Skip to main content
Category: Continuous Monitoring

Continuous Diagnostics and Mitigation

Also known as: CDM, CDM Program, Continuous Diagnostics and Mitigation Program
Simply put

Continuous Diagnostics and Mitigation (CDM) is a U.S. federal government program designed to strengthen the cybersecurity of government networks and systems through a dynamic, ongoing approach. It provides participating agencies with tools, services, and dashboards that help them monitor, detect, and respond to cyber threats. The program is intended to support risk-based and cost-effective cybersecurity assessments across the federal enterprise.

Formal definition

CDM is a Congressionally established federal program, administered by the Cybersecurity and Infrastructure Security Agency (CISA), that provides a dynamic approach to fortifying the cybersecurity of government networks and systems. As described in available authoritative sources, it delivers tools, services, and visualization/dashboard capabilities to enable agencies to conduct adequate, risk-based, and cost-effective cybersecurity assessments and to more efficiently allocate cybersecurity resources. Acquisition of CDM tools is generally supported through federal procurement vehicles such as the GSA Multiple Award Schedule. The evidence provided does not specify the program's constituent phases, capability areas, applicable impact levels, or how CDM requirements map to specific control frameworks; readers should verify current program scope and implementation details against official CISA and GSA sources.

Why it matters

Continuous Diagnostics and Mitigation matters because it reflects a broader shift in federal cybersecurity away from point-in-time, checklist-style assessments toward a dynamic and ongoing approach to monitoring government networks and systems. Rather than treating security posture as something confirmed once and assumed to hold, CDM is intended to support risk-based and cost-effective assessments that help agencies understand what is on their networks and respond to threats as conditions change. This aligns with the principle that authorization and compliance are not static states but require continuous attention.

For federal agencies operating under constrained budgets, CDM's emphasis on cost-effective, risk-based assessment is significant: the program is designed to help agencies more efficiently allocate cybersecurity resources rather than spread effort uniformly across every asset. The tools, services, and dashboard capabilities are meant to give agencies clearer visibility into their environments, which in turn supports better-informed decisions about where risk is concentrated.

It is important not to overstate what CDM does. The evidence available here describes the program's purpose and general capabilities but does not specify its constituent phases, capability areas, applicable impact levels, or how it maps to specific control frameworks. Participation in or use of CDM tools should not be equated with full compliance under any particular framework, and readers should confirm current program scope and requirements against official CISA and GSA sources rather than assuming the program satisfies obligations it does not explicitly address.

Who it's relevant to

Federal agency CISOs and information system security managers
Security leaders at participating federal agencies are the primary audience for CDM, as the program provides the tools, services, and dashboards intended to help them monitor, detect, and respond to threats and conduct risk-based assessments. They should confirm current program scope, capability areas, and how CDM fits within their existing continuous monitoring obligations against official CISA sources, since the evidence here does not specify those details.
Federal procurement and acquisition personnel
Because acquisition of CDM tools is generally supported through federal procurement vehicles such as the GSA Multiple Award Schedule, contracting and acquisition staff play a role in obtaining the tools associated with the program. They should verify current contract vehicle terms and eligible offerings through official GSA sources.
Vendors offering cybersecurity tools and services
Suppliers of cybersecurity tools, services, and dashboard capabilities may engage with CDM through federal procurement channels. Vendors should consult current CISA and GSA program documentation to understand qualification and offering requirements, which are not detailed in the evidence provided here.
Auditors and compliance officers assessing federal environments
Professionals evaluating an agency's cybersecurity posture should understand CDM as a program supporting ongoing, risk-based assessment, but should not treat use of CDM tools as equivalent to compliance with any specific control framework. The mapping of CDM to particular frameworks, impact levels, and control baselines is not established in the available evidence and must be confirmed against authoritative sources.

Inside CDM

CISA Program Sponsorship
CDM is a program administered by the Cybersecurity and Infrastructure Security Agency (CISA) within the Department of Homeland Security. It is oriented primarily toward federal civilian executive branch agencies rather than DoD systems governed by the RMF or national security systems. Readers should verify current program scope and participating agencies against official CISA sources.
Asset Management Capability Area
CDM generally addresses questions related to what is on the network, including hardware asset management, software asset management, configuration settings management, and vulnerability management. The specific tools and coverage vary by agency implementation.
Identity and Access Management Capability Area
CDM generally addresses who is on the network, including credential and authentication management, privilege management, and related access controls. Implementation details differ across participating agencies.
Network Security and Data Protection Capability Areas
CDM has expanded over time toward what is happening on the network and how data is protected, covering areas such as network and boundary activity monitoring and data protection. Because these areas have evolved through program phases, readers should confirm the current set of capabilities against authoritative CISA guidance.
Dashboard and Reporting Architecture
CDM generally provides agency-level and federal-level dashboards intended to give near real-time visibility into an organization's security posture and to support summary reporting. The reporting flow and dashboard functionality are subject to program updates.
Support for Continuous Monitoring
CDM is intended to support ongoing awareness of an organization's security posture, aligning conceptually with continuous monitoring expectations under FISMA and related NIST guidance. It is a program that supplies capabilities and data feeds, not itself a control catalog such as NIST SP 800-53.

Common questions

Answers to the questions practitioners most commonly ask about CDM.

Does participating in the CDM program mean an agency has met its FISMA requirements or achieved compliance?
No. CDM is a CISA-administered program that provides tools and capabilities to help agencies identify and prioritize cybersecurity risks, but participation is not equivalent to satisfying FISMA obligations or achieving compliance. FISMA responsibilities remain with each agency, and CDM generally supports those responsibilities rather than replacing them. Compliance and security are distinct concepts, and using CDM capabilities does not by itself demonstrate either. Agencies should confirm how CDM data feeds into their broader FISMA reporting and continuous monitoring processes against current official guidance.
Is CDM the same as continuous monitoring under the RMF?
Not exactly. CDM is a specific federal program managed by CISA that provides diagnostic tools, dashboards, and capabilities, primarily oriented toward federal civilian executive branch agencies. Continuous monitoring is a broader RMF concept and step maintained through NIST guidance that applies across federal systems, including DoD systems under the RMF. CDM can support an agency's continuous monitoring activities, but the two terms are not interchangeable, and DoD and national security systems may follow different arrangements. Readers should verify applicability to their specific environment.
Which types of agencies and systems is the CDM program primarily intended to support?
The CDM program is generally oriented toward federal civilian executive branch agencies under CISA's coordination. Its applicability to DoD systems, national security systems, or state, local, tribal, and territorial entities may differ or may be handled through separate arrangements. Because scope and participation details can vary and evolve, organizations should confirm current CDM applicability and eligibility with CISA and their own authorizing officials rather than assuming coverage.
How does CDM data relate to agency and federal-level dashboards?
In most implementations, CDM capabilities feed diagnostic data into agency-level dashboards, which in turn can support summary reporting to a federal-level view coordinated by CISA. This structure is intended to give both individual agencies and federal cybersecurity leadership visibility into asset, vulnerability, and configuration status. The specific data elements, reporting frequency, and dashboard architecture can change across program phases, so implementers should confirm current requirements and integration specifications against official CISA CDM documentation.
What should teams consider when integrating CDM tools with existing security infrastructure?
Teams should generally consider how CDM tools will collect and normalize data from existing asset management, vulnerability scanning, identity, and configuration systems without duplicating or conflicting with current tooling. Integration typically involves data mapping, sensor placement, and ensuring collected data flows into the appropriate dashboards. Because agency environments and CDM capability areas differ, integration approaches are often agency-specific. This entry does not cover procurement, contractual, or technical implementation specifics, which should be confirmed with CISA guidance and the agency's own architecture teams.
Does CDM eliminate the need for an agency's own security operations and personnel?
No. CDM generally provides tools, capabilities, and visibility, but agencies remain responsible for acting on the findings, managing their systems, and operating their security programs. The value of CDM depends on how agency staff interpret diagnostic results, prioritize mitigation, and maintain their own processes. CDM is a support capability, not a substitute for agency security operations, governance, or accountability, and readers should confirm role and responsibility boundaries within their specific program arrangements.

Common misconceptions

CDM applies to all federal systems, including DoD and national security systems.
CDM, as a CISA-administered program, is oriented primarily toward federal civilian executive branch agencies. DoD systems are generally governed by the RMF under DoD authorities, and national security systems follow separate requirements. State, local, tribal, and territorial obligations may differ. Readers should confirm applicability against current authoritative sources.
Participating in CDM means an agency has satisfied its compliance and authorization requirements.
CDM provides capabilities and visibility that support ongoing security awareness, but participation is not equivalent to achieving compliance or an Authority to Operate. Assessment and authorization remain distinct activities, and compliance is not the same as security. An ATO remains time-bound and subject to continuous monitoring regardless of CDM tooling.
CDM is a static, fixed set of tools and capabilities.
CDM has evolved through program phases, generally expanding from asset management toward identity, network activity, and data protection areas. The current set of capabilities and dashboard functions is subject to change, so readers should verify the present scope against official CISA guidance rather than assuming a fixed configuration.

Best practices

Confirm whether your organization falls within CDM's intended scope, recognizing that the program is oriented toward federal civilian executive branch agencies and that DoD, national security, and SLTT obligations may differ.
Treat CDM as a source of visibility and capabilities that supports continuous monitoring, not as a substitute for formal assessment, authorization, or an Authority to Operate.
Verify the current set of CDM capability areas and dashboard functions against authoritative CISA sources before relying on any specific feature, since the program has evolved through phases.
Integrate CDM asset, identity, and configuration data into your broader continuous monitoring processes so that near real-time posture information informs risk decisions rather than sitting unused.
Maintain the distinction between compliance and security, using CDM data to identify and remediate real exposures rather than treating program participation as an end in itself.
Coordinate CDM dashboard reporting with your organization's existing authorization and continuous monitoring documentation to keep posture reporting consistent and defensible during audits.