The Cross-Sector Cybersecurity Performance Goals (CPGs) are a set of baseline cybersecurity practices developed by CISA to help organizations of all sizes and sectors strengthen their resilience against common cyber threats. They provide prioritized, actionable measures that align with the NIST Cybersecurity Framework and are designed to be achievable, cost-effective, and impactful.
The Cross-Sector Cybersecurity Performance Goals (CPGs) are voluntary baseline practices developed by CISA to help organizations strengthen resilience against common cyber threats. They provide prioritized, actionable measures—such as multi-factor authentication, data encryption, and incident response planning—that align with the NIST Cybersecurity Framework. Designed to be achievable and cost-effective, the CPGs serve as a practical checklist for organizations across all sectors, especially critical infrastructure, to raise their cybersecurity posture.