CISA CPG 2.0
The Highest-Priority Control, Delivered.
Align with CISA CPG 2.0 using phishing-resistant MFA
CISA Cybersecurity Performance Goals 2.0 ranks hardware-based, phishing-resistant MFA as the highest-priority authentication control. TokenCore™ delivers FIDO2-certified, hardware-bound authentication that proves the authorized person before access is granted
No shared secret. No code to phish. No fallback.
The Framework
Baseline for Critical Infrastructure.
What is CISA CPG 2.0?
The Cybersecurity Performance Goals are CISA's prioritized baseline of security practices for critical infrastructure. Authentication sits near the top of the list.
Cybersecurity Performance Goals
A prioritized set of practices ranked by impact and effort. Guidance you can act on in order.
Critical Infrastructure Security
Written for the sectors the country runs on, where a breach carries real-world consequence.
Aligned to NIST CSF 2.0
The goals map to the NIST Cybersecurity Framework, so the work fits what you already run.
Federal Cybersecurity Expectations
CPG 2.0 signals where federal expectations are heading for infrastructure operators.
Voluntary. Increasingly Expected
Referenced widely across critical infrastructure and cyber insurance.
The Priority
CISA Ranked It First.
Why CISA prioritizes phishing-resistant MFA
CPG 2.0 does not treat all MFA as equal. It names hardware-based, phishing-resistant MFA as the control to reach first.
Goal 2.H - Phishing-Resistant MFA
MFA across every account, from privileged to remote to OT.
- MFA across all IT accounts
- Privileged access protection
- Remote access requirements
- OT environment requirements
CISA's MFA Priority Ranking
Not all factors are equal. CISA ranks them, and hardware sits on top.
- FIDO2 / WebAuthn
- PKI authentication
- Mobile soft tokens
- SMS authentication
.webp?width=560&height=726&name=image%20233%20(5).webp)
The Guide
Map Every Goal.
Download the CISA CPG 2.0 Requirements Mapping Guide
The mapping guide lines up CISA CPG 2.0 goals against phishing-resistant FIDO2 authentication, goal by goal. A practical reference for critical infrastructure teams.
The Support
Every Goal, Grounded in Identity.
How TokenCore™ supports CISA CPG 2.0 goals
Goal 2.H - Phishing-Resistant MFA
Hardware-bound credentials and match-on-chip biometrics.
- FIDO2-certified authentication
- Hardware-bound credentials
- Match-on-chip biometrics
- Possession + inherence factors
Goal 2.D - Credential Revocation
Access removed the moment someone leaves.
- Workforce departures
- Immediate revocation
- Credential lifecycle management
Goal 1.A - Asset Inventory
Every authenticator known, managed, and visible.
- Authenticator inventory
- Device management
- Identity asset visibility
Goal 1.F - Third-Party Validation
Independently certified, not self-asserted.
- FIDO certification
- Independent verification
- Security assurance
Account Security Goals
Passwordless access with no shared credentials to steal.
- Passwordless authentication
- Elimination of shared credentials
- Authentication anomaly detection
Vendor and Third-Party Access
External and OT access held to the same proven standard.
- Contractors
- MSPs
- OEM technicians
- OT remote access
Beyond Legacy MFA
The Code Is the Weakness.
Why traditional MFA falls short
OTP Vulnerabilities
A one-time code can be entered by anyone who intercepts it. A shared secret is a secret an attacker can hold too.
Push Fatigue Attacks
Approval prompts can be worn down until someone taps yes. TokenCore™ has nothing to approve and nothing to pressure.
AiTM and Reverse Proxy Attacks
Relay pages capture codes in real time and pass them through. There is no code to relay when the fingerprint stays on the device.
Why FIDO2 Stops These Attacks
The credential is bound to the hardware and the person. Nothing to phish, nothing to reuse, nothing to send.
See It in Action
Make Identity Absolute
Strengthen security with CISA's highest-priority MFA control
See how TokenCore™ deploys hardware-based, phishing-resistant MFA that aligns with CISA guidance and closes the credential-based attack path across critical infrastructure.