The Small and Midsize Business Guide to NIST Cybersecurity Standards

Share this post

NIST Cybersecurity

“Are you NIST compliant?”

Four words in a procurement email, and the CEO who forwarded them to me had already typed “Yes” into the reply box, deleted it, typed “Mostly,” and deleted that too. Then he called me.

He was right to hesitate. Nobody can answer that question as written, because “NIST compliant” tells you about as much as “we follow the rules.” NIST publishes hundreds of documents for wildly different audiences, and they are not interchangeable, not ranked from beginner to advanced, and not all aimed at you.

Let’s sort out the four that matter to a small and midsize businesses: what each one is, who it applies to, whether it is mandatory, and where to start. The short answer is that nearly every small business can put one of these references to work. CSF 2.0 is a sensible starting point for almost anyone, several of you will never need the other three, and the entry cost is lower than most leaders assume.

What NIST Is, and Who Has to Follow It

NIST, the National Institute of Standards and Technology, is a federal agency that publishes measurement and technology standards. It regulates nobody and audits nobody. NIST writes the guidance that regulators, contracting officers, insurers, and your customers then reference in their own requirements, which explains most of the confusion around the word “compliant.”

The Federal Information Security Modernization Act (FISMA) made NIST responsible for developing information security standards for federal information systems. Federal agencies must categorize each system and implement the matching controls, which is where the Low, Moderate, and High baselines we cover later originate.

Federal contractors and subcontractors are bound too, by contract rather than statute. The obligation arrives in a contract clause and flows down the supply chain, so a three-person machine shop that has never spoken to a contracting officer can inherit the full requirement from the prime above it. Being “just a subcontractor” is not an exemption, and plenty of businesses discover that only after signing.

Everyone else is voluntary. No federal agency will audit your private company against CSF 2.0.

Voluntary does not mean optional in the market, though. Insurance underwriters, enterprise customers, banks, and state privacy regulators increasingly reference NIST outcomes in their own paperwork, which quietly turns guidance into a condition of doing business. Choosing the reference that fits your context starts with the cheapest part: the documents themselves.

A Practical Advantage: Free, and Written by Career Practitioners

Every document in this article is downloadable from the NIST website at no cost. That includes the frameworks, plus the playbooks, quick start guides, and spreadsheets that make them usable. 

No license fee, no per-seat cost, and no paywall between you and the actual text. You can hand the same PDF to your IT provider, your insurance broker, and your operations manager this afternoon, and it was written by career federal technical staff working through public comment periods rather than by a vendor.

Standards do not usually work that way. ISO documentation is a purchase: the ISO store lists ISO/IEC 27001 at roughly $190, and ISO/IEC 42001, the AI management system standard, at roughly $275. Add ISO 27002 for the control guidance and the document budget runs $300 to $400 just to read the documents. 

(In fairness to ISO, document sales fund its standards development.)

The Quick Answer, Side by Side

If you read nothing else in this article, read this table, then jump to the section that matches your situation.

FrameworkWhat it isWho it applies toRequired or voluntaryCertifiableCost
NIST CSF 2.0Strategic outcomes frameworkAny organization, any sizeVoluntary for private businessNo, self-assessmentFree
SP 800-171Controls for protecting sensitive government informationNon-federal organizations handling CUIRequired by contract, including subcontractsYes, via CMMC for defense workFree
SP 800-53Full control catalog with Low, Moderate, and High baselinesFederal agencies and their system and cloud vendorsCompulsory for federal systemsYes, via programs such as FedRAMPFree
AI RMF 1.0Risk framework for AI systemsAny organization building or using AIVoluntaryNoFree
ISO 27001, for cost comparisonCertifiable security management systemAny organization, usually customer-drivenVoluntaryYes, accredited auditDocuments plus audit fees

NIST CSF 2.0: A Good Starting Point for Any Business

Most small business security spending happens reactively, one tool at a time. The Cybersecurity Framework (CSF) 2.0 fixes that without requiring anyone to walk leadership through a technical standard. Its six functions cover the breadth of what a cybersecurity program must do to be successful. 

FunctionThe question it answers
GovernWho owns this, what is our risk appetite, and how is it reported to leadership?
IdentifyWhat do we have, what matters most, and who has access?
ProtectWhat are we doing to keep it from happening?
DetectHow would we know if something went wrong?
RespondWhat happens in the first 24 hours, and who makes the calls?
RecoverHow do we get back to serving customers, and how long will it take?

Govern is the most important function on this list, even though it was only added in NIST CSF 2.0. Govern pulls accountability, roles, policy, and risk tolerance into the leadership domain. In plain terms, it answers who is responsible for security.

If no one is responsible for security, you do not have a security program! 

CSF does not add traditional compliance work. It helps to organize the work that goes into building any cybersecurity program. Identify includes your asset and vendor inventories. Protect looks at decisions about access, passwords, and training. Detect and Respond unsurprisingly include monitoring and incident response plans. Recover includes controls like backups and restore processes. 

Once you map your cybersecurity activities to these functions, it becomes easier to identify where gaps in your programs may lie. So fill them! 

Important to note: NIST CSF will not tell you what to do. It defines outcomes, not methods. Other NIST standards provide specific controls that can meet the outcomes. 

If you’re starting from scratch, I recommend the free CSF 2.0 Small Business Quick-Start Guide and the sector Community Profiles.

NIST SP 800-171: For the Government Supply Chain

SP 800-171 is the requirement set for protecting Controlled Unclassified Information (CUI) on systems the government does not own. CUI means sensitive but unclassified government information: technical drawings, specifications, and certain contract data. If a contract at any tier flows a CUI clause down to you, this is yours.

NIST built 800-171 by taking SP 800-53 and removing the controls written specifically for federal agencies, which is the clearest illustration of how these documents relate.

For defense work, verification runs through CMMC, the Cybersecurity Maturity Model Certification program. Those rules have been moving for years, but are paused at time of writing (Summer 2026).

What has not moved is the underlying requirement. Implement what your contract specifies today.

Here is the objection I hear whenever an enforcement date slips: “Great, we can stand down.” No! Self-assessments, DFARS 252.204-7012, score submissions, and annual affirmations stay in force, and an affirmation is still a statement to the federal government with all the liability that carries. Your prime can also require whatever it likes in your subcontract, so ask what it expects.

If you do not hold or process CUI, none of this is your obligation. Chasing it spends your budget with no commercial return. 

SP 800-53 and the Low, Moderate, and High Baselines

SP 800-53 is the master control catalog: roughly 1,200 security and privacy controls across 20 families, the broadest catalog NIST publishes. (I have read large stretches of it, which tells you something about how I spend my weekends.) 

Revision 5 remains current, with Release 5.2.0 finalized in August 2025.

The Low, Moderate, and High labels trip people up. They are information impact levels describing the consequence if confidentiality, integrity, or availability were lost, so the system gets categorized first and the baseline follows. A public website lands at Low; a system holding personal data lands at Moderate.

Who needs to care? Federal agencies and the vendors running systems on their behalf, most often cloud providers pursuing FedRAMP, the Federal Risk and Authorization Management Program. If Sarah’s SaaS Startup decides to sell to a federal agency, this becomes a real project with a real budget.

For everyone else, 800-53 is a reference library rather than a project. Its value to you is supplying specific control language once CSF has identified a gap.

The AI Risk Management Framework: The Responsible AI Piece

The AI Risk Management Framework (AI RMF) is a voluntary framework built on four functions: Govern, Map, Measure, and Manage. NIST released AI RMF 1.0 in January 2023, and it remains the only finalized version, though NIST has said the document is being revised.

It’s useful to any organization building, buying, or using AI, which now includes almost everyone. An AI writing tool, a customer service chatbot, resume screening software, or the AI features your accounting platform switched on last quarter all put you in scope.

The distinction from every other framework here matters. Cybersecurity frameworks address someone attacking your systems. The AI RMF addresses your own systems behaving in ways that create legal, reputational, or fairness problems. Different risk, different playbook.

Multiple federal agencies now reference AI RMF principles in enforcement guidance. The free Generative AI Profile (NIST AI 600-1) covers risks specific to generative tools.

You can start this week with three things: an inventory of where AI is used in the business, a written acceptable use policy, and a human review requirement for any consequential decision.

How the Four Fit Together, and Which One Fits You

CSF sets direction and ownership. SP 800-53 supplies the detailed controls. SP 800-171 is a trimmed subset of 800-53 aimed at protecting CUI outside government systems. The AI RMF runs alongside all of it, covering a different risk (that cybersecurity practitioners are usually responsible for).

That shared lineage means effort is rarely wasted, and NIST publishes free crosswalk tools, including the Cybersecurity and Privacy Reference Tool, for moving between documents.

Here is the quick matching guide:

  • No government work and no AI in consequential decisions? CSF 2.0 alone, which describes a large share of the businesses we advise.
  • Any contract mentioning CUI or DFARS? CSF for structure, plus 800-171 at the revision your contract specifies.
  • Selling cloud software to a federal agency? 800-53 at the appropriate impact level, through FedRAMP.
  • AI used in hiring, lending, pricing, medical, or safety decisions? Add the AI RMF.
  • A customer demanding proof from an outside party? Most small businesses land on SOC 2 (System and Organization Controls 2), an attestation issued by a CPA firm. Build on CSF first, since the gaps it surfaces are largely the same ones a SOC 2 readiness effort works through.

Pick the reference that matches your obligations and your risks, not the one that sounds most rigorous. Starting with CSF costs nothing and rarely turns out to be the wrong call.

Misconceptions to Clear Up, and First Steps

Five things I correct constantly:

  • “NIST compliance” is not a single achievement, and no certificate exists to buy.
  • A higher document number does not mean a stronger standard. SP 800-171 is smaller than SP 800-53 by design.
  • Low, Moderate, and High describe information impact, not organizational maturity.
  • Voluntary is not the same as unnecessary. Most small business NIST obligations arrive on a purchase order rather than from a regulator.
  • Free documentation does not mean free implementation. Staff time, tooling, and evidence gathering are the real budget lines.

Five things to do about it:

  • Read your contracts and customer agreements for obligations already in force.
  • Inventory what data you hold and where it lives, since scope drives cost more than anything.
  • Run a CSF 2.0 self-assessment across the six functions and write down every gap.
  • Build an AI inventory if AI is used anywhere in the business.
  • Assign one accountable owner, technical or not, and document decisions as you go, since evidence is what assessors, insurers, and customers review.

The Answer to That Email

The CEO who called me sent his reply the next day. It did not say “yes,” and it did not say “mostly.” It said his company runs its security program against NIST CSF 2.0, listed the six functions, named the owner of each, and offered to walk through the self-assessment on a call. The prospect’s security team asked two follow-up questions and moved on. Total cost: about eleven hours of internal time. Zero dollars in new license or tool fees.

Want to get great cybersecurity content delivered to your inbox? Click here to sign up for our monthly newsletter, Tales from the Click!

Dan Bjorklund
Dan is a vCISO Principal for Fractional CISO. In this role, he provides strategic guidance and instruction to help clients build and manage their security and compliance programs. Dan served in the U.S. Army for 20+ years and entered the information security industry shortly after retiring from service. He has helped many Department of Defense contractors and commercial SMBs with their security and compliance programs. He has a master’s degree in Information Security from Capella University, is a Certified Information Systems Security Professional (CISSP) and is a CMMC Certified Professional (CCP).

Tales From The Click

Sign up for our monthly newsletter for business leaders on minimizing cybersecurity risk.

Suceed at SOC 2

Free eBook:
5 Things to Know for your First SOC 2

  • How to scope your SOC 2
  • Estimate the cost and length of your SOC 2
  • Prepare for your SOC 2
  • Manage the SOC 2 audit period
  • Leverage your SOC 2 for growth

Related Posts

Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales
Is your Cyber Insurance really going to cover you?

Only 1/3 of cyber insurance policies actually pay out in incidents. Most companies have cyber insurance policies that insure too little, or too much, and have absurdly low caps and silly exclusions.

To learn more about cyber insurance and determine if you have the right coverage for you, join us for a free vCISO Office Hours session on Tuesday, April 18 at 1 p.m. eastern time. Bring your questions!

New Release: Free SOC 2 eBook!

Getting ready for your first SOC 2? This eBook is full of actionable advice to help you prepare for and succeed in your first SOC 2 audit.

Learn:

  • How to scope your SOC 2 project
  • How to estimate the cost and length of your SOC 2 project
  • How to prepare for your SOC 2
  • How to succeed in your SOC 2 audit period
  • How to leverage your SOC 2 report to enable your business and sales