CISA Cross-Sector Cybersecurity Performance Goals 2.0
The CISA Cybersecurity Performance Goals (CPGs) 2.0 are a set of prioritised cybersecurity practices for critical infrastructure organisations of all sizes. Released December 2025, CPG 2.0 aligns with the NIST CSF 2.0 six-function structure including the new GOVERN function. The goals provide actionable, measurable benchmarks for reducing cyber risk.
6
Functions
2.0
Version (Dec 2025)
NIST CSF
Aligned With
16
CI Sectors
New in CPG 2.0. Leadership accountability, risk management strategy, cybersecurity governance policies, and supply chain risk management.
Asset management, risk assessment, access control, awareness training, data security, and secure configuration baselines.
Continuous monitoring, anomaly detection, security event analysis, and comprehensive logging and audit trails.
Incident response planning, communication procedures, analysis and mitigation, and incident reporting to CISA.
Recovery planning, continuity of operations, lessons learned integration, and public communication during recovery.
Evaluate current cybersecurity posture against CPG 2.0 goals across all six functions.
Start with GOVERN and IDENTIFY goals to establish foundational governance and asset awareness.
Deploy access controls, patching procedures, and secure configuration baselines.
Enable logging, monitoring, and anomaly detection aligned with CPG detection goals.
Create incident response procedures and test recovery plans regularly.
Reassess quarterly, track progress against CPG benchmarks, and report to CISA as appropriate.