Skip to main content
Image coming soon

CISA Cross-Sector Cybersecurity Performance Goals 2.0 Evidence & Implementation Kit

$249.00
Adding to cart… The item has been added
CISA Cross-Sector Cybersecurity Performance Goals 2.0 · Evidence & Implementation Kit
Reach the CISA cybersecurity baseline fast, with every performance goal turned into a control you can adopt and evidence.
All 34 CPGs handed to you as adopt-ready controls, sequenced by cost and impact, with the exact evidence an assessor examines and the shortfall organizations most often show.
Baseline-ready in a weekend, not a quarter.

Here is the honest situation. The CISA CPGs are the practices the US government judges most impactful against the most common and dangerous cyber threats, and critical-infrastructure operators are increasingly expected to meet them. They are voluntary and outcome-focused, which is exactly the problem: turning 34 goals into concrete controls, evidence and a sequence of work is left to you. Reading the CPG report and mapping each goal to your environment takes time you would rather spend fixing things.

This Kit removes the interpretation. It is all 34 CPGs as adopt-ready controls you personalize in a weekend, each with the evidence an assessor examines and a cost-and-impact note to sequence the work.

What you get, the moment you buy

34
Goals as adopt-ready controls. Every CPG across govern, identify, protect, detect, respond and recover, written as implementable policy. Personalize and you are done.
34
Evidence-they-examine checklists. For each goal, exactly what an assessor examines, plus the shortfall organizations most often show, and the cost, impact and effort rating to prioritize.
1
CPG Control Matrix, pre-built. Every goal in a working spreadsheet, ready to record your implementation, status and evidence location.
1
Gap & Readiness Assessment. Score each goal and the workbook tells you your baseline readiness as a single percentage, and exactly what to fix next.

Grounded in the CISA CPG version 2.0 report, organized by the NIST Cybersecurity Framework functions, preserving the cost, impact and complexity ratings and the IT and OT distinctions. Editable Word and Excel files.

The floor, reached fast
The CPGs are a prioritized baseline, not a full framework. This Kit sequences them by cost and impact so you close the low-cost, high-impact gaps first, then build toward the NIST CSF or ISO 27001 from a solid floor.

What one control looks like

This is 3.A, Change Default Passwords, one of the highest-impact, lowest-cost goals. All 34 are built to this depth.

3.A Change Default Passwords PROTECT
Adopt this goal

[Organization] enforces an organization-wide policy that requires changing default manufacturer passwords on all hardware, software, and firmware before the asset connects to any internal or external network, including IT assets used in OT such as administration web pages. Where changing a default is not feasible, such as hard-coded control-system credentials, compensating controls are documented and network traffic and login logs are monitored.

Evidence an assessor examines
  • A written policy requiring default password changes before deployment
  • Configuration records showing default passwords changed on deployment
  • A list of assets with unchangeable defaults and their compensating controls
  • Monitoring logs for assets that retain default or hard-coded credentials
Common finding they raise: New devices and OT interfaces are connected with factory default credentials that are published online and trivially abused.

Why this is not another template pack

  • The evidence is the point. A goal list is not a program. This tells you exactly what an assessor examines and the shortfall organizations show, for every goal. That is what actually raises your security.
  • Sequenced by impact. Each goal carries its cost, impact and effort, so you fix the highest-value gaps first rather than working alphabetically.
  • Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
  • It compounds. The CPGs map to the NIST Cybersecurity Framework, so meeting them is a running start on the full CSF and on sector requirements.

Who buys this

Critical-infrastructure operators and small-to-mid organizations that need a credible security baseline fast, IT and OT security leads, and consultants raising a client's floor. Whether it is a first baseline or a gap-closing sprint, you save weeks and walk in with the goals and evidence structured.

By the end of the weekend you will have
✓  A control for every one of the 34 CPGs
✓  A completed CPG control matrix
✓  The evidence an assessor examines
✓  Your work sequenced by cost and impact
✓  A baseline readiness percentage and a fix list
✓  The common shortfalls closed

Common questions

Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.

Are the CPGs mandatory? They are voluntary goals published by CISA, though critical-infrastructure operators are increasingly expected to meet them. The Kit helps you adopt and evidence them.

Which version is this? CPG version 2.0, read from the primary CISA report, organized by the cybersecurity framework functions.

Does it cover OT? Yes. The IT and OT distinctions from the source are preserved in the controls and notes.

What if it is not for me? A 30-day money-back guarantee.

Do not leave the baseline as a to-do list.
Reaching it is fast when the goals are controls with evidence. The Kit is instant, and it is guaranteed.
Add it to your cart and hit the baseline this weekend.

Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com