Are you CISA-ready? The 2-minute check
Eight questions, two minutes. Scored against the control areas CISA's guidance emphasizes first — assets, KEV patching, MFA, response, logging, backups, segmentation.
What a CPG gap assessment actually includes
A CPG gap assessment is a dry run against CISA's Cybersecurity Performance Goals: a consultant tests your program against the goals and hands you a prioritized remediation list. It is not an audit and produces no certificate — its product is the gap list. Our estimates put it at $15,000–$50,000 depending on size and scope — often the highest-ROI spend in the program, because it prevents buying the wrong implementation work.
The 2-minute quiz
1. Do you have a complete, current inventory of internet-facing assets?
2. How fast do you remediate CISA KEV-catalog vulnerabilities on internet-facing systems?
3. Is phishing-resistant MFA enforced for all privileged and remote access?
4. Do you have a tested incident response plan with defined CISA/FBI reporting paths?
5. Are security logs centralized, retained, and reviewed (per CISA logging guidance)?
6. Do you run regular backups that are isolated from the network and tested for restore?
7. Is your network segmented so a compromise can't move laterally unchecked?
8. Have leadership and staff run a tabletop exercise in the last year?
How scoring works
Each answer is worth 0–2 points (max 16). 0–5: foundational gaps — start with CISA's free services plus a gap assessment. 6–11: core controls exist — allow 1–3 months of prep. 12–16: likely ready. This is a self-assessment aid, not an audit opinion.
Know your score? Get quotes
Firms scope fees around readiness. Tell us where you stand and get matched.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.