“Are you NIST compliant?”
Four words in a procurement email, and the CEO who forwarded them to me had already typed “Yes” into the reply box, deleted it, typed “Mostly,” and deleted that too. Then he called me.
He was right to hesitate. Nobody can answer that question as written, because “NIST compliant” tells you about as much as “we follow the rules.” NIST publishes hundreds of documents for wildly different audiences, and they are not interchangeable, not ranked from beginner to advanced, and not all aimed at you.
Let’s sort out the four that matter to a small and midsize businesses: what each one is, who it applies to, whether it is mandatory, and where to start. The short answer is that nearly every small business can put one of these references to work. CSF 2.0 is a sensible starting point for almost anyone, several of you will never need the other three, and the entry cost is lower than most leaders assume.
What NIST Is, and Who Has to Follow It
NIST, the National Institute of Standards and Technology, is a federal agency that publishes measurement and technology standards. It regulates nobody and audits nobody. NIST writes the guidance that regulators, contracting officers, insurers, and your customers then reference in their own requirements, which explains most of the confusion around the word “compliant.”
The Federal Information Security Modernization Act (FISMA) made NIST responsible for developing information security standards for federal information systems. Federal agencies must categorize each system and implement the matching controls, which is where the Low, Moderate, and High baselines we cover later originate.
Federal contractors and subcontractors are bound too, by contract rather than statute. The obligation arrives in a contract clause and flows down the supply chain, so a three-person machine shop that has never spoken to a contracting officer can inherit the full requirement from the prime above it. Being “just a subcontractor” is not an exemption, and plenty of businesses discover that only after signing.
Everyone else is voluntary. No federal agency will audit your private company against CSF 2.0.
Voluntary does not mean optional in the market, though. Insurance underwriters, enterprise customers, banks, and state privacy regulators increasingly reference NIST outcomes in their own paperwork, which quietly turns guidance into a condition of doing business. Choosing the reference that fits your context starts with the cheapest part: the documents themselves.
A Practical Advantage: Free, and Written by Career Practitioners
Every document in this article is downloadable from the NIST website at no cost. That includes the frameworks, plus the playbooks, quick start guides, and spreadsheets that make them usable.
No license fee, no per-seat cost, and no paywall between you and the actual text. You can hand the same PDF to your IT provider, your insurance broker, and your operations manager this afternoon, and it was written by career federal technical staff working through public comment periods rather than by a vendor.
Standards do not usually work that way. ISO documentation is a purchase: the ISO store lists ISO/IEC 27001 at roughly $190, and ISO/IEC 42001, the AI management system standard, at roughly $275. Add ISO 27002 for the control guidance and the document budget runs $300 to $400 just to read the documents.
(In fairness to ISO, document sales fund its standards development.)
The Quick Answer, Side by Side
If you read nothing else in this article, read this table, then jump to the section that matches your situation.
| Framework | What it is | Who it applies to | Required or voluntary | Certifiable | Cost |
|---|---|---|---|---|---|
| NIST CSF 2.0 | Strategic outcomes framework | Any organization, any size | Voluntary for private business | No, self-assessment | Free |
| SP 800-171 | Controls for protecting sensitive government information | Non-federal organizations handling CUI | Required by contract, including subcontracts | Yes, via CMMC for defense work | Free |
| SP 800-53 | Full control catalog with Low, Moderate, and High baselines | Federal agencies and their system and cloud vendors | Compulsory for federal systems | Yes, via programs such as FedRAMP | Free |
| AI RMF 1.0 | Risk framework for AI systems | Any organization building or using AI | Voluntary | No | Free |
| ISO 27001, for cost comparison | Certifiable security management system | Any organization, usually customer-driven | Voluntary | Yes, accredited audit | Documents plus audit fees |
NIST CSF 2.0: A Good Starting Point for Any Business
Most small business security spending happens reactively, one tool at a time. The Cybersecurity Framework (CSF) 2.0 fixes that without requiring anyone to walk leadership through a technical standard. Its six functions cover the breadth of what a cybersecurity program must do to be successful.
| Function | The question it answers |
|---|---|
| Govern | Who owns this, what is our risk appetite, and how is it reported to leadership? |
| Identify | What do we have, what matters most, and who has access? |
| Protect | What are we doing to keep it from happening? |
| Detect | How would we know if something went wrong? |
| Respond | What happens in the first 24 hours, and who makes the calls? |
| Recover | How do we get back to serving customers, and how long will it take? |
Govern is the most important function on this list, even though it was only added in NIST CSF 2.0. Govern pulls accountability, roles, policy, and risk tolerance into the leadership domain. In plain terms, it answers who is responsible for security.
If no one is responsible for security, you do not have a security program!
CSF does not add traditional compliance work. It helps to organize the work that goes into building any cybersecurity program. Identify includes your asset and vendor inventories. Protect looks at decisions about access, passwords, and training. Detect and Respond unsurprisingly include monitoring and incident response plans. Recover includes controls like backups and restore processes.
Once you map your cybersecurity activities to these functions, it becomes easier to identify where gaps in your programs may lie. So fill them!
Important to note: NIST CSF will not tell you what to do. It defines outcomes, not methods. Other NIST standards provide specific controls that can meet the outcomes.
If you’re starting from scratch, I recommend the free CSF 2.0 Small Business Quick-Start Guide and the sector Community Profiles.
NIST SP 800-171: For the Government Supply Chain
SP 800-171 is the requirement set for protecting Controlled Unclassified Information (CUI) on systems the government does not own. CUI means sensitive but unclassified government information: technical drawings, specifications, and certain contract data. If a contract at any tier flows a CUI clause down to you, this is yours.
NIST built 800-171 by taking SP 800-53 and removing the controls written specifically for federal agencies, which is the clearest illustration of how these documents relate.
For defense work, verification runs through CMMC, the Cybersecurity Maturity Model Certification program. Those rules have been moving for years, but are paused at time of writing (Summer 2026).
What has not moved is the underlying requirement. Implement what your contract specifies today.
Here is the objection I hear whenever an enforcement date slips: “Great, we can stand down.” No! Self-assessments, DFARS 252.204-7012, score submissions, and annual affirmations stay in force, and an affirmation is still a statement to the federal government with all the liability that carries. Your prime can also require whatever it likes in your subcontract, so ask what it expects.
If you do not hold or process CUI, none of this is your obligation. Chasing it spends your budget with no commercial return.
SP 800-53 and the Low, Moderate, and High Baselines
SP 800-53 is the master control catalog: roughly 1,200 security and privacy controls across 20 families, the broadest catalog NIST publishes. (I have read large stretches of it, which tells you something about how I spend my weekends.)
Revision 5 remains current, with Release 5.2.0 finalized in August 2025.
The Low, Moderate, and High labels trip people up. They are information impact levels describing the consequence if confidentiality, integrity, or availability were lost, so the system gets categorized first and the baseline follows. A public website lands at Low; a system holding personal data lands at Moderate.
Who needs to care? Federal agencies and the vendors running systems on their behalf, most often cloud providers pursuing FedRAMP, the Federal Risk and Authorization Management Program. If Sarah’s SaaS Startup decides to sell to a federal agency, this becomes a real project with a real budget.
For everyone else, 800-53 is a reference library rather than a project. Its value to you is supplying specific control language once CSF has identified a gap.
The AI Risk Management Framework: The Responsible AI Piece
The AI Risk Management Framework (AI RMF) is a voluntary framework built on four functions: Govern, Map, Measure, and Manage. NIST released AI RMF 1.0 in January 2023, and it remains the only finalized version, though NIST has said the document is being revised.
It’s useful to any organization building, buying, or using AI, which now includes almost everyone. An AI writing tool, a customer service chatbot, resume screening software, or the AI features your accounting platform switched on last quarter all put you in scope.
The distinction from every other framework here matters. Cybersecurity frameworks address someone attacking your systems. The AI RMF addresses your own systems behaving in ways that create legal, reputational, or fairness problems. Different risk, different playbook.
Multiple federal agencies now reference AI RMF principles in enforcement guidance. The free Generative AI Profile (NIST AI 600-1) covers risks specific to generative tools.
You can start this week with three things: an inventory of where AI is used in the business, a written acceptable use policy, and a human review requirement for any consequential decision.
How the Four Fit Together, and Which One Fits You
CSF sets direction and ownership. SP 800-53 supplies the detailed controls. SP 800-171 is a trimmed subset of 800-53 aimed at protecting CUI outside government systems. The AI RMF runs alongside all of it, covering a different risk (that cybersecurity practitioners are usually responsible for).
That shared lineage means effort is rarely wasted, and NIST publishes free crosswalk tools, including the Cybersecurity and Privacy Reference Tool, for moving between documents.
Here is the quick matching guide:
- No government work and no AI in consequential decisions? CSF 2.0 alone, which describes a large share of the businesses we advise.
- Any contract mentioning CUI or DFARS? CSF for structure, plus 800-171 at the revision your contract specifies.
- Selling cloud software to a federal agency? 800-53 at the appropriate impact level, through FedRAMP.
- AI used in hiring, lending, pricing, medical, or safety decisions? Add the AI RMF.
- A customer demanding proof from an outside party? Most small businesses land on SOC 2 (System and Organization Controls 2), an attestation issued by a CPA firm. Build on CSF first, since the gaps it surfaces are largely the same ones a SOC 2 readiness effort works through.
Pick the reference that matches your obligations and your risks, not the one that sounds most rigorous. Starting with CSF costs nothing and rarely turns out to be the wrong call.
Misconceptions to Clear Up, and First Steps
Five things I correct constantly:
- “NIST compliance” is not a single achievement, and no certificate exists to buy.
- A higher document number does not mean a stronger standard. SP 800-171 is smaller than SP 800-53 by design.
- Low, Moderate, and High describe information impact, not organizational maturity.
- Voluntary is not the same as unnecessary. Most small business NIST obligations arrive on a purchase order rather than from a regulator.
- Free documentation does not mean free implementation. Staff time, tooling, and evidence gathering are the real budget lines.
Five things to do about it:
- Read your contracts and customer agreements for obligations already in force.
- Inventory what data you hold and where it lives, since scope drives cost more than anything.
- Run a CSF 2.0 self-assessment across the six functions and write down every gap.
- Build an AI inventory if AI is used anywhere in the business.
- Assign one accountable owner, technical or not, and document decisions as you go, since evidence is what assessors, insurers, and customers review.
The Answer to That Email
The CEO who called me sent his reply the next day. It did not say “yes,” and it did not say “mostly.” It said his company runs its security program against NIST CSF 2.0, listed the six functions, named the owner of each, and offered to walk through the self-assessment on a call. The prospect’s security team asked two follow-up questions and moved on. Total cost: about eleven hours of internal time. Zero dollars in new license or tool fees.
Want to get great cybersecurity content delivered to your inbox? Click here to sign up for our monthly newsletter, Tales from the Click!