National Institute of Standards and Technology
The National Institute of Standards and Technology (NIST) is a U.S. federal agency, part of the Department of Commerce, that develops and promotes measurement science, standards, and technology. Congress established it to help remove obstacles to U.S. industrial competitiveness, and it is one of the nation's oldest physical science laboratories. In the compliance world, NIST is widely known for publishing cybersecurity and information security guidance, though most of that material is voluntary rather than legally binding on private organizations unless adopted by law or contract.
NIST is an agency of the United States Department of Commerce whose mission is to promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology. It develops and maintains standards, guidelines, and reference materials across scientific and technical domains, including a substantial body of information security and cybersecurity resources published and aggregated through its Computer Security Resource Center (CSRC). NIST publications (for example its cybersecurity frameworks and special publications) are generally voluntary and non-binding as a matter of law for private-sector entities; they may acquire mandatory force only where incorporated into statute, regulation, agency policy, or contractual obligation—most directly for U.S. federal agencies and their contractors. NIST is a standards-development and guidance body, not a regulator or enforcement authority, and it does not itself certify organizations; its outputs are periodically revised and superseded, so readers should verify against the current authoritative NIST source.
Why it matters
NIST occupies an unusually influential position in the compliance landscape despite the fact that most of its cybersecurity and information security output is voluntary as a matter of law. Its guidance—published and aggregated through resources such as the Computer Security Resource Center—has become a common reference point for organizations designing security programs, precisely because it is developed by a respected federal science agency and is freely available. Compliance officers and security professionals frequently encounter NIST materials as the de facto vocabulary and structure for discussing risk, controls, and safeguards, even in sectors where no law compels their use.
The distinction between influence and legal obligation matters greatly. For U.S. federal agencies and, in many cases, their contractors, certain NIST guidance can carry mandatory force where it is incorporated into statute, regulation, or agency policy. For private-sector organizations without such a nexus, the same publications generally remain non-binding unless adopted through contract or referenced by an applicable law. Treating NIST guidance as universally mandatory—or dismissing it as merely optional without checking whether a contractual or regulatory hook applies—can each lead to compliance errors.
Because NIST is a standards-development and guidance body rather than a regulator, it does not enforce its publications or certify organizations against them. Readers should therefore separate the act of aligning with NIST guidance from any formal certification or attestation, and should confirm whether a specific obligation to follow NIST exists in their particular legal or contractual context.
Who it's relevant to
Inside NIST
Common questions
Answers to the questions practitioners most commonly ask about NIST.

