GuideAdvisoryCybersecurity

Build a practical baseline with CISA Cybersecurity Performance Goals

Use CISA’s voluntary Cross-Sector Cybersecurity Performance Goals to identify a manageable set of high-impact improvements, assign owners, capture evidence, and avoid confusing a baseline assessment with compliance or certification.

Executive summary

What you need to know

Use CISA’s voluntary Cross-Sector Cybersecurity Performance Goals to identify a manageable set of high-impact improvements, assign owners, capture evidence, and avoid confusing a baseline assessment with compliance or certification.

Potentially affected

Small and midsize organizations, critical-infrastructure operators, business leaders, and IT teams prioritizing limited security resources.

DSE recommendation

Review the current CISA goals, mark each item implemented, partial, not implemented, or not applicable, and assign the next evidence-backed action.

A long security-control catalog can overwhelm a team that needs to decide what to do next. CISA’s Cross-Sector Cybersecurity Performance Goals, commonly called the CPGs, are designed to focus attention on a limited set of practices with meaningful risk-reduction value.

What the official source says

Source fact: CISA describes the Cross-Sector CPGs as voluntary baseline practices that are broadly applicable across critical infrastructure. CISA says they were selected to help organizations, particularly small and midsize organizations, prioritize investments in essential actions with high-impact security outcomes. The goals include information-technology and operational-technology considerations and are aligned to Cybersecurity Framework functions.

The CPGs are not a promise that an organization will avoid an incident. CISA’s published FAQ also explains that implementing a goal does not necessarily fulfill an entire referenced NIST Cybersecurity Framework subcategory, and CISA does not operate an official CPG assessor-certification program.

A useful assessment method

DSE recommendation: work from the current CISA page and downloadable materials rather than a copied checklist that may become stale. For every goal, record five things:

  1. Status: implemented, partially implemented, not implemented, or not applicable.
  2. Owner: the person accountable for the decision and the team operating the practice.
  3. Evidence: a configuration export, policy, ticket, report, test record, diagram, or other reproducible proof.
  4. Gap: what remains incomplete, including technology, process, people, or supplier dependencies.
  5. Next review: when someone will verify that the practice still operates as intended.

Prioritize instead of chasing a score

Start with goals connected to the organization’s most consequential services and likely attack paths. A partially deployed safeguard protecting every critical account may deserve attention before a fully deployed safeguard on a low-impact system. Consider safety, operational disruption, sensitive data, financial loss, contractual commitments, and recovery difficulty.

DSE recommendation: convert the review into a short backlog. Each item should identify the business risk, accountable owner, safe implementation sequence, dependencies, success evidence, and rollback or escalation condition. Test changes with a representative group before broad production deployment.

Important limits

The CPGs are a baseline, not a complete security program, legal opinion, audit, certification, or substitute for sector-specific requirements. “Not applicable” should include a written reason. “Implemented” should mean the control is configured, operating, and periodically verified—not simply licensed or purchased.

Practical next step: select five current CPG items related to your most critical business service. Confirm evidence for each one, assign one improvement owner, and schedule a follow-up review before expanding the assessment.

Primary reference

Review the official source

CISA Cross-Sector Cybersecurity Performance Goals · Verified July 19, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE