CISA Cybersecurity Performance Goals
The CISA Cybersecurity Performance Goals are a voluntary set of recommended cybersecurity practices published by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to help organizations, particularly those in critical infrastructure, improve their defenses. They are meant to work for organizations of all sizes and levels of cybersecurity experience by identifying a prioritized subset of practices rather than a complete security program. They are guidance and best-practice goals, not an insurance policy term and not a mandatory regulation on their own.
The Cross-Sector Cybersecurity Performance Goals (CPGs) are a prioritized subset of cybersecurity practices selected by CISA through an industry engagement process and intended as a common baseline of protections for critical infrastructure entities across sectors. The CPGs are organized around functional categories reflected in CISA's materials, including Identify, Protect, Detect, Respond, and Recover, along with incident planning and preparedness, and the 2.0 revision emphasizes measurable actions. As a security and resilience framework, the CPGs describe controls and outcomes; they are distinct from cyber insurance policy terms such as coverage triggers, retentions, or sublimits, and adoption of the CPGs does not itself constitute risk transfer. Whether alignment with the CPGs affects underwriting, premium, or the applicability of failure-to-maintain-standards exclusions depends on the specific insurer, policy wording, and jurisdiction, and is outside the scope of the CPGs themselves. Precise version dates, adoption figures, and any regulatory mandates tied to the CPGs should be verified against current CISA materials rather than assumed.
Why it matters
For organizations that lack the resources to build a comprehensive security program from scratch, the CPGs offer a prioritized, voluntary starting point rather than an exhaustive checklist. By identifying a common baseline of protections intended to work for critical infrastructure entities of all sizes and levels of cyber maturity, they help organizations focus limited budgets and staff on a defined subset of practices. This prioritization matters most to smaller entities and those early in their cybersecurity journey, who may struggle to interpret and implement broader frameworks in full.
For insurance and risk transfer professionals, the CPGs are relevant as a reference point for organizational hygiene, but they are a security and resilience framework, not a policy term. Adopting the CPGs does not transfer risk, does not by itself constitute resilience, and does not reduce the likelihood of an incident being covered under any particular policy. Whether alignment with the CPGs influences underwriting appetite, premium, or the applicability of exclusions such as failure-to-maintain-standards provisions depends entirely on the specific insurer, policy wording, and jurisdiction. Those questions sit outside the CPGs themselves and should not be assumed from adoption alone.
The CPGs also evolve. The 2.0 revision emphasizes measurable actions, which can make it easier for an organization to demonstrate progress internally, but users should verify current version details, functional categories, and any sector-specific expectations against live CISA materials rather than relying on a static understanding. Because the CPGs are voluntary guidance and not a mandatory regulation on their own, their weight in any given context is a matter of how organizations, regulators, or counterparties choose to reference them.
Who it's relevant to
Inside CPGs
Common questions
Answers to the questions practitioners most commonly ask about CPGs.
