Cross-Sector Cybersecurity Performance Goals (program page)
Published by Cybersecurity and Infrastructure Security Agency, U.S. Department of Homeland Security. Jurisdiction US.
Exactly what this source supports
These are the only claims this record is used to carry anywhere in the library.
CISA's Cross-Sector Cybersecurity Performance Goals 2.0 are a subset of cybersecurity practices aimed at meaningfully reducing risks to critical infrastructure operations and the American people.
claim cisa-cpg-program-page#c1Cross-Sector CPGs 2.0 have been updated to align to the NIST Cybersecurity Framework (CSF) 2.0 functions and build upon the foundation established in version 1.0.1, with the addition of the GOVERN function.
claim cisa-cpg-program-page#c2Net-new goals address managed service providers (MSPs), the principle of least privileges, and incident communication procedures.
claim cisa-cpg-program-page#c3The CPGs are intended as a baseline set of practices broadly applicable across critical infrastructure and a benchmark for operators to measure and improve.
claim cisa-cpg-program-page#c4Sector-Specific Goals are available now for the Chemical, Energy (Distribution and Distributed Energy Resources), Healthcare, and Information Technology sectors, with Financial Services SSGs listed as coming.
claim cisa-cpg-program-page#c5A new CSET assessment module for CPG 2.0 and an updated CPG 2.0 Checklist are noted as becoming available in Q1 2026.
claim cisa-cpg-program-page#c6These voluntary Cross-Sector CPGs strive to help small- and medium-sized organizations kickstart their cybersecurity efforts by prioritizing investment in a limited number of essential actions with high-impact security outcomes.
claim cisa-cpg-program-page#c7
Each claim above has its own address. Link to a single claim with/sources/cisa-cpg-program-page#c1, and read the same list with its identifiers, checksums and dates at cisa-cpg-program-page.json. A checksum lets you tell whether a claim you cited still says what it said.