{
  "$schema": "https://bestinsuranceresearch.com/llms-full.txt",
  "recordType": "source",
  "id": "cisa-cpg-2-0",
  "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0",
  "contentVersion": "2026.08.31",
  "generatedFor": "2026-09-06",
  "operator": {
    "legalName": "WJB Services, Inc.",
    "dba": "Bollinsure Insurance Services",
    "license": "6013787",
    "licenseAuthority": "California Department of Insurance"
  },
  "license": "Text on this page may be quoted with attribution and a link to the canonical URL.",
  "notice": "Public page facts only. This record contains no visitor question, no tool input, and no identifier. It is not a coverage determination, an eligibility decision, or individualized advice.",
  "title": "Cross-Sector Cybersecurity Performance Goals, Version 2.0",
  "publisher": "Cybersecurity and Infrastructure Security Agency, U.S. Department of Homeland Security",
  "url": "https://www.cisa.gov/sites/default/files/2025-12/CPG_Report_2.0_508c.pdf",
  "officialHost": true,
  "sourceType": "official-documentation",
  "authorityLevel": "secondary",
  "primary": true,
  "jurisdiction": "US",
  "publishedDate": "2025-12-01",
  "effectiveDate": "2025-12-01",
  "accessedDate": "2026-08-31",
  "lastChecked": "2026-08-31",
  "updateCadence": "major-revision",
  "status": "active",
  "supportsClaims": [
    {
      "claimId": "cisa-cpg-2-0#c1",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c1",
      "checksum": "d0dfff90adf6",
      "text": "Cover page reads Cross-Sector Cybersecurity Performance Goals, Version 2.0, December 2025, Cybersecurity and Infrastructure Security Agency; marked TLP:CLEAR."
    },
    {
      "claimId": "cisa-cpg-2-0#c2",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c2",
      "checksum": "25f6379a9be6",
      "text": "Contents are organized as 1. GOVERN, 2. IDENTIFY, 3. PROTECT, 4. DETECT, 5. RESPOND, 6. RECOVER, aligning to NIST Cybersecurity Framework version 2.0."
    },
    {
      "claimId": "cisa-cpg-2-0#c3",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c3",
      "checksum": "2a5d8f426ffc",
      "text": "Goal 1.C MAINTAIN INCIDENT RESPONSE PLANS: organizations develop, maintain, update, and regularly exercise IR plans; IR plans should be reviewed and drilled, at a minimum, on an annual basis."
    },
    {
      "claimId": "cisa-cpg-2-0#c4",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c4",
      "checksum": "c956a5ee9d73",
      "text": "Goal 1.D SUPPLY CHAIN INCIDENT REPORTING AND VULNERABILITY DISCLOSURE addresses notifying a customer of security incidents and vulnerabilities within a risk-informed time frame."
    },
    {
      "claimId": "cisa-cpg-2-0#c5",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c5",
      "checksum": "e7a23776afff",
      "text": "Goal 2.C MITIGATE KNOWN VULNERABILITIES: implement a vulnerability management program to patch and mitigate misconfigured software in a timely manner, covering all organizational assets including those that face the internet."
    },
    {
      "claimId": "cisa-cpg-2-0#c6",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c6",
      "checksum": "7aeadbff56f9",
      "text": "Goal 3.D REVOKE CREDENTIALS FOR DEPARTING STAFF: a defined and enforced administrative process to offboard staff including revocation of all access; review user access and disable accounts when inactive for a specified period, for example 30 days."
    },
    {
      "claimId": "cisa-cpg-2-0#c7",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c7",
      "checksum": "ae7bd6f78e55",
      "text": "Goal 3.F IMPLEMENT MULTIFACTOR AUTHENTICATION (MFA): organizations require MFA to access assets using the strongest available method; options sorted high to low are phishing-resistant MFA, then mobile app-based soft tokens, then SMS or voice only when no other options are possible; all IT accounts leverage MFA, prioritizing privileged administrative accounts."
    },
    {
      "claimId": "cisa-cpg-2-0#c8",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c8",
      "checksum": "225eb0ff605e",
      "text": "Goal 3.H IMPLEMENT THE PRINCIPLES OF LEAST PRIVILEGE: user accounts do not have administrator privileges, administrators maintain separate user accounts for non-admin activity, and privileges are re-evaluated on a recurring basis to validate continued need."
    },
    {
      "claimId": "cisa-cpg-2-0#c9",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c9",
      "checksum": "11366cd1355b",
      "text": "Goal 3.J IMPLEMENT CYBERSECURITY TRAINING: new employees receive initial cybersecurity training prior to accessing computer systems, and at least annual cybersecurity training is provided for all organizational users covering recognizing social engineering, reporting suspicious activity, and basic cyber hygiene."
    },
    {
      "claimId": "cisa-cpg-2-0#c10",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c10",
      "checksum": "b0e7cf6677a0",
      "text": "Goal 3.M ENABLE EMAIL SECURITY: on all corporate email infrastructure STARTTLS is enabled, SPF and DKIM are enabled, and DMARC is enabled and set to reject."
    },
    {
      "claimId": "cisa-cpg-2-0#c11",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c11",
      "checksum": "7db37bd28e3f",
      "text": "Goal 3.O MAINTAIN SYSTEM BACKUPS AND RESTORATION ABILITY: develop a list of all maintained backups including installation media, license keys, configuration information, and retention period; securely store backups offsite and offline; test backups and recovery on a recurring basis, no less than once per year; validate the integrity of backups before initiating restoration."
    },
    {
      "claimId": "cisa-cpg-2-0#c12",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c12",
      "checksum": "783b826786d1",
      "text": "Goal 4.A ESTABLISH MALICIOUS CODE DETECTION: implement signature-based and non-signature-based mechanisms to detect and eradicate malicious code at system endpoints, organization-wide."
    },
    {
      "claimId": "cisa-cpg-2-0#c13",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c13",
      "checksum": "34380437b864",
      "text": "Goal 4.B IDENTIFY ADVERSE EVENTS: define clear criteria and processes for adverse events, and if an adverse event is suspected follow the protocol outlined in the incident response plan to escalate."
    },
    {
      "claimId": "cisa-cpg-2-0#c14",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c14",
      "checksum": "e2948afba431",
      "text": "The CPGs are voluntary and strive to help small- and medium-sized organizations kickstart cybersecurity efforts by prioritizing a limited number of essential actions."
    },
    {
      "claimId": "cisa-cpg-2-0#c15",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c15",
      "checksum": "3f6f5b22a65e",
      "text": "Goal 1.A ESTABLISH CYBERSECURITY RESPONSIBILITIES: roles, responsibilities, and authorities related to the organization's cybersecurity program are established, communicated, enforced, and aligned within the organization and external partners, and all roles and responsibilities involving cybersecurity should be documented in an organization's cybersecurity policy; scope reaches C-suite personnel, critical section leadership, physical and cybersecurity personnel, third-party contractors, vendors, and suppliers; NIST CSF 2.0 reference GV.RR-02."
    },
    {
      "claimId": "cisa-cpg-2-0#c16",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c16",
      "checksum": "9382f6554f78",
      "text": "Goal 1.B MANAGE CYBERSECURITY OVERSIGHT is a separate goal: policies for managing the cybersecurity program are reviewed at least annually, updated when changes are applied, communicated, and enforced; NIST CSF 2.0 reference GV.OV-03."
    },
    {
      "claimId": "cisa-cpg-2-0#c17",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c17",
      "checksum": "5960638dc5f2",
      "text": "Goal 2.A MANAGE ORGANIZATIONAL ASSETS: maintain a regularly updated inventory of all organizational assets, meaning data, hardware, software, systems, facilities, and personnel, with IT and OT assets determined to be critical for business or operational functions updated on a more frequent basis."
    },
    {
      "claimId": "cisa-cpg-2-0#c18",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c18",
      "checksum": "1fbb980c0d91",
      "text": "Goal 3.K UTILIZE STRONG ENCRYPTION: use encryption, digital signatures, and cryptographic hashes to protect the confidentiality and integrity of network communications, and identify critical electronic file types and data to protect while in transit and at rest, which may include personally identifiable information and sensitive, proprietary or trade secret information."
    },
    {
      "claimId": "cisa-cpg-2-0#c19",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c19",
      "checksum": "876f515fa61d",
      "text": "Goal 2.B MITIGATE KNOWN VULNERABILITIES: implement a vulnerability management program to patch and mitigate misconfigured software in a timely manner, with a scope of all organizational assets, to include those that face the internet; monitor risk response progress through tools such as plan of action and milestones, risk registers, and risk detail reports; assign responsibilities and ensure procedures are followed. Goal 2.C is a different goal, OBTAIN INDEPENDENT VALIDATION OF CYBERSECURITY CONTROLS."
    },
    {
      "claimId": "cisa-cpg-2-0#c20",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c20",
      "checksum": "44da0283e7bc",
      "text": "Goal 3.G ADMINISTRATORS MAINTAIN SEPARATE USER AND PRIVILEGED ACCOUNTS: user accounts do not have administrator privileges, administrators maintain separate user accounts for activities unrelated to their admin role, such as business email and web browsing, and privileges are re-evaluated on a recurring basis to validate continued need for a given set of permissions."
    },
    {
      "claimId": "cisa-cpg-2-0#c21",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c21",
      "checksum": "45ef0e613f06",
      "text": "Goal 3.H IMPLEMENT THE PRINCIPLES OF LEAST PRIVILEGE: all user accounts, system roles, and processes operate with the minimum privileges necessary to perform their tasks, and quarterly reviews of access permissions and role assignments are performed to verify compliance with established policies."
    },
    {
      "claimId": "cisa-cpg-2-0#c22",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c22",
      "checksum": "f3a3603ede30",
      "text": "Goal 3.L ENABLE EMAIL SECURITY: on all corporate email infrastructure (1) STARTTLS is enabled, (2) Sender Policy Framework (SPF) and DomainKeys Identified Mail (DKIM) are enabled, and (3) Domain-based Message Authentication, Reporting, and Conformance (DMARC) is enabled and set to reject; the stated outcome is reduced risk from spoofing, phishing, and interception. Goal 3.M is a different goal, DISABLE AUTORUN AND MACROS BY DEFAULT."
    },
    {
      "claimId": "cisa-cpg-2-0#c23",
      "canonicalUrl": "https://bestinsuranceresearch.com/sources/cisa-cpg-2-0#c23",
      "checksum": "b47b8ffdefb3",
      "text": "On small organizations the PDF says only that each organization faces unique cybersecurity challenges and that small- and medium-sized organizations may have limited budgets, staffing, and expertise; one of the stated criteria for a goal is that it be reasonably straightforward and not cost-prohibitive for small- and medium-sized entities to successfully implement. The voluntary and kickstart framing quoted in this module comes from the CISA program page, not from this PDF."
    }
  ],
  "reliedOnBy": [
    {
      "kind": "Example",
      "title": "Reading the HIPAA notification rule against the CISA and NIST control cadences to see why one is a ceiling and the others are intervals",
      "url": "https://bestinsuranceresearch.com/examples/breach-clock-is-a-ceiling-not-a-cadence"
    },
    {
      "kind": "Module",
      "title": "Cyber Control Readiness (33 checks)",
      "url": "https://bestinsuranceresearch.com/tools/cyber-control-readiness"
    }
  ],
  "reliedOnByCount": 2,
  "citation": {
    "text": "Cybersecurity and Infrastructure Security Agency, U.S. Department of Homeland Security. \"Cross-Sector Cybersecurity Performance Goals, Version 2.0.\" 2025-12-01. https://www.cisa.gov/sites/default/files/2025-12/CPG_Report_2.0_508c.pdf (retrieved 2026-08-31).",
    "viaThisSite": "BestInsurance Research source record cisa-cpg-2-0, content version 2026.08.31. https://bestinsuranceresearch.com/sources/cisa-cpg-2-0",
    "note": "Cite the underlying source when you can. Cite this record when you are describing our synthesis or our claim list."
  }
}
