§ Cybersecurity proof & diagnostic assets·free · browser-local

Score your baseline against the CISA CPGs.

Mark each Cross-Sector Cybersecurity Performance Goal as implemented, partial, not implemented, or not applicable. The scorecard returns coverage by goal family and your next three discussion items — the highest-impact goals you have not implemented yet. It runs entirely in your browser.

Discussion starters, not remediation advice or a compliance result. The CPGs are a voluntary baseline published by CISA. This scorecard describes each goal by outcome and family; it does not grade you against the goals or assert a compliance status.

About this asset

Audience
Leaders establishing a first baseline against CISA's voluntary Cross-Sector Cybersecurity Performance Goals.
Owner service
Free 30-Minute Cyber Risk Check
Classification
Classification: Public · Version 1.0 · July 2026
Methodology
Goals are organized into the eight CISA CPG goal families and stated as plain-language outcomes rather than reproduced verbatim goal identifiers, so no identifier is invented. Impact tags (High / Medium) reflect CISA's own qualitative cost, impact, and complexity framing and are used only to order the discussion items.
Limitations
Point-in-time, self-diagnostic scorecard you complete yourself. It is not a DSE assessment, an audit, an attestation, or legal advice, and it produces no compliance result, score of record, or certification.
Verification
The primary-source citation below was checked against the cisa.gov landing page for the Cross-Sector Cybersecurity Performance Goals. The goal families are cited to that source; DSE added no goal the source does not describe.
The scorecard

Mark each goal, read the coverage.

Set a status for every goal. Coverage is implemented goals divided by the goals that apply to you. The next three discussion items are the highest-impact goals still marked “Not implemented”.

Performance goal Impact Status

Talk through your next three moves.

Bring your scorecard to a free 30-minute Cyber Risk Check. We discuss the highest-impact gaps, the evidence you already hold, and the sequence — and scope a fixed-fee assessment only if it helps.

What this is and is not. The CPGs are a voluntary baseline, not a regulation and not a certification regime. This scorecard is a point-in-time self-diagnostic to start a conversation. It is not a DSE assessment, an audit, an attestation, legal advice, or a remediation plan, and marking goals “implemented” here asserts nothing to any third party.

Primary source, verified.