What “CISA compliance” actually means — and why no certificate exists
Search “CISA compliance” and you'll find vendors implying a certificate you can buy. Let's be blunt: there is no CISA certification. The Cybersecurity and Infrastructure Security Agency — part of the U.S. Department of Homeland Security — publishes guidance, runs free services, and issues binding orders to federal agencies. It does not certify companies, does not endorse consultants, and does not sell a badge.
What CISA actually publishes
- Cybersecurity Performance Goals (CPGs) — voluntary baseline goals for critical-infrastructure operators. The closest thing to a “CISA standard.”
- Binding Operational Directives (BODs) — mandatory for federal agencies (e.g., remediate Known Exploited Vulnerabilities on schedule, maintain asset inventories). Contractors often adopt them voluntarily because agency customers expect it.
- Secure by Design principles — guidance for software manufacturers, co-authored with international partners. Buyers increasingly ask vendors about it.
- The KEV catalog — the list of vulnerabilities CISA says are actively exploited and must be patched on federal timelines.
- Shields Up guidance — CISA's standing posture guidance for heightened threat periods.
So what do “CISA consultants” actually sell?
Implementation help: CPG gap assessments, BOD-readiness programs for agencies, zero-trust roadmaps aligned to CISA's Zero Trust Maturity Model, incident-response retainers, tabletop exercises, and OT security for critical infrastructure. Nobody can sell you a CISA certificate — because none exists. Run from anyone who claims otherwise.
What to do before hiring anyone
Start with CISA's free services: vulnerability scanning (Cyber Hygiene) for eligible organizations, tabletop exercise packages, and the CPGs themselves as a self-assessment checklist. Then, if you need help, use our directory — every firm verified, no pay-to-rank — or get matched quotes.
Get quotes from verified firms
One brief, matched firms, competing quotes — free.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.