| Resource Type | Report |
| Author / Source | Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Homeland Security |
| Publication Date | December 2025 |
| Location | United States |
| Initiative Type | Program, Technology, Policy |
| Project Complexity | Intermediate |
| Recommended For | Board, Staff |
Estimated reading time: 30+ minutes
Why This Matters for Rural Electric Co-ops
Electric co-ops are critical infrastructure, and most run lean IT operations without dedicated security staff. This report is CISA's current baseline of cybersecurity practices for exactly that situation, written so a non-technical reader can follow it. Version 2.0 adds a Govern function, which makes cybersecurity oversight a leadership responsibility and puts it on the board's agenda rather than leaving it with IT alone.
The practical companion is the CPG Checklist and Worksheet (CISA.gov), a fill-in tracker that lists each goal with Implemented, In Progress, Scoped, and Not Started boxes, plus notes, dates, and ratings for cost, impact, and ease of implementation. That is the piece staff can actually work through and bring to a board to show where the co-op stands and what to fund first. A co-op ready to go deeper can run the free CSET assessment, which contains the CPG assessment module and produces a scored report, though it takes more time and commitment.
Key Takeaways
| › | The CPGs are voluntary baseline practices, not a regulation, chosen specifically so small and medium organizations can start without a large budget. |
| › | The worksheet's cost, impact, and ease of implementation ratings give staff a simple way to sequence work and justify spending to a non-technical board. |
| › | Version 2.0 adds a Govern function, placing cybersecurity oversight and accountability directly with organizational leadership rather than treating it as an IT-only issue. |
| › | Third-party and vendor risk now carries its own goal, which matters for co-ops that rely on managed service providers, software vendors, or their G&T for systems access. |
Implementation Considerations
- Cost or Funding Requirements: The documents and CSET are free. CISA defines cost as a share of security budget, with low under 5% and high above 15%, and recommends a cost-benefit analysis for any goal a co-op decides not to implement. That framing gives staff a defensible way to justify or defer spending at budget time.
- Staffing or Technology Requirements: A general manager and an IT lead or outside provider can work through the goal list and tracker together. Several goals, including network segmentation, log collection and storage, and independent validation of controls, are rated complex and high cost, so smaller co-ops will likely need vendor or statewide association support for those. CSET requires contact information and a software install.
- Time-Sensitive Information: The tracking checklist and worksheet currently posted are still the v1.0.1 version from March 2023. They use the old goal numbering and the retired "Complexity" rating, so they do not line up with this report. CISA indicated an updated 2.0 checklist and CSET module were expected in early 2026. Page 9 of the report carries a crosswalk between the v1.0.1 and 2.0 goal numbers for anyone working from the older file.
Notable Examples
- National Rural Electric Cooperative Association (NRECA): Contributed input on the goals, giving co-ops a direct voice in the framework.
- American Public Power Association and Edison Electric Institute: Utility associations that also contributed, signaling broad electric sector participation.
- CPG Checklist and Worksheet (CISA.gov): Fill-in tracker for recording implementation status against each goal.
- Cyber Security Evaluation Tool (CSET): Free downloadable self-assessment application containing the CPG assessment module and worksheet.
- National Institute of Standards and Technology (NIST): Publisher of Cybersecurity Framework 2.0, which every goal maps to.
Estimated reading time: 30+ minutes
Related to
Comments
0 comments
Please sign in to leave a comment.