CISA CPG Crosswalk: Cybersecurity Performance Goals on Bidda ============================================================ JS-free text mirror for AI crawlers. Canonical page: https://bidda.com/cisa/cpg-crosswalk Last updated: 2026-08-04 ← BIDDA × CISA PROGRAM 3 OF 3 · READY CPG and Bidda Crosswalk The Cybersecurity Performance Goals (CPGs) are CISA's voluntary, prioritised baseline for cybersecurity in United States critical infrastructure. There are eight outcome areas, which apply to both information-technology and operational-technology environments and which are designed to be accessible to small and medium-sized operators. Bidda's executable compliance nodes resolve CPG outcomes into deterministic workflow steps traceable to primary regulatory sources. The eight CISA CPG outcome areas are Account Security, Device Security, Data Security, Governance and Training, Vulnerability Management, Supply Chain and Third Party, Response and Recovery, and Other (cross-cutting). This crosswalk is the lightweight, surface-level view. The full bidirectional mapping, in which per-node CPG anchors are attached to every relevant Bidda node, lives inside the registry itself and is queryable via the MCP tool get_crosswalk. BIDIRECTIONAL Both directions of the mapping work CPG TO EXECUTABLE WORKFLOW "How do I implement CPG 2.A device security?" Bidda resolves the question into the dependency chain of NIST SP 800-128, CIS Control 1 and IEC 62443-3-3 nodes, each of which has its own deterministic workflow and actionable schema. WORKFLOW TO CPG OUTCOME "Which CPG outcomes does this NIST control satisfy?" The Bidda node carries its CPG anchors as part of its crosswalks block, so a compliance officer sees exactly which CISA outcome each implemented control is delivering against. Eight outcome areas 1 Account Security Detect and prevent unauthorised access to accounts: unique credentials, MFA, revocation of old accounts, separating privileged accounts. BIDDA PILLARS Cybersecurity AI Governance & Law EXAMPLE NODES ▸ nist-sp-800-63b-digital-identity NIST SP 800-63B: Digital Identity ▸ nist-sp-800-205-access-control NIST SP 800-205: Access Control ▸ cis-controls-v8 CIS Controls v8 OUTCOME A defender can resolve the requirement to "implement CPG account security" into the specific executable workflow steps that Bidda has indexed against the authoritative standards. 2 Device Security Asset inventory, hardware/software inventory currency, secure configurations, default-deny on devices that touch the OT network. BIDDA PILLARS Cybersecurity Industrial IoT & Energy EXAMPLE NODES ▸ nist-sp-800-128-config-management NIST SP 800-128: Security-Focused Configuration Management ▸ iec-62443-4-2-component-security-2019 IEC 62443-4-2: Component Security Requirements ▸ isa-99-iec-62443-industrial-security-framework ISA-99 and IEC 62443: Industrial Security Framework OUTCOME Bidda exposes IT and OT device-security obligations as a single chain, with the IT control pointing to the OT control via the dependency graph. 3 Data Security Log collection, encryption at rest and in transit, segmentation, secure disposal, secrets management. BIDDA PILLARS Cybersecurity Banking & Global Finance Medical & Healthcare EXAMPLE NODES ▸ nist-sp-800-53-r5 NIST SP 800-53 Rev 5: Security and Privacy Controls ▸ pci-dss-v4-requirement-3 PCI DSS v4 Requirement 3: Protect Stored Account Data ▸ us-hipaa-45-cfr-164-312-technical-safeguards HIPAA 45 CFR 164.312: Technical Safeguards OUTCOME Domain-specific data-security obligations such as PCI for payments, HIPAA for health and GDPR for the European Union all resolve through the same CPG entry point. 4 Governance and Training Designate a security leader, board oversight, OT cyber leadership, security training for staff, mitigation against known exploited vulnerabilities (KEVs). BIDDA PILLARS Cybersecurity AI Governance & Law Workplace EXAMPLE NODES ▸ iso-iec-27001-2022-information-security-workflow ISO/IEC 27001:2022: Information Security Management ▸ nist-csf-2-0-govern-function NIST CSF 2.0: Govern Function (added in v2.0) ▸ iso-iec-42001-clause-7-support-resources ISO/IEC 42001 Clause 7: Support and Resources OUTCOME Bidda explicitly captures the CSF 2.0 Govern function alongside the original Identify, Protect, Detect, Respond and Recover spine, which remains unusual across competing registries. 5 Vulnerability Management Mitigate known exploited vulnerabilities (KEV catalogue), accept third-party vulnerability reports, do not roll your own crypto, no exploitable services on the public internet. BIDDA PILLARS Cybersecurity EXAMPLE NODES ▸ nist-sp-800-40r4-enterprise-patch-management NIST SP 800-40 Rev 4: Enterprise Patch Management ▸ nist-sp-800-216-vulnerability-disclosure-guidelines NIST SP 800-216: Vulnerability Disclosure Guidelines ▸ nis2-directive-article-12-coordinated-vulnerability-disclosure NIS2 Directive Article 12: Coordinated Vulnerability Disclosure OUTCOME A CPG-aligned vulnerability programme reduces to a small number of Bidda nodes, each with a deterministic workflow. 6 Supply Chain and Third Party Detect and respond to supplier incidents, supplier risk management, SBOM availability, no procurement of unsupported software. BIDDA PILLARS Cybersecurity Logistics & Supply Chain AI Governance & Law EXAMPLE NODES ▸ nist-sp-800-161-r1-supply-chain-risk-management NIST SP 800-161 Rev 1: Cyber Supply Chain Risk Management ▸ eu-cra-2024-2847-article-3-essential-requirements-products-digital-elements EU Cyber Resilience Act Article 3: Essential Requirements for Products with Digital Elements ▸ cisa-sbom-minimum-elements-2021 CISA SBOM Minimum Elements OUTCOME AI supply-chain risk, including model provenance, training-data software bill of materials and fine-tune lineage, is captured alongside conventional software supply chain inside the same registry. 7 Response and Recovery Incident reporting to CISA, incident response plan, system backups, OT cyber incident response, OT recovery plans. BIDDA PILLARS Cybersecurity Industrial IoT & Energy Banking & Global Finance EXAMPLE NODES ▸ nist-sp-800-61r3-incident-response-2024 NIST SP 800-61 Rev 3: Computer Security Incident Handling ▸ us-circia-cyber-incident-reporting-act-2022 CIRCIA: Cyber Incident Reporting for Critical Infrastructure (2022) ▸ dora-regulation-article-17-ict-related-incident-management-process EU DORA Article 17: ICT-Related Incident Management Process OUTCOME US incident-reporting obligations under CIRCIA and EU obligations under DORA are mapped together, so a multinational operator does not have to maintain two parallel runbooks. 8 Other (cross-cutting) Encompasses items that span IT and OT or that do not fit cleanly into the seven categories above, for example email security, OT default-deny on encrypted protocols, and network segmentation. BIDDA PILLARS Cybersecurity Telecoms & Digital Infrastructure EXAMPLE NODES ▸ nist-sp-800-177-trustworthy-email NIST SP 800-177: Trustworthy Email ▸ nist-sp-800-207-zero-trust NIST SP 800-207: Zero Trust Architecture ▸ iec-62443-iacs IEC 62443: Industrial Automation and Control Systems OUTCOME Cross-cutting CPG outcomes resolve into a small set of foundational architecture nodes covering zero trust, network segmentation and trustworthy email. HONEST SCOPE The example nodes named above are illustrative anchors. They are the nodes that most directly express each CPG outcome, and they are intended to give a defender an entry point into the registry. Hundreds of additional Bidda nodes contribute to each area in some form. The deep, per-node CPG annotation is built incrementally, and the full bidirectional crosswalk lives inside each node's crosswalks block where it is queryable via the free MCP tool. ← BACK TO CISA HUB BROWSE INTELLIGENCE FOREST → MCP GET_CROSSWALK →