cross-Sector Cybersecurity Performance Goals contains 35 controls organized across 14 domains.
Where does CISA Cross-Sector Cybersecurity Performance Goals apply?
CISA Cross-Sector Cybersecurity Performance Goals is applicable in United States. Organizations operating in or serving customers in this jurisdiction should evaluate its requirements.
What frameworks does CISA Cross-Sector Cybersecurity Performance Goals map to?
CISA Cross-Sector Cybersecurity Performance Goals has control-to-control mappings with 282 other compliance frameworks in our database. Use our compliance platform to explore these mappings interactively.
How do I get started with CISA Cross-Sector Cybersecurity Performance Goals compliance?
Start by understanding the framework's key controls and domains. Our compliance platform provides AI-powered gap analysis and mapping tools to help you assess your current posture and build a remediation plan.
How ready are you for CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.