What is NIST?
Key takeaway
NIST (National Institute of Standards and Technology) is a US government agency that publishes widely used cybersecurity frameworks and guidelines, including the NIST Cybersecurity Framework (CSF).
What is NIST?
NIST (National Institute of Standards and Technology) is a non-regulatory agency of the United States Department of Commerce that develops and publishes standards, guidelines, and best practices for technology and cybersecurity. NIST's publications are among the most widely referenced resources in information security worldwide, influencing both government and private sector organizations.
What are the key NIST publications?
- NIST Cybersecurity Framework (CSF) — a voluntary framework organized around five core functions (Identify, Protect, Detect, Respond, Recover) that provides a common language for managing cybersecurity risk. Widely adopted by organizations of all sizes.
- NIST SP 800-53 — a comprehensive catalog of security and privacy controls for federal information systems. Often used as a reference by private organizations building security programs.
- NIST SP 800-171 — security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems, required for defense contractors.
- NIST SP 800-37 — the Risk Management Framework (RMF) that guides organizations through a structured process for managing security risk.
Why does NIST matter for compliance?
While NIST frameworks are voluntary for most private organizations, they serve as the foundation or reference point for many compliance requirements:
- Federal agencies are required to follow NIST guidelines
- Defense contractors must comply with NIST SP 800-171 (enforced through CMMC)
- Many ISO 27001 and SOC 2 control mappings reference NIST publications
- Cyber insurance providers increasingly reference NIST CSF alignment
How does episki help with NIST?
episki ships the NIST family — CSF 2.0, 800-53, 800-171, and the AI Risk Management Framework — with controls evaluated continuously and crosswalks between them derived through the SCF hub with recorded provenance. Adding another NIST framework alongside the ones you run costs nothing extra. Learn more on our NIST CSF compliance page.
Dealing with this in your own program? episki's agents handle the drafting, mapping, and evidence work.
Start free trialRelated questions
Continue exploring
NIST CSF Detect Function
Framework topic
NIST CSF Five Functions
Framework topic
What is NIST CSF?
Framework overview
What is Access Control?
Glossary definition
What is Business Continuity?
Glossary definition
Drata vs Secureframe
Head-to-head comparison
episki vs Archer
See how we compare
Securing the Pipeline: Why DevSecOps Belongs on Your GRC Roadmap
From the blog