Continuous Diagnostics and Mitigation
Continuous Diagnostics and Mitigation (CDM) is a U.S. federal government program designed to strengthen the cybersecurity of government networks and systems through a dynamic, ongoing approach. It provides participating agencies with tools, services, and dashboards that help them monitor, detect, and respond to cyber threats. The program is intended to support risk-based and cost-effective cybersecurity assessments across the federal enterprise.
CDM is a Congressionally established federal program, administered by the Cybersecurity and Infrastructure Security Agency (CISA), that provides a dynamic approach to fortifying the cybersecurity of government networks and systems. As described in available authoritative sources, it delivers tools, services, and visualization/dashboard capabilities to enable agencies to conduct adequate, risk-based, and cost-effective cybersecurity assessments and to more efficiently allocate cybersecurity resources. Acquisition of CDM tools is generally supported through federal procurement vehicles such as the GSA Multiple Award Schedule. The evidence provided does not specify the program's constituent phases, capability areas, applicable impact levels, or how CDM requirements map to specific control frameworks; readers should verify current program scope and implementation details against official CISA and GSA sources.
Why it matters
Continuous Diagnostics and Mitigation matters because it reflects a broader shift in federal cybersecurity away from point-in-time, checklist-style assessments toward a dynamic and ongoing approach to monitoring government networks and systems. Rather than treating security posture as something confirmed once and assumed to hold, CDM is intended to support risk-based and cost-effective assessments that help agencies understand what is on their networks and respond to threats as conditions change. This aligns with the principle that authorization and compliance are not static states but require continuous attention.
For federal agencies operating under constrained budgets, CDM's emphasis on cost-effective, risk-based assessment is significant: the program is designed to help agencies more efficiently allocate cybersecurity resources rather than spread effort uniformly across every asset. The tools, services, and dashboard capabilities are meant to give agencies clearer visibility into their environments, which in turn supports better-informed decisions about where risk is concentrated.
It is important not to overstate what CDM does. The evidence available here describes the program's purpose and general capabilities but does not specify its constituent phases, capability areas, applicable impact levels, or how it maps to specific control frameworks. Participation in or use of CDM tools should not be equated with full compliance under any particular framework, and readers should confirm current program scope and requirements against official CISA and GSA sources rather than assuming the program satisfies obligations it does not explicitly address.
Who it's relevant to
Inside CDM
Common questions
Answers to the questions practitioners most commonly ask about CDM.