NIST Releases Updated Cybersecurity Framework


Pursuant to Executive Order 13636, the National Institute of Standards and Technology (“NIST”) established the Framework for Improving Critical Infrastructure Cybersecurity, Version 1.0, a technology-neutral, voluntary, risk-based cybersecurity framework that includes standards and processes intended to align policy, business, and technological approaches to addressing cybersecurity risks.  Four years later, NIST has released an updated version of the Framework.

Prior to releasing this update, NIST to get a better understanding of how companies were using the Framework, released a draft of the revised Framework for public comment, and held a public webcast to discuss the updates to the Framework.  The key updates in Version 1.1 are summarized below.

The changes made in Version 1.1 are intended to be “fully compatible” with Version 1.0.  Companies that have already incorporated Framework Version 1.0 are encouraged to implement the additional content as appropriate.  Companies new to the Framework should follow Version 1.1.


© 2025 Covington & Burling LLP
National Law Review, Volume VIII, Number 113