National Institute of Standards and Technology (NIST)
NIST is a non-regulatory agency inside the Department of Commerce. Founded in 1901. For cybersecurity, NIST is the standards body that authors the frameworks and special publications everyone references: SP 800-171 for CUI in nonfederal systems, SP 800-53 for federal system controls, the Cybersecurity Framework (CSF) for voluntary adoption, and SP 800-37 for the Risk Management Framework. When a compliance program points to a control standard, the standard almost always comes from NIST.
- glossary
- NIST Publications Defense Contractors Encounter
NIST Publications Defense Contractors Encounter
- NIST SP 800-171 Rev 2 / Rev 3: The 110 requirements (Rev 2) for protecting CUI in nonfederal systems. CMMC Level 2 and DFARS 252.204-7012 both point here.
- NIST SP 800-172: Enhanced requirements that sit on top of 800-171, for the highest-risk CUI. Forms the basis of CMMC Level 3.
- NIST SP 800-53 Rev 5: The full catalog of federal security and privacy controls. FedRAMP baselines are derived from 800-53.
- NIST Cybersecurity Framework (CSF) 2.0: Voluntary framework organized around six functions (Govern, Identify, Protect, Detect, Respond, Recover). Widely adopted outside federal.
- NIST SP 800-37 Rev 2: The Risk Management Framework. Federal system authorization process and the backbone of FedRAMP.
- NIST SP 800-161 Rev 1: Cybersecurity supply chain risk management practices (C-SCRM).
- NIST SP 800-82 Rev 3: Guide to operational technology (OT) security.
- FIPS 140-3: Cryptographic module validation standard.
- FIPS 199: Security categorization standard. Underpins RMF Step 2 (Categorize).
How NIST Publications Get Updated
NIST drafts in the open. A Public Draft gets published, public comments come in (sometimes thousands), and NIST revises. Significant changes go through multiple public draft rounds. The timeline from initial draft to final publication is typically 12 to 24 months. This is why watching NIST's CSRC site (csrc.nist.gov) gives you a year or more of warning before a new control standard is final.
NIST Is Not a Regulator
NIST publishes standards and guidance. It does not enforce compliance. Enforcement comes from regulators and contracting authorities (DoD through DFARS and CMMC, OMB through Circular A-130, agencies through their contract terms). So when a rule cites NIST SP 800-171, the rule is enforceable and the NIST publication is the technical reference.
How NIST Publications Fit Together
800-53 is the big control catalog. 800-171 is a subset of 800-53 tailored for nonfederal handling of CUI. 800-172 is enhanced requirements on top of 800-171. FIPS 199 feeds categorization into RMF (SP 800-37), which drives control selection from 800-53. The CSF offers a higher-level framing that organizations use to map their program across multiple standards. All of it composes together rather than competing.