The CISA Cybersecurity Performance Goals, explained for operators
The Cybersecurity Performance Goals are CISA's voluntary baseline for critical-infrastructure cybersecurity — a few dozen concrete goals across account security, device security, data security, governance, and response. If you run anything in the 16 critical-infrastructure sectors, the CPGs are the document your board should know about.
Why the CPGs matter even though they're voluntary
Three reasons: (1) regulators and sector risk agencies reference them; (2) insurers and large customers increasingly ask whether you meet them; (3) they're genuinely a good minimum baseline — most are things like “enforce MFA” and “fix KEV vulnerabilities on time,” not exotic controls.
How organizations use them
- Self-assessment. CISA publishes a CPG checklist — score yourself before spending a dollar.
- Gap assessment. A consultant tests you against the goals and hands you a prioritized remediation list (see our cost guide for planning ranges).
- Roadmap. Group the gaps into quick wins (MFA, KEV patching, backups) and capital projects (segmentation, OT monitoring).
Common failure points
Asset inventory is the perennial #1 — you can't patch what you can't see. Phishing-resistant MFA (not SMS codes) is #2. Untested backups are #3: everyone has backups until restore day.
Take our 2-minute readiness quiz — it's built around exactly these control areas.
Get quotes from verified firms
One brief, matched firms, competing quotes — free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.