Guide

The CISA Cybersecurity Performance Goals, explained for operators

The Cybersecurity Performance Goals are CISA's voluntary baseline for critical-infrastructure cybersecurity — a few dozen concrete goals across account security, device security, data security, governance, and response. If you run anything in the 16 critical-infrastructure sectors, the CPGs are the document your board should know about.

Why the CPGs matter even though they're voluntary

Three reasons: (1) regulators and sector risk agencies reference them; (2) insurers and large customers increasingly ask whether you meet them; (3) they're genuinely a good minimum baseline — most are things like “enforce MFA” and “fix KEV vulnerabilities on time,” not exotic controls.

How organizations use them

Common failure points

Asset inventory is the perennial #1 — you can't patch what you can't see. Phishing-resistant MFA (not SMS codes) is #2. Untested backups are #3: everyone has backups until restore day.

Take our 2-minute readiness quiz — it's built around exactly these control areas.

Independent directory. CISACompliance.com is an independent directory and quote-matching service.

Get quotes from verified firms

One brief, matched firms, competing quotes — free.

Get a free quote

← All guides