Skip to main content
U.S. flag

An official website of the United States government

Dot gov

The .gov means it’s official.
Federal government websites often end in .gov or .mil. Before sharing sensitive information, make sure you’re on a federal government site.

Https

The site is secure.
The https:// ensures that you are connecting to the official website and that any information you provide is encrypted and transmitted securely.

Frequently Asked Questions

Framework Basics

What is the Framework, and what is it designed to accomplish?

Is my organization required to use the Framework?

Does it provide a recommended checklist of what all organizations should do?

See all questions


Framework Users

What critical infrastructure does the Framework address?

Does the Framework apply only to critical infrastructure companies?

Does the Framework benefit organizations that view their cybersecurity programs as already mature?

See all questions


Framework Components

What is the Framework Core and how is it used?

What are Framework Profiles and how are they used?

What are Framework Implementation Tiers and how are they used?

See all questions


Using the Framework

What is the difference between 'using', 'adopting', and 'implementing' the Framework?

Would the Framework have prevented recent highly publicized attacks?

Does the Framework address the cost and cost-effectiveness of cybersecurity risk management?

See all questions


Small Business Use

Does the Framework apply to small businesses?

Will NIST provide guidance for small businesses? Is there a starter kit or guide for organizations,  just getting started with cybersecurity?

Will NIST provide guidance for small businesses? Is there a starter kit or guide for organizations just getting started with cybersecurity?

See all questions


U.S. Federal Agency Use

Are U.S. Federal agencies required to apply the Framework to Federal information systems?

Can U.S. Federal agencies apply the Framework to Federal information systems?

How is NIST integrating the Cybersecurity Framework into the cybersecurity risk management practices of federal agencies?

See all questions


Relationship Between the Framework and Other Approaches and Initiatives

What is the relationship between the Cybersecurity Framework and the NICE Cybersecurity Workforce Framework?

What is the relationship between the Cybersecurity Framework and the NIST Privacy Framework currently under development?

What is the relationship between the Framework and the DHS Critical Infrastructure Cyber Community (C3) Voluntary Program?

See all questions


Updates to the Cybersecurity Framework

How often will NIST update the Framework?

How did NIST process the V1.1 update?

How did NIST determine features for this update?

See all questions


Informative References

What are Informative References?

What is the Online Informative References (OLIR) Program?

Why were Online Informative References necessary?

See all questions


Communicating with NIST

How can I ensure resources or case studies my organization has released publicly are visible for others to use?

Does NIST encourage translations of the Cybersecurity Framework? If so, is there a procedure to follow?

Who can answer additional questions regarding the Framework?

See all questions

Created February 11, 2015, Updated September 13, 2019