NIST Seeks Comments on Cybersecurity Framework Refresh


The National Institute of Standards and Technology (NIST) is seeking comments to improve its Cybersecurity Framework, “Framework for Improving Critical Infrastructure Cybersecurity” (Request for Information available here). The Cybersecurity Framework is a key document providing organizations with standards, guidelines, and best practices to manage cybersecurity risk. With many changes to the cybersecurity landscape since the last update to the Cyber Framework in 2018, NIST hopes to address new threats, capabilities, technologies, and resources. Comments are due by April 25, 2022.

In particular, NIST is seeking guidance on whether it should integrate supply chain-related cybersecurity guidance into the Cyber Framework or create a new cyber-related supply chain framework. In addition, NIST seeks public feedback on the following key categories:

The comment period closes on April 25, 2022, and information on submitting comments can be found here.

Putting it into Practice: The NIST Cyber Framework is an important cyber threat management tool for companies looking to develop and secure their data security programs. This comment period is a key opportunity for organizations to improve the Framework and provide important feedback to ensure the Framework reflects actual experience and practice.


Copyright © 2025, Sheppard Mullin Richter & Hampton LLP.
National Law Review, Volume XII, Number 69