Here is the honest situation. The CISA CPGs are the practices the US government judges most impactful against the most common and dangerous cyber threats, and critical-infrastructure operators are increasingly expected to meet them. They are voluntary and outcome-focused, which is exactly the problem: turning 34 goals into concrete controls, evidence and a sequence of work is left to you. Reading the CPG report and mapping each goal to your environment takes time you would rather spend fixing things.
This Kit removes the interpretation. It is all 34 CPGs as adopt-ready controls you personalize in a weekend, each with the evidence an assessor examines and a cost-and-impact note to sequence the work.
What you get, the moment you buy
Grounded in the CISA CPG version 2.0 report, organized by the NIST Cybersecurity Framework functions, preserving the cost, impact and complexity ratings and the IT and OT distinctions. Editable Word and Excel files.
What one control looks like
This is 3.A, Change Default Passwords, one of the highest-impact, lowest-cost goals. All 34 are built to this depth.
Why this is not another template pack
- The evidence is the point. A goal list is not a program. This tells you exactly what an assessor examines and the shortfall organizations show, for every goal. That is what actually raises your security.
- Sequenced by impact. Each goal carries its cost, impact and effort, so you fix the highest-value gaps first rather than working alphabetically.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The CPGs map to the NIST Cybersecurity Framework, so meeting them is a running start on the full CSF and on sector requirements.
Who buys this
Critical-infrastructure operators and small-to-mid organizations that need a credible security baseline fast, IT and OT security leads, and consultants raising a client's floor. Whether it is a first baseline or a gap-closing sprint, you save weeks and walk in with the goals and evidence structured.
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
Are the CPGs mandatory? They are voluntary goals published by CISA, though critical-infrastructure operators are increasingly expected to meet them. The Kit helps you adopt and evidence them.
Which version is this? CPG version 2.0, read from the primary CISA report, organized by the cybersecurity framework functions.
Does it cover OT? Yes. The IT and OT distinctions from the source are preserved in the controls and notes.
What if it is not for me? A 30-day money-back guarantee.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com