CCCyber Security Resource Center logo

Cyber Security Resource Center Unclaimed

Cybersecurity

csrc.nist.gov

Gaithersburg, MD, United States

NIST's Cyber Security Resource Center provides standards, guidelines, and collaborative cybersecurity resources to protect information systems.

The Cyber Security Resource Center (CSRC) is the National Institute of Standards and Technology (NIST) Information Technology Laboratory’s hub for computer security, cybersecurity, and privacy resources. It provides publications, projects, and events and coordinates two major divisions— the Computer Security Division (CSD) and the Applied Cybersecurity Division (ACD)—to develop standards, guidelines, mechanisms, tools, metrics, and practices to protect the United States' information and information systems and to advance practical cybersecurity and privacy through outreach and collaboration.

CSRC aims to advance practical cybersecurity and privacy through outreach and the application of standards and best practices to enable the U.S. to adopt robust cybersecurity capabilities.

What we offer

IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements

Establishes guidelines for IoT product cybersecurity within federal systems, aiming to enhance risk management and control allocation.

csrc.nist.gov/publications/sp/800/213/r1/ipd

NIST SP 1326: Cybersecurity Supply Chain Risk Management — Due Diligence Assessment Quick-Start Guide

Facilitates informed procurement decisions through due diligence in cybersecurity supply chain risk management.

csrc.nist.gov/publications/sp/1326/final

NIST SP 1339: OT Backup Quick Start Guide

A comprehensive guide for backup management in Operational Technology environments to ensure effective recovery.

csrc.nist.gov/pubs/sp/1339/final

Market segments

Market size by segment

Growth potential (CAGR)

IoT security and product governance

7.5 Billion USD22% CAGR

Capabilities for establishing cybersecurity requirements, allocating controls, and managing risk for Internet of Things products used in federal and regulated information systems.

Supplier discovery and procurement intelligence

3.5 Billion USD16% CAGR

Discovery, due diligence and continuous monitoring of technology suppliers and partners to support vendor selection, procurement decisions and supplier risk assessment.

Operational technology backup and resilience

1.5 Billion USD15% CAGR

Guidance for OT backup strategy, integration with change management, regular recovery testing, and measures to improve operational technology system resilience.

Federal risk management and security program advisory

3 Billion USD12.5% CAGR

Risk assessments, security program design and governance, remediation planning, and acquisition-focused cybersecurity support for federal agencies and government contractors.

More information about our offering

IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements

NIST SP 800-213 Rev. 1 IPD provides guidelines for establishing cybersecurity requirements for IoT products in federal information systems. It covers risk management considerations and how to allocate appropriate controls, with an emphasis on creating a structured, government-facing IoT security baseline. The IPD is a public draft intended for stakeholder input.

  • Establishes Clear Cybersecurity Requirements
    Facilitates informed decision-making to ensure necessary security controls are derived and implemented effectively.
  • Provides Comprehensive Allocation Guidance
    Ensures IoT products are integrated with security controls tailored to their functionality and risks.
  • Incorporates Risk Management Strategies
    Improves understanding of risks posed by IoT integration, enhancing overall information system security.
  • Encourages Community Engagement
    Promotes a collaborative approach in refining guidelines for broader applicability and effectiveness.

NIST SP 1326: Cybersecurity Supply Chain Risk Management — Due Diligence Assessment Quick-Start Guide

NIST SP 1326 is a quick-start guide for C-SCRM program management, focusing on due diligence assessments for ICT suppliers. It outlines components such as foreign ownership, provenance, resilience, foundational cyber practices, and supply chain tiers, to support risk-informed procurement decisions.

  • Informs Risk Assessment Decisions
    Provides key metrics to assess supplier risks related to foreign control and influence.
  • Integrates Cybersecurity Standards
    Ensures that cybersecurity best practices are part of supplier assessments to enhance overall security.
  • Establishes Product Origins
    Helps ascertain the origin and manufacturing processes of ICT products to mitigate risks.
  • Evaluates Supply Chain Strength
    Analyzes the ability of suppliers to withstand and recover from disruptions.
  • Clarifies Supplier Relationships
    Provides a structured approach to assess the interconnectedness of different supply chain levels.

NIST SP 1339: OT Backup Quick Start Guide

NIST SP 1339 provides an OT backup quick-start guide. It covers backup management for Operational Technology environments, integrating backups into change management, testing recovery procedures, and enhancing system resilience in OT contexts.

  • Integrate Backups Into Change Management
    Ensures operational continuity by aligning backup processes with change management practices, minimizing risks during system updates.
  • Provide OT Backup Management Guidelines
    Offers essential strategies tailored for managing backups in OT environments, addressing unique challenges faced by these systems.
  • Conduct Regular Testing Of Backups
    Ensures that recovery processes are effective by routinely verifying backup integrity and restore capabilities, thus enhancing overall system reliability.
  • Enhance Resilience Of OT Systems
    Provides targeted advice to strengthen operational resilience in OT environments by implementing robust backup strategies.

References

Methodology and sourcing behind the figures shown above.

IoT security and product governance

Estimation based on published IoT security market figures and the broader IoT market as context. Fortune Business Insights reports the global IoT security market at USD 45.51B (2025) with very high growth; Ken Research (US) reports a USD 9.85B US IoT security market (2024) and projects 25.7% CAGR to 2030. The overall IoT market (MarketsandMarkets) is much larger (USD ~547B in 2025), establishing ceiling for device-related spending. ‘IoT security and product governance’ (secure-by-design, compliance, SBOM, lifecycle/OTA, PKI) is a focused subset (governance/compliance-heavy, federal/regulatory buyers) of IoT security; using a conservative share (~15–18%) of the global IoT security market yields ~USD 6–8.5B today. Given regulatory acceleration and recurring SaaS/managed models, expected CAGR is high but slightly below some aggressive IoT-security forecasts; I estimate ~22% CAGR for this specialized segment.

Supplier discovery and procurement intelligence

Estimate based on published market figures for adjacent markets in the provided results. Procurement analytics is reported at USD 8.73B (2025) while procurement/data intelligence is reported at USD 2.6B (2022) with a high CAGR forecast. Supplier discovery & procurement intelligence is a narrower subsegment (discovery, due diligence, continuous monitoring) of these markets; I conservatively sized it at roughly one-third of the broader procurement analytics market and between the smaller procurement data intelligence figure and the larger procurement analytics figure. Growth potential (CAGR ~16%) is a midpoint between the lower, broad-market forecast (6.5%) and the higher niche forecast (25.3%), reflecting faster adoption for specialized supplier intelligence tools.

Operational technology backup and resilience

Estimates use multiple OT security market reports from the search results as the primary base (global and US market sizes and CAGRs). Global OT security is reported in the mid‑teens billions (2025/2026) with CAGRs commonly 9–17%. Operational-technology backup & resilience is a narrower subsegment of OT security (backup, recovery testing, change-management integration, resilience services). Conservatively allocating ~5–7% of the overall OT security market to backup & resilience yields ~USD 1.5B today. Growth potential is aligned with the broader OT security market average (~15% CAGR), reflecting high demand for resilience, regulatory drivers, and services-led spending.

Federal risk management and security program advisory

Estimation based on published global security advisory / risk-management market sizes and CAGRs in the search results (FMI, MRFR, MarketDataForecast). FMI reports ~USD 18.4B (2025) with 12.3% CAGR and MRFR reports ~USD 14.47B (2024) with 17.6% CAGR; risk-management market reports show similar double-digit growth. Applying a conservative government/federal vertical share (≈15–20%) of the broader security advisory market—plus expected continued federal cybersecurity and resilience investments (Treasury/CISA activity)—yields an estimated federal-focused advisory market of about USD 3.0B and a growth potential around 12.5% CAGR (aligned with the mid-to-lower range of reported global CAGRs).

Related Organizations