HHemanth Vishnu Akula

CISA Cross-Sector Performance Goals,
aligned and scored without the guesswork.

The US baseline of high-impact cybersecurity practices, drawn from the NIST CSF and built for organisations that need somewhere clear to start. I run the assessment alongside your team, measure where you stand and hand you a scored posture you own, not a certificate.

A voluntary baseline, not a box-tick.

The Cross-Sector Cybersecurity Performance Goals are published by CISA, the US Cybersecurity and Infrastructure Security Agency. They distil a large body of guidance into a prioritised set of high-impact practices, organised around the NIST Cybersecurity Framework. For a growing business they are the fastest, clearest way to understand where your security actually stands and what to fix first.

CISA is explicit that the CPGs are not a certification programme. They are a voluntary starting point, which is exactly what makes them useful. My job is to align you against them, run a proper gap analysis and give you a scored posture and evidence you can put in front of insurers, tenders and due-diligence reviews.

The NIST CSF functions, made practical.

Govern

Organisational governance

Cyber governance and accountability set at the top, so security has an owner and a mandate.

Identify

Asset & risk visibility

A clear picture of the assets you hold and the risks they carry, because you cannot protect what you cannot see.

Protect

Core safeguards

The practical controls that stop most attacks: multi-factor authentication, strong passwords and staff training.

Detect

Threat detection

The means to spot threats and intrusions early, before a small problem becomes a serious one.

Respond & Recover

Response & recovery

A tested incident response plan, backed by reliable backups and recovery, so you can respond calmly and get back on your feet.

Six functions, aligned to the NIST CSF, in one scored posture you keep.
Talk it through

Where the CPGs fit for you.

Your baseline

CPGs as your baseline

A voluntary baseline that sits below the heavier US regimes and gives US SMBs and critical-infrastructure suppliers a clear, prioritised place to start.

  • Prioritised, high-impact practices to work through first
  • No maturity levels to interpret and no audit to pass
  • The right fit if you do not yet need CMMC
  • A scored posture you own, ready for insurers and tenders
The path onward

Growing into CMMC & 800-171

Because the CPGs map cleanly up to the full NIST CSF, the work you do here carries forward into the heavier US regimes when your obligations grow.

  • A clean mapping up to the full NIST CSF
  • Groundwork that carries into NIST SP 800-171
  • A sensible on-ramp toward CMMC when it applies
  • No wasted effort if your requirements change later

Thinking about CISA CPG v2.0? Let’s map a realistic path in a free 20-minute call.

Start with an assessment

Done with you, not handed over a wall.

01 · Assess

Know where you stand

We scope your environment and run the assessment together in CISA’s free CSET tool, so you see exactly where you meet the goals and where you don’t.

02 · Align

Close the gaps together

I walk your team through each gap in plain English and prioritise the fixes by impact, gathering the evidence as we go.

03 · Report

A posture you own

You end with a scored gap report from CSET, a prioritised roadmap and an evidence pack you keep, not a certificate.

More than a scored assessment.

  • A scored CPG assessment run in CSET
  • A prioritised remediation roadmap
  • An evidence pack you own and keep
  • A clear map to the NIST CSF
  • A path toward 800-171 or CMMC if you need it
  • A re-assessment reminder, so your posture stays current

The things buyers usually ask.

Is this a certification?

No. CISA is explicit that the Cross-Sector Performance Goals are not a certification programme. This is a voluntary alignment and assessment engagement: you come away with a scored posture, a gap analysis and an evidence pack you own, rather than a certificate or badge.

How does it relate to CMMC and NIST 800-171?

The CPGs sit as a voluntary baseline below the heavier US regimes such as CMMC and NIST SP 800-171. Because they are organised around the NIST Cybersecurity Framework, the work maps cleanly upward, so aligning to the CPGs is a sensible on-ramp if you later need to meet those requirements.

Who is it for?

US small and medium-sized businesses and critical-infrastructure suppliers that want a clear, prioritised place to start, and that do not yet need the full weight of CMMC or 800-171. It is the right starting point when you want to know where you stand and what to fix first.

Is CSET free?

Yes. CISA provides the Cyber Security Evaluation Tool free of charge, and it is what we use to run and score the assessment. My role is to run it well alongside you, interpret the results and turn them into a roadmap you can act on.

How long does it take?

Most organisations complete an assessment within three to five weeks. It depends on the size of your environment and how quickly your team can gather evidence and work through the priority fixes.

Ready to see where you stand against the CPGs?

Tell me a little about your organisation and I’ll map a realistic path to a scored posture you own. A free 20-minute call, no obligation.

Start with an assessment