Score your baseline against the CISA CPGs.
Mark each Cross-Sector Cybersecurity Performance Goal as implemented, partial, not implemented, or not applicable. The scorecard returns coverage by goal family and your next three discussion items — the highest-impact goals you have not implemented yet. It runs entirely in your browser.
Discussion starters, not remediation advice or a compliance result. The CPGs are a voluntary baseline published by CISA. This scorecard describes each goal by outcome and family; it does not grade you against the goals or assert a compliance status.
Mark each goal, read the coverage.
Set a status for every goal. Coverage is implemented goals divided by the goals that apply to you. The next three discussion items are the highest-impact goals still marked “Not implemented”.
Coverage by goal family
| Goal family | Implemented | Partial | Not implemented | N/A | Coverage |
|---|
Next three discussion items
Talk through your next three moves.
Bring your scorecard to a free 30-minute Cyber Risk Check. We discuss the highest-impact gaps, the evidence you already hold, and the sequence — and scope a fixed-fee assessment only if it helps.
What this is and is not. The CPGs are a voluntary baseline, not a regulation and not a certification regime. This scorecard is a point-in-time self-diagnostic to start a conversation. It is not a DSE assessment, an audit, an attestation, legal advice, or a remediation plan, and marking goals “implemented” here asserts nothing to any third party.
Primary source, verified.