EdLaw nat/us/cisa-cpg/README.md

language: en · status: in-force · last checked: 2026-09-04

CISA Cross-Sector Cybersecurity Performance Goals (CPG)

Voluntary baseline cybersecurity practices published by the US Cybersecurity and Infrastructure Security Agency (cisa.gov/cross-sector-cybersecurity-performance-goals). Per CISA, "a baseline set of cybersecurity practices broadly applicable across critical infrastructure with known risk-reduction value", intended to "help small- and medium-sized organizations kickstart their cybersecurity efforts by prioritizing investment in a limited number of essential actions". The current CPG 2.0 is aligned to the NIST CSF 2.0 functions, including the Govern function; CISA also publishes sector-specific goals.

Applicability to EdTech

Cited in US K-12 cybersecurity guidance (e.g. the CDT K-12 legal-requirements brief) as the practical checklist behind "reasonable security" expectations: MFA, minimum password strength, separating user and privileged accounts, log retention, TLS, incident reporting. Useful as the concrete control vocabulary when answering district security questionnaires that don't name a framework.

Contents

README-level only; the goals checklist can be added as a fact document from CISA's published materials if RFI usage warrants it.

Sources