CISA CPG 2.0

The Highest-Priority Control, Delivered.

Align with CISA CPG 2.0 using phishing-resistant MFA

CISA Cybersecurity Performance Goals 2.0 ranks hardware-based, phishing-resistant MFA as the highest-priority authentication control. TokenCore™ delivers FIDO2-certified, hardware-bound authentication that proves the authorized person before access is granted

No shared secret. No code to phish. No fallback.

CISA CPG 2.0 Masthead

The Framework

Baseline for Critical Infrastructure.

What is CISA CPG 2.0?

The Cybersecurity Performance Goals are CISA's prioritized baseline of security practices for critical infrastructure. Authentication sits near the top of the list.

Cybersecurity Performance Goals

A prioritized set of practices ranked by impact and effort. Guidance you can act on in order.

Critical Infrastructure Security

Written for the sectors the country runs on, where a breach carries real-world consequence.

Aligned to NIST CSF 2.0

The goals map to the NIST Cybersecurity Framework, so the work fits what you already run.

Federal Cybersecurity Expectations

CPG 2.0 signals where federal expectations are heading for infrastructure operators.

Voluntary. Increasingly Expected

Referenced widely across critical infrastructure and cyber insurance.

The Priority

CISA Ranked It First.

Why CISA prioritizes phishing-resistant MFA

CPG 2.0 does not treat all MFA as equal. It names hardware-based, phishing-resistant MFA as the control to reach first.

Goal 2.H - Phishing-Resistant MFA

MFA across every account, from privileged to remote to OT.

  • MFA across all IT accounts
  • Privileged access protection
  • Remote access requirements
  • OT environment requirements
Goal 2.H - Phishing-Resistant MFA

CISA's MFA Priority Ranking

Not all factors are equal. CISA ranks them, and hardware sits on top.

  • FIDO2 / WebAuthn
  • PKI authentication
  • Mobile soft tokens
  • SMS authentication
CISAs MFA Priority Ranking
image 233 (5)

The Guide

Map Every Goal.

Download the CISA CPG 2.0 Requirements Mapping Guide

The mapping guide lines up CISA CPG 2.0 goals against phishing-resistant FIDO2 authentication, goal by goal. A practical reference for critical infrastructure teams.

The Support

Every Goal, Grounded in Identity.

How TokenCore™ supports CISA CPG 2.0 goals

Goal 2.H - Phishing-Resistant MFA

Hardware-bound credentials and match-on-chip biometrics.

  • FIDO2-certified authentication
  • Hardware-bound credentials
  • Match-on-chip biometrics
  • Possession + inherence factors

Goal 2.D - Credential Revocation

Access removed the moment someone leaves.

  • Workforce departures
  • Immediate revocation
  • Credential lifecycle management

Goal 1.A - Asset Inventory

Every authenticator known, managed, and visible.

  • Authenticator inventory
  • Device management
  • Identity asset visibility

Goal 1.F - Third-Party Validation

Independently certified, not self-asserted.

  • FIDO certification
  • Independent verification
  • Security assurance

Account Security Goals

Passwordless access with no shared credentials to steal.

  • Passwordless authentication
  • Elimination of shared credentials
  • Authentication anomaly detection

Vendor and Third-Party Access

External and OT access held to the same proven standard.

  • Contractors
  • MSPs
  • OEM technicians
  • OT remote access

Beyond Legacy MFA

The Code Is the Weakness.

Why traditional MFA falls short

OTP Vulnerabilities

A one-time code can be entered by anyone who intercepts it. A shared secret is a secret an attacker can hold too.

Push Fatigue Attacks

Approval prompts can be worn down until someone taps yes. TokenCore™ has nothing to approve and nothing to pressure.

AiTM and Reverse Proxy Attacks

Relay pages capture codes in real time and pass them through. There is no code to relay when the fingerprint stays on the device.

Why FIDO2 Stops These Attacks

The credential is bound to the hardware and the person. Nothing to phish, nothing to reuse, nothing to send.

See It in Action

Make Identity Absolute

Strengthen security with CISA's highest-priority MFA control

See how TokenCore™ deploys hardware-based, phishing-resistant MFA that aligns with CISA guidance and closes the credential-based attack path across critical infrastructure.