Overview
The Cross-Sector Cybersecurity Performance Goals (CPGs) are voluntary baseline practices developed by CISA to help organizations strengthen resilience against common cyber threats. They provide prioritized, actionable measures—such as multi-factor authentication, data encryption, and incident response planning—that align with the NIST Cybersecurity Framework. Designed to be achievable and cost-effective, the CPGs serve as a practical checklist for organizations across all sectors, especially critical infrastructure, to raise their cybersecurity posture.