NIST is the U.S. government agency that writes many of the cybersecurity standards other rules point to. Even if you've never heard of it, your cyber insurance application, your auditor or your biggest client probably has.
NIST isn't a technology or a product. It is the agency behind a large share of the security guidance that shows up in HIPAA risk assessments, CMMC, PCI DSS conversations, SOC 2 reports and insurance questionnaires. Here is what it is, which documents matter and why it affects a business that never deals with the federal government.
What does NIST stand for?
National Institute of Standards and Technology. It is part of the U.S. Department of Commerce and dates to 1901, when it was created to standardize weights, measures and industrial materials. Over time, "standards" grew to include cybersecurity, and NIST now publishes some of the most widely referenced security guidance in the country.
The simple way to think about it
NIST writes the rulebook; it doesn't enforce it. Regulators, contracts and insurance carriers point at NIST documents and say "do what this says." Think of it like a building code author: NIST writes the code, and someone else does the inspection.
The NIST documents you'll run into
- NIST Cybersecurity Framework (CSF) 2.0: the flagship, updated in February 2024. Version 2.0 added a sixth function, Govern, alongside Identify, Protect, Detect, Respond and Recover. It is a roadmap for what good cybersecurity looks like at any size of organization.
- NIST SP 800-171: the requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems. It feeds directly into CMMC for defense contractors. Revision 3 was published in May 2024, though CMMC still references Revision 2.
- NIST SP 800-53: the large, detailed catalog of security controls used by federal agencies and the cloud providers that serve them (FedRAMP is built on it).
- NIST SP 800-66: guidance for implementing the HIPAA Security Rule. Many HIPAA risk assessments map to it.
- NIST SP 800-63: digital identity guidelines, and the reason many organizations dropped forced password changes every 90 days.
Who actually has to follow NIST?
Directly required: federal agencies, many federal contractors, anyone handling CUI (through SP 800-171 and CMMC) and cloud providers serving the federal government.
Pulled in indirectly:
- Healthcare practices: HHS points to NIST guidance such as SP 800-66 for implementing the HIPAA Security Rule.
- Financial firms: regulators and examiners commonly use NIST CSF concepts when reviewing cybersecurity programs, and many firms use it to organize their policies.
- Cyber insurance applications: questions about MFA, endpoint protection, incident response and tested backups line up closely with the CSF.
- Vendor questionnaires: larger clients often send security questionnaires written in NIST terms.
That second group is where most small businesses sit. You may not be required to follow NIST by name, but the people who review your security often expect it.
How NIST relates to other frameworks
- HIPAA: a law. NIST SP 800-66 is a guide to implementing its Security Rule.
- PCI DSS: the payment card industry's standard. Separate from NIST, with a lot of overlap.
- SOC 2: an attestation based on the AICPA's Trust Services Criteria. It isn't built on NIST, but published mappings connect the two.
- CMMC: the Department of Defense program built directly on SP 800-171.
- ISO 27001: an international standard with similar goals, often cross-mapped to NIST.
Why it matters for your business
- Your insurance carrier speaks NIST. Many of the controls insurers ask about come straight from the CSF.
- Your clients and auditors speak NIST. Being able to say "we use the NIST CSF as our framework," and show the documentation behind it, can make questionnaires much easier.
- Your industry's rules borrow from NIST. HIPAA guidance, CMMC and many state requirements use NIST language. Aligning with the CSF gives you a strong head start on most other frameworks, though each still has its own specific requirements.
Where NerdSquad fits in
Most of our clients aren't federal contractors, but nearly all of them meet NIST somewhere: through HIPAA, cyber insurance, regulator expectations or a large client's questionnaire. As a Managed Service Provider (MSP), we use the NIST CSF as a common reference when planning a client's cybersecurity, then add the specific requirements each business needs: HIPAA for medical and dental practices, Regulation S-P and books-and-records rules for financial advisers, PCI DSS for businesses that take cards. The goal is that when an auditor or insurer asks how you protect data, you have documentation ready to show them.
Talk to NerdSquad
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.
Related: Cybersecurity services for businesses