Planning

How long does CISA CPG implementation take?

A realistic end-to-end range for a first CPG-alignment program: 6–12 months. Here's where the time goes — and how to compress it.

  1. Enroll in free CISA services — 1–2 weeks
    Sign up for Cyber Hygiene scanning and pull the CPG checklist. Free visibility while you plan.
  2. CPG gap assessment — 4–6 weeks
    A consultant tests your program against the goals and delivers a prioritized gap list. Get 2–3 scoped quotes first.
  3. Quick wins — 30–60 days
    MFA enforcement, KEV patching cadence, offline backups. The highest-risk gaps close first.
  4. Program build-out — 3–6 months
    Segmentation, logging and monitoring, incident-response plan with reporting paths, tabletop exercise.
  5. OT scope (if applicable) — 2–4 months, parallel
    OT asset inventory, passive monitoring, IT/OT separation. Safety-constrained, so it runs on its own track.
  6. Continuous operation — ongoing
    CPG alignment isn't a project with an end date. Annual reassessment keeps the program honest.

What causes delays

  • Discovery debt. No asset inventory means months of archaeology before control work.
  • OT treated as an afterthought. OT assessment runs on a safety-constrained track — start it in parallel, not after.
  • Tool-first buying. Buying monitoring tools before defining what they'll monitor. Define the program, then tool it.
  • Scope creep. Adding business units mid-program without re-baselining the timeline.

Fastest realistic path

Small operator, decent starting posture: free CISA scanning (week 1) + 4-week gap assessment + 60 days of quick wins ≈ 3–4 months to a defensible CPG baseline. Large or OT-heavy: plan for 9–12+ months.

Timeline questions

Do I need a consultant, or can I do this in-house?

Start in-house with CISA's free services and the CPG checklist. Hire a consultant for the gaps you can't close — specialized assessments, OT scope, or program build-out at speed.

What slows CPG programs down most?

Asset inventory. Organizations that can't see their exposed systems spend months on discovery before any control work starts. Run CISA's free scanning on day one.

Is there a deadline?

For federal agencies: yes — BOD timelines and zero-trust milestones are mandatory. For everyone else: no federal deadline, but customers, insurers, and contracts increasingly set their own.

Start the clock

Tell us your deadline — we'll match you with firms who can hit it.

Get a free quote