✳ US · CISA Cross-Sector CPGs

CISA Cross-Sector CPGs: voluntary prioritized practices (not a law, not FISMA)

An educational overview of CISA Cross-Sector Cybersecurity Performance Goals version 2.0: voluntary prioritized practices for critical infrastructure, including IT and OT themes. Not a law, not FISMA, and not a certification.

US · CISA Cross-Sector CPGsGuidance explainerLast reviewed

What category of goals this is

CISA Cross-Sector Cybersecurity Performance Goals (CPGs) are a voluntary subset of cybersecurity practices. CISA says they were selected with industry, government, and expert consultation to meaningfully reduce risks to critical infrastructure operations and to the public. They are aimed especially at helping small- and medium-sized organizations prioritize a limited number of essential, high-impact actions.

The hub says the goals are intended to be a baseline set of practices with known risk-reduction value, a benchmark for measuring and improving maturity, recommended practices for information technology (IT) and operational technology (OT) owners, and practices that also consider aggregate national risk, not only risk to a single organization. That is a prioritized starting set. It is not a comprehensive control encyclopedia.

Edition pin

Teach Cross-Sector CPGs version 2.0 (CPG 2.0). CISA's news release is dated 11 December 2025. The CPG 2.0 Report resource page lists Revision Date December 11, 2025. CPG 2.0 builds on the foundation of version 1.0.1. The hub says the update aligns the goals to NIST Cybersecurity Framework (CSF) 2.0 functions, including added emphasis on the GOVERN function.

Re-open the hub, the CPG 2.0 page, and the report at publish. If a newer version appears, update this pin and treat the older claim as UNKNOWN. The hub also says a CSET assessment module and an updated checklist were planned for Q1 2026. Whether those tools are live is UNKNOWN on this page. This lesson is not that assessment.

What voluntary means

The Public sector path already says these are voluntary prioritized practices, not a universal legal mandate for public agencies. Adopting CPGs can be smart risk prioritization. Doing so does not, by itself, prove a FISMA program is complete, create a certification, or replace a sector-specific legal duty.

CISA's 11 December 2025 news encourages organizations to adopt the voluntary Cross-Sector CPGs. Voluntary is the category. A goal set is not a statute, and it is not an Authorization.

CPG 2.0 themes, not a worksheet

The hub highlights a few literacy themes. Governance and leadership accountability sit under GOVERN. IT and OT goals are consolidated so one shared structure covers both, instead of treating them as separate silos. Newer goal themes include oversight, managed service provider (MSP) risk, least privilege, and incident communication. The report adds Cost, Impact, and Ease of Implementation ratings to support prioritization.

Those are categories. This page does not turn the goal list, the ratings, or a checklist into an Atlas gap assessment. The official report and checklist live on cisa.gov.

Sector-specific goals are a different overlay

The hub also describes Sector-Specific Goals that build on the Cross-Sector CPGs. Which sectors are listed, and which lines still say coming soon, can go stale. Treat the live inventory as UNKNOWN until you re-open the hub. Those overlays are not the body of this page.

For healthcare, prefer the HHS healthcare cybersecurity performance goals already cited on the Healthcare path. Do not expand a CISA healthcare sector overlay into a second Atlas article.

Same-category siblings, not this page

HHS publishes voluntary healthcare and public-health Cybersecurity Performance Goals. HHS says they were built off the chassis of CISA's CPGs to help healthcare organizations prioritize high-impact practices. They are a sibling set. They are not a HIPAA certification, and they are not this Cross-Sector page.

CISA Protecting Our Future is recommendations to help K-12 organizations prioritize security investments, recovery, and collaboration. The report encourages near-term progression toward CISA's Cybersecurity Performance Goals, and longer-term maturity with the NIST Cybersecurity Framework. Following that report is not a FERPA certification. It is not a duplicate of this page, and Atlas does not give it a separate explainer in this wave.

Related tools, different jobs

CSF 2.0 is outcomes language. Alignment to CSF functions, including GOVERN, does not make CPGs into CSF, and it does not make CSF into FISMA. SP 800-53 is a security and privacy control catalog to select and tailor from. SP 800-82 Rev. 3 is OT security guidance. FedRAMP is a federal cloud product Authorization program. None of those is a CPG certificate, and none of them is replaced by reading this page.

FISMA is the statutory and program backdrop for federal agency information security management. A voluntary goal set is a different category. A plant Authorization and an agency Authorization to Operate are also different objects. This lesson issues neither.

Rewrite the one-line claim

Replace "we are CPG and FISMA compliant" with this sentence: we use Cross-Sector CPG 2.0 as voluntary prioritized practices, which is not the same category as a FISMA program duty.

At work, privately ask the risk owner which prioritized goals, if any, the organization tracks, and which legal or program lane actually applies. Do not paste internal worksheet scores or sensitive gaps into Atlas.

CPGs are not a mandate, not FISMA, and not a certificate

Teaching table only. It does not assign a legal duty, a FISMA result, a FedRAMP Authorization, or a plant or agency certificate.

Phrases people fold into one CPG badge. Not a mandate, and not a seal.
Phrase people sayLiteracy correction
CPGs are federal law, or a FISMA mandate.CPGs are voluntary CISA goals. FISMA is a different statutory and program lane. Goals are not a universal legal mandate. Atlas card: /learn/explainers/fisma/.
We follow CPGs, so the plant or agency is certified.No CPG certificate comes from Atlas or from following the PDF. Completing this lesson is not a plant Authorization or an agency Authorization to Operate.
CPGs are a FedRAMP Authorization.FedRAMP is the federal cloud product Authorization program. Different object. Atlas card: /learn/explainers/fedramp/.
CPGs replace CSF, SP 800-53, or SP 800-82.CSF 2.0 is outcomes language. SP 800-53 is a control catalog. SP 800-82 is OT security guidance. Related tools, different jobs. Cards: /reference/frameworks/nist-csf-2-0/ and /learn/explainers/sp-800-82/.
A public agency, hospital, or school is covered because CPGs exist.Coverage and legal duty questions go to counsel, the privacy officer, or the authorizing owner. Goals are not an automatic mandate. HHS healthcare CPGs and Protecting Our Future are sibling guidance, not this page.

Claims to retire

CPGs are a law, or a FISMA substitute.

Cross-Sector CPGs are voluntary CISA goals. FISMA is a different statutory and program lane. A goal set is not a mandate.

We follow CPGs, so we are certified or Authorized.

There is no CPG certificate from Atlas, and none from following the PDF. Completing this lesson is not a plant Authorization or an agency Authorization to Operate.

CPGs are only for huge critical infrastructure operators.

CISA frames the goals as a kickstart for small- and medium-sized organizations as well as a baseline for critical infrastructure operators of any size.

HHS healthcare CPGs, or the K-12 Protecting Our Future report, are this same page.

Those are same-category siblings. HHS goals are healthcare prioritized practices built on the CISA chassis. Protecting Our Future is K-12 recommendations. Neither one is the Cross-Sector CPG 2.0 page.

Finishing this lesson is a CPG determination, or a FedRAMP Authorization.

Atlas does not issue CPG compliance seals or FedRAMP Authorizations. FedRAMP is a cloud Authorization program. This page is voluntary goal literacy.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.