Cross-Sector Cybersecurity Performance Goals (CPGs)

Cybersecurity and Infrastructure Security Agency (CISA)

A strategic framework outlining prioritized cybersecurity practices that help organizations reduce cyber risk, improve resilience, and strengthen critical infrastructure security across all sectors.
Executive summary
Developed by CISA in collaboration with government and industry partners, the Cross-Sector Cybersecurity Performance Goals (CPGs) establish a voluntary baseline of high-impact cybersecurity practices for organizations of all sizes.
The framework focuses on measurable actions that improve governance, asset visibility, identity management, vulnerability management, incident response, and recovery planning. Designed to complement existing standards such as the NIST Cybersecurity Framework, the CPGs help organizations prioritize investments and build stronger cyber resilience across critical infrastructure sectors.