How long does CISA CPG implementation take?
A realistic end-to-end range for a first CPG-alignment program: 6–12 months. Here's where the time goes — and how to compress it.
- Enroll in free CISA services — 1–2 weeks
Sign up for Cyber Hygiene scanning and pull the CPG checklist. Free visibility while you plan. - CPG gap assessment — 4–6 weeks
A consultant tests your program against the goals and delivers a prioritized gap list. Get 2–3 scoped quotes first. - Quick wins — 30–60 days
MFA enforcement, KEV patching cadence, offline backups. The highest-risk gaps close first. - Program build-out — 3–6 months
Segmentation, logging and monitoring, incident-response plan with reporting paths, tabletop exercise. - OT scope (if applicable) — 2–4 months, parallel
OT asset inventory, passive monitoring, IT/OT separation. Safety-constrained, so it runs on its own track. - Continuous operation — ongoing
CPG alignment isn't a project with an end date. Annual reassessment keeps the program honest.
What causes delays
- Discovery debt. No asset inventory means months of archaeology before control work.
- OT treated as an afterthought. OT assessment runs on a safety-constrained track — start it in parallel, not after.
- Tool-first buying. Buying monitoring tools before defining what they'll monitor. Define the program, then tool it.
- Scope creep. Adding business units mid-program without re-baselining the timeline.
Fastest realistic path
Small operator, decent starting posture: free CISA scanning (week 1) + 4-week gap assessment + 60 days of quick wins ≈ 3–4 months to a defensible CPG baseline. Large or OT-heavy: plan for 9–12+ months.
Timeline questions
Do I need a consultant, or can I do this in-house?
Start in-house with CISA's free services and the CPG checklist. Hire a consultant for the gaps you can't close — specialized assessments, OT scope, or program build-out at speed.
What slows CPG programs down most?
Asset inventory. Organizations that can't see their exposed systems spend months on discovery before any control work starts. Run CISA's free scanning on day one.
Is there a deadline?
For federal agencies: yes — BOD timelines and zero-trust milestones are mandatory. For everyone else: no federal deadline, but customers, insurers, and contracts increasingly set their own.
Start the clock
Tell us your deadline — we'll match you with firms who can hit it.
How it works: tell us once (4 questions, 2 min) → we match licensed auditors to your size and scope → they send scoped quotes directly. Free, no obligation.