Microsoft Secure Score vs CISA CPG — what each one measures and when to use which
Microsoft Secure Score and CISA's Cross-Sector Cybersecurity Performance Goals (CPG) often appear in the same audit-report paragraph, but they answer different questions. One is relative, one absolute. One shifts with every Microsoft announcement, the other is anchored to national risk. When to cite which, and what happens when a report mixes them.
The problem
A meaningful share of Microsoft 365 audit reports circulating in the Mexican mid-market mention both Microsoft Secure Score and CISA CPG (Cross-Sector Cybersecurity Performance Goals) as if they were complementary layers of the same framework. They are not. They are metrics with different purposes, different publishers, and different calculation rules. When a report presents them as interchangeable, it's using one to legitimise the other — a classic "framework laundering" pattern.
This article separates what each one does.
Microsoft Secure Score
What it is. A native Microsoft metric that assigns a 0–100% number to your tenant based on how many recommendations from Microsoft's active catalogue you've implemented. Visible in security.microsoft.com under "Secure Score". Covers Identity, Apps, Data, Devices.
How it's calculated. Each control has a weight. Enabling it adds points; not enabling it does not. The total is normalised against the maximum achievable for your licensing (a Business Premium tenant has a different max than an E5). The number is relative to Microsoft's current view of relevant controls.
What it measures. Feature adoption. If Microsoft announces a new control tomorrow, your Secure Score drops without you changing anything — because the denominator grew. The score rises when you enable the new feature.
What it doesn't measure. Defensibility. Enabling a feature without configuring it correctly still earns Secure Score points. Configuring it well is another matter. And it doesn't cover controls outside Microsoft's catalogue (local regulation, operational practice, training).
When it's useful. Internal month-over-month reporting — "this month we implemented controls X, Y, Z; Secure Score went from 64% to 71%". Tracking adoption over time on an individual tenant.
When it's not. Comparing tenants against each other, defending posture to an external auditor, or calibrating security investment. The number doesn't mean the same thing between two tenants with different licensing.
CISA CPG (Cross-Sector Cybersecurity Performance Goals)
What it is. A set of cybersecurity goals published by CISA (US Cybersecurity & Infrastructure Security Agency) designed as a minimum baseline applicable across all critical-infrastructure sectors. Current version: October 2024. Source: cisa.gov/cross-sector-cybersecurity-performance-goals.
How it's structured. Not a score — a list of goals grouped under five functions (Identify, Protect, Detect, Respond, Recover) inherited from NIST CSF. Each goal has a stable identifier (e.g. `2.A` — MFA), an explanation of the risk it mitigates, and cross-references to NIST 800-53.
What it measures. Coverage of an absolute set of controls considered non-negotiable for reducing population-level risk. Deliberately product-agnostic — a CPG goal doesn't say "enable Microsoft Defender", it says "implement endpoint detection with centralised telemetry".
What it doesn't measure. Specific configuration. CPG says "MFA on all privileged accounts"; it doesn't say "MS.AAD.3.1v1 with phishing-resistant MFA and a specific conditional-access policy". For that you need SCuBA or CIS.
When it's useful. As a communication framework for boards, non-technical regulators, and auditors who need to see the why of investment, not the how of configuration. CPG is the language of risk, not of control.
When it's not. As a technical-configuration benchmark. A tenant that "complies with CPG" can still have weak Microsoft 365 configurations because CPG doesn't reach that granularity.
The reality table
| | Microsoft Secure Score | CISA CPG |
|---|---|---|
| Type | Relative % score | Absolute goal list |
| Publisher | Microsoft | CISA (US federal) |
| Granularity | Per Microsoft 365 feature | Per cross-sector risk goal |
| Versioning | Implicit (changes continuously) | Explicit (v1 Oct 2022, updated Oct 2024) |
| Language | Product-technical | Risk-functional |
| Auditable as primary evidence | No | Yes (with CPG ID reference) |
| Changes without you touching your tenant | Yes (when Microsoft adds controls) | No |
| Maps to specific Microsoft 365 controls | Not directly | Not directly (via SCuBA / CIS) |
How to use them together correctly
A serious audit report uses all three in distinct layers:
1. CISA CPG as high-level risk narrative — "you've implemented 18 of 20 CPG goals; the 2 pending are recovery testing and supply-chain risk management".
2. CIS Benchmark / CISA SCuBA as the underlying technical configuration — "CPG goal 2.A (MFA) is satisfied via controls MS.AAD.3.1v1 and MS.AAD.3.2v1; your tenant has MFA applied to 94% of accounts".
3. Microsoft Secure Score as month-over-month operational adoption metric — "your Secure Score climbed from 67% to 74% this quarter".
If a report delivers only the Secure Score and positions it as "compliance", it's misreading its own mechanism.
How simiriki treats it
The simiriki Posture Brief cites all three frameworks on Page 3 with distinct descriptions. The sIPO score (simiriki Infrastructure Posture Observable) is not a Secure Score rewrite — it's a stable metric derived from the 201 internal rules, calibrated to stay comparable over time independent of Microsoft catalogue changes. CPG and SCuBA mapping is published in docs/SCUBAGEAR_MAPPING.md.
Bottom line
Microsoft Secure Score answers "how many of Microsoft's recommendations am I following?" CISA CPG answers "which non-negotiable security goals am I covering?" These are different questions. When a report presents them as synonyms, it's confusing product adoption with risk coverage — and that confusion is exactly what a sophisticated auditor will use to invalidate the report.
Related reading:
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.