Bidda Sovereign Intelligence · 10,108 Verified Nodes · 39 Sovereign Pillars

CISA CPG Crosswalk on Bidda

CISA's voluntary Cybersecurity Performance Goals (CPGs) mapped bidirectionally to Bidda's executable compliance nodes across all eight outcome areas, queryable in both directions through the registry.

← BIDDA × CISA
PROGRAM 3 OF 3 · READY
CPG and Bidda Crosswalk

The Cybersecurity Performance Goals (CPGs) are CISA's voluntary, prioritised baseline for cybersecurity in United States critical infrastructure. There are eight outcome areas, which apply to both information-technology and operational-technology environments and which are designed to be accessible to small and medium-sized operators. Bidda's executable compliance nodes resolve CPG outcomes into deterministic workflow steps traceable to primary regulatory sources.

The eight CISA CPG outcome areas are Account Security, Device Security, Data Security, Governance and Training, Vulnerability Management, Supply Chain and Third Party, Response and Recovery, and Other (cross-cutting).

This crosswalk is the lightweight, surface-level view. The full bidirectional mapping, in which per-node CPG anchors are attached to every relevant Bidda node, lives inside the registry itself and is queryable via the MCP tool get_crosswalk.

BIDIRECTIONAL

Both directions of the mapping work

CPG TO EXECUTABLE WORKFLOW

"How do I implement CPG 2.A device security?"

Bidda resolves the question into the dependency chain of NIST SP 800-128, CIS Control 1 and IEC 62443-3-3 nodes, each of which has its own deterministic workflow and actionable schema.

WORKFLOW TO CPG OUTCOME

"Which CPG outcomes does this NIST control satisfy?"

The Bidda node carries its CPG anchors as part of its crosswalks block, so a compliance officer sees exactly which CISA outcome each implemented control is delivering against.

Eight outcome areas
1
Account Security

Detect and prevent unauthorised access to accounts: unique credentials, MFA, revocation of old accounts, separating privileged accounts.

BIDDA PILLARS

Cybersecurity
AI Governance & Law

EXAMPLE NODES


nist-sp-800-63b-digital-identity
NIST SP 800-63B: Digital Identity

nist-sp-800-205-access-control
NIST SP 800-205: Access Control

cis-controls-v8
CIS Controls v8

OUTCOME

A defender can resolve the requirement to "implement CPG account security" into the specific executable workflow steps that Bidda has indexed against the authoritative standards.

2
Device Security

Asset inventory, hardware/software inventory currency, secure configurations, default-deny on devices that touch the OT network.

BIDDA PILLARS

Cybersecurity
Industrial IoT & Energy

EXAMPLE NODES


nist-sp-800-128-config-management
NIST SP 800-128: Security-Focused Configuration Management

iec-62443-4-2-component-security-2019
IEC 62443-4-2: Component Security Requirements

isa-99-iec-62443-industrial-security-framework
ISA-99 and IEC 62443: Industrial Security Framework

OUTCOME

Bidda exposes IT and OT device-security obligations as a single chain, with the IT control pointing to the OT control via the dependency graph.

3
Data Security

Log collection, encryption at rest and in transit, segmentation, secure disposal, secrets management.

BIDDA PILLARS

Cybersecurity
Banking & Global Finance
Medical & Healthcare

EXAMPLE NODES


nist-sp-800-53-r5
NIST SP 800-53 Rev 5: Security and Privacy Controls

pci-dss-v4-requirement-3
PCI DSS v4 Requirement 3: Protect Stored Account Data

us-hipaa-45-cfr-164-312-technical-safeguards
HIPAA 45 CFR 164.312: Technical Safeguards

OUTCOME

Domain-specific data-security obligations such as PCI for payments, HIPAA for health and GDPR for the European Union all resolve through the same CPG entry point.

4
Governance and Training

Designate a security leader, board oversight, OT cyber leadership, security training for staff, mitigation against known exploited vulnerabilities (KEVs).

BIDDA PILLARS

Cybersecurity
AI Governance & Law
Workplace

EXAMPLE NODES


iso-iec-27001-2022-information-security-workflow
ISO/IEC 27001:2022: Information Security Management

nist-csf-2-0-govern-function
NIST CSF 2.0: Govern Function (added in v2.0)

iso-iec-42001-clause-7-support-resources
ISO/IEC 42001 Clause 7: Support and Resources

OUTCOME

Bidda explicitly captures the CSF 2.0 Govern function alongside the original Identify, Protect, Detect, Respond and Recover spine, which remains unusual across competing registries.

5
Vulnerability Management

Mitigate known exploited vulnerabilities (KEV catalogue), accept third-party vulnerability reports, do not roll your own crypto, no exploitable services on the public internet.

BIDDA PILLARS

Cybersecurity

EXAMPLE NODES


nist-sp-800-40r4-enterprise-patch-management
NIST SP 800-40 Rev 4: Enterprise Patch Management

nist-sp-800-216-vulnerability-disclosure-guidelines
NIST SP 800-216: Vulnerability Disclosure Guidelines

nis2-directive-article-12-coordinated-vulnerability-disclosure
NIS2 Directive Article 12: Coordinated Vulnerability Disclosure

OUTCOME

A CPG-aligned vulnerability programme reduces to a small number of Bidda nodes, each with a deterministic workflow.

6
Supply Chain and Third Party

Detect and respond to supplier incidents, supplier risk management, SBOM availability, no procurement of unsupported software.

BIDDA PILLARS

Cybersecurity
Logistics & Supply Chain
AI Governance & Law

EXAMPLE NODES


nist-sp-800-161-r1-supply-chain-risk-management
NIST SP 800-161 Rev 1: Cyber Supply Chain Risk Management

eu-cra-2024-2847-article-3-essential-requirements-products-digital-elements
EU Cyber Resilience Act Article 3: Essential Requirements for Products with Digital Elements

cisa-sbom-minimum-elements-2021
CISA SBOM Minimum Elements

OUTCOME

AI supply-chain risk, including model provenance, training-data software bill of materials and fine-tune lineage, is captured alongside conventional software supply chain inside the same registry.

7
Response and Recovery

Incident reporting to CISA, incident response plan, system backups, OT cyber incident response, OT recovery plans.

BIDDA PILLARS

Cybersecurity
Industrial IoT & Energy
Banking & Global Finance

EXAMPLE NODES


nist-sp-800-61r3-incident-response-2024
NIST SP 800-61 Rev 3: Computer Security Incident Handling

us-circia-cyber-incident-reporting-act-2022
CIRCIA: Cyber Incident Reporting for Critical Infrastructure (2022)

dora-regulation-article-17-ict-related-incident-management-process
EU DORA Article 17: ICT-Related Incident Management Process

OUTCOME

US incident-reporting obligations under CIRCIA and EU obligations under DORA are mapped together, so a multinational operator does not have to maintain two parallel runbooks.

8
Other (cross-cutting)

Encompasses items that span IT and OT or that do not fit cleanly into the seven categories above, for example email security, OT default-deny on encrypted protocols, and network segmentation.

BIDDA PILLARS

Cybersecurity
Telecoms & Digital Infrastructure

EXAMPLE NODES


nist-sp-800-177-trustworthy-email
NIST SP 800-177: Trustworthy Email

nist-sp-800-207-zero-trust
NIST SP 800-207: Zero Trust Architecture

iec-62443-iacs
IEC 62443: Industrial Automation and Control Systems

OUTCOME

Cross-cutting CPG outcomes resolve into a small set of foundational architecture nodes covering zero trust, network segmentation and trustworthy email.

HONEST SCOPE

The example nodes named above are illustrative anchors. They are the nodes that most directly express each CPG outcome, and they are intended to give a defender an entry point into the registry. Hundreds of additional Bidda nodes contribute to each area in some form. The deep, per-node CPG annotation is built incrementally, and the full bidirectional crosswalk lives inside each node's crosswalks block where it is queryable via the free MCP tool.

← BACK TO CISA HUB
BROWSE INTELLIGENCE FOREST →
MCP GET_CROSSWALK →

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.