Skip to main content

Federal Requirements

Cybersecurity Frameworks

The major cybersecurity frameworks that govern federal contractors and the businesses around them — federal (CMMC, NIST SP 800-171, NIST CSF, FISMA, FedRAMP), industry (PCI DSS, HIPAA, SOC 2, HITRUST, CIS), and international (ISO 27001, GDPR, NIS2, DORA): what each is, who must comply, and how it is verified.

Overview

Cybersecurity "frameworks" are the named standards, regulations, and certifications that tell an organization what security to put in place and how it gets checked. They overlap heavily, which is why they are so easily confused. This page is a map across the three families that matter most to organizations doing business with — or alongside — the U.S. government: federal and government-contracting frameworks, industry and sector frameworks, and international standards and laws.

Keep one principle in mind throughout: every framework below sits on top of the generally-applicable legal baseline — the FTC Act, state breach and data-security laws, GLBA, and HIPAA — that already governs any business handling data. Frameworks are what a particular contract, customer, or market adds; they are not where your data-security duty begins.

How to read this page. The side-by-side comparison and the "which applies to me?" decision tree are at the bottom. The sections below explain each framework in plain language — what it is, who it binds, and how it is verified. Where a framework has its own detailed page on this site, follow the link.

Federal & Government-Contracting Frameworks

These are the frameworks a federal contract can require directly through its clauses.

FAR 52.204-21 — The FCI Baseline

The Federal Acquisition Regulation's basic safeguarding clause sets 15 minimum controls for any contractor system that handles Federal Contract Information (FCI) — non-public information generated for the government. It is the universal floor for federal contractors, with no dollar threshold; contracts solely for commercial off-the-shelf (COTS) items are the main carve-out. See the FAR baseline for the full list.

NIST SP 800-171 — The CUI Standard

When a contract involves Controlled Unclassified Information (CUI), NIST SP 800-171 is the standard you implement. A critical nuance as of 2026: DoD contracts under DFARS 252.204-7012 remain tied to Revision 2 and its 110 controls through a standing DoD class deviation that has no announced end date, even though NIST published Revision 3 in 2024. DoD has issued draft organization-defined parameters signaling an eventual move to Rev 3 for both DFARS and CMMC, but until your contract says otherwise, Rev 2's 110 controls in 14 families are what you must meet. Watch your contract language and SPRS guidance for the transition.

SPRS: the Supplier Performance Risk System, where DoD contractors post their NIST SP 800-171 self-assessment scores. A current score (generally within three years) is a condition of award on covered DoD contracts.

CMMC 2.0 — Verification, Not a New Standard

The Cybersecurity Maturity Model Certification does not invent new controls — it verifies that you have implemented NIST SP 800-171 (and, at Level 3, selected 800-172 enhanced controls). Its three levels:

  • Level 1 — basic FCI safeguarding (the FAR 52.204-21 fifteen); annual self-assessment.
  • Level 2 — full NIST SP 800-171; self-assessment or, for most CUI, a third-party (C3PAO) certification.
  • Level 3 — Level 2 plus selected 800-172 controls; government-led (DIBCAC) assessment.

The CMMC program rule (32 C.F.R. Part 170) and the DFARS acquisition rule (48 CFR) took effect November 10, 2025, starting a phased rollout: Level 1/2 self-assessments in solicitations from Phase 1 (Nov 2025), Level 2 C3PAO certifications from Phase 2 (Nov 10, 2026), Level 3 from Phase 3 (Nov 2027), and full implementation by Phase 4 (Nov 2028). See the Defense industry page for the rollout timeline.

FISMA, FIPS 200 & NIST SP 800-53

The Federal Information Security Modernization Act (FISMA) requires federal agencies — and contractors operating information systems on their behalf — to secure those systems. FIPS 200 sets the minimum security requirements, and the control catalog is NIST SP 800-53 (Rev 5), tailored to a system's FIPS 199 impact level (Low/Moderate/High). Compliance is demonstrated through an agency Authorization to Operate (ATO) and ongoing continuous monitoring.

NIST Risk Management Framework (SP 800-37)

The RMF is the seven-step process — Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor — that agencies use to apply SP 800-53 controls and reach an ATO. It is the procedural backbone behind FISMA and FedRAMP rather than a control set of its own.

NIST CSF 2.0

The NIST Cybersecurity Framework 2.0 (2024) organizes cybersecurity into six functions — Govern, Identify, Protect, Detect, Respond, Recover. It is voluntary and risk-based, not contractually mandated, and many organizations use it as the management layer that sits above their detailed control set (such as 800-171 or 800-53). Version 2.0 added the Govern function and broadened the framework's audience well beyond critical infrastructure.

FedRAMP & GovRAMP — Cloud Authorization

FedRAMP standardizes the security authorization of cloud services sold to federal agencies. It uses NIST SP 800-53 baselines by impact level, a third-party assessment (3PAO), and an agency or program authorization plus continuous monitoring. FedRAMP is modernizing through "FedRAMP 20x," a phased effort (in cohort testing as of 2026) to automate authorization using machine-readable Key Security Indicators and cut timelines from many months toward weeks. GovRAMP — the program formerly known as StateRAMP, rebranded in February 2025 — provides an analogous authorization path for state, local, education, and tribal governments. See the GovRAMP page.

Industry & Sector Frameworks

These bind organizations based on the kind of data or business they handle, regardless of any government contract.

PCI DSS v4.0.1 — Payment Card Data

The Payment Card Industry Data Security Standard applies to any organization that stores, processes, or transmits payment card data. It is enforced contractually by the card brands and acquiring banks, not by statute. The current version is v4.0.1, and as of March 31, 2025 every requirement — including the formerly "future-dated" controls for stronger authentication, e-commerce script protection, and authenticated internal vulnerability scanning — is mandatory.

HIPAA Security Rule — Health Information

The HIPAA Security Rule (45 C.F.R. Part 164) requires healthcare "covered entities" and their "business associates" to safeguard electronic protected health information (ePHI). HHS's Office for Civil Rights published a Notice of Proposed Rulemaking in January 2025 to modernize the rule — including making most "addressable" specifications mandatory — but no final rule had issued as of mid-2026. It also appears on the legal baseline because it binds healthcare businesses independent of any contract.

GLBA Safeguards Rule — Financial Institutions

The Gramm-Leach-Bliley Act Safeguards Rule (16 C.F.R. Part 314) requires "financial institutions," broadly defined by the FTC to include many non-bank businesses, to maintain a written information-security program. Since May 2024, covered entities must report breaches affecting 500 or more consumers to the FTC within 30 days.

SOC 2 — Service Organizations

SOC 2 is an attestation report, performed by a CPA firm against the AICPA Trust Services Criteria (the 2017 criteria with revised points of focus, 2022). It evaluates a service organization's controls across up to five categories — Security, Availability, Processing Integrity, Confidentiality, and Privacy — and is the de facto trust artifact that SaaS and cloud vendors provide to enterprise customers. It is a report, not a certification or a fixed control list.

HITRUST CSF — Certifiable, Healthcare-Centric

The HITRUST CSF is a certifiable framework that harmonizes many authoritative sources (HIPAA, NIST, ISO, PCI DSS, and others) into one prescriptive control set, widely used in healthcare and by vendors that serve it. Releases are frequent; v11.7.0 shipped in December 2025, adding mappings to sources such as FedRAMP 20x Key Security Indicators. HITRUST offers tiered assessments (e1, i1, r2) of increasing rigor.

CIS Controls v8.1 — Prioritized Safeguards

The CIS Critical Security Controls are a prioritized, vendor-neutral set of safeguards maintained by the Center for Internet Security. The current release, v8.1 (2024), organizes 18 controls into three Implementation Groups (IG1–IG3) so smaller organizations can start with the essentials. CIS publishes mappings to NIST CSF, NIST SP 800-53, and ISO/IEC 27001, making it a practical on-ramp to the heavier frameworks.

NERC CIP — Bulk Electric System

The NERC Critical Infrastructure Protection standards are mandatory, enforceable cybersecurity requirements for owners and operators of the North American bulk electric system, overseen by FERC. They are a sector-specific regime rather than a general-purpose framework.

International Frameworks & Laws

These reach organizations that operate, sell, or hold data across borders — especially in the EU.

ISO/IEC 27001:2022 — The ISMS Standard

ISO/IEC 27001 is the leading international standard for an Information Security Management System (ISMS). It is voluntary but frequently required by commercial and international partners, and it offers something U.S. frameworks generally do not: an accredited third-party certification. The 2022 revision restructured Annex A into 93 controls across four themes (organizational, people, physical, technological); organizations certified to the 2013 version had to transition by October 31, 2025.

EU General Data Protection Regulation (GDPR)

The GDPR governs the processing of EU residents' personal data and reaches any organization worldwide that offers goods or services to, or monitors, people in the EU. It is a data-protection law rather than a security control set, but it carries a "security of processing" obligation (Article 32) and large fines for breaches.

EU NIS2 Directive

NIS2 raises baseline cybersecurity and incident-reporting obligations for "essential" and "important" entities across critical sectors in the EU. Member States were to transpose it into national law by October 17, 2024, though transposition has lagged in several states. U.S. companies with EU operations or EU critical-sector customers can be pulled into its scope.

DORA — EU Financial Sector

The Digital Operational Resilience Act sets ICT risk-management, incident-reporting, resilience-testing, and third-party-oversight requirements for EU financial entities and their critical ICT providers. It has applied since January 17, 2025.

Other International Instruments

The EU Cybersecurity Act (Reg. 2019/881) established the EU's cybersecurity certification framework and ENISA's mandate. The Council of Europe Convention on Cybercrime ("Budapest Convention," ETS No. 185) harmonizes cybercrime law internationally — context for contractors operating abroad, not a control set. The PRC Personal Information Protection Law (PIPL) governs personal-data handling in and out of China and can bind multinationals with Chinese operations.

Side-by-Side Comparison

FrameworkWho it bindsWhat it coversHow it is verifiedApplies if
FAR 52.204-21All federal contractors with FCI15 basic FCI safeguardsAnnual self-assessment (CMMC Level 1 for DoD)Contract includes the clause and FCI flows through your systems
NIST SP 800-171Federal contractors with CUI110 CUI protection controlsSPRS self-assessment; C3PAO for DoD CMMC Level 2Contract requires DFARS 252.204-7012 or CMMC Level 2
CMMCDoD contractorsLevels 1-3 (FCI to CUI to enhanced CUI)Self-assessment (L1/some L2) or C3PAO (L2/L3)DoD solicitation includes DFARS 252.204-7021
NIST CSFVoluntary; CISA-recommendedRisk-based cybersecurity outcomesSelf-assessed or third-partyNo federal mandate; common in civilian agency guidance
FedRAMPCloud service providers selling to agenciesNIST SP 800-53 cloud controlsThird-party assessment organization (3PAO)Offering a cloud service to a federal agency
ISO/IEC 27001Voluntary; international standardISMS with 93 Annex A controlsAccredited third-party certificationCommercial/international partner requirement

Which Applies to Me? Decision Tree

1. Federal contract or subcontract? No: FAR/CMMC do not apply. Yes: continue. 2. Contract involves FCI? No: FAR 52.204-21 does not apply. Yes: FAR 52.204-21 applies (15 safeguards). 3. Contract involves CUI? No: stop at FAR 52.204-21. Yes: NIST SP 800-171 applies (DFARS 252.204-7012). 4. DoD contract? No: CMMC does not apply. Yes: CMMC applies; check solicitation for level (1, 2, or 3). 5. Offering a cloud service to an agency? FedRAMP may apply; confirm with the agency. 6. EU operations or EU customers? GDPR and potentially NIS2/DORA may apply.

Note (updated July 2026): On May 13, 2026, NIST finalized **SP 800-172 Revision 3** and its companion SP 800-172A Revision 3, expanding enhanced CUI requirements from 39 to roughly 115. CMMC Level 3 has not yet adopted Rev 3 — it still references the February 2021 edition, so the control mappings on this page remain current for compliance today. With both 800-171 Rev 3 and 800-172 Rev 3 now final, a single future DoD rulemaking could update CMMC Levels 2 and 3 together. These control IDs will be refreshed once DoD acts.
Was this page helpful?

Side-by-Side Comparison

Major frameworks at a glance

A plain-English summary of what each framework is, who it applies to, and how it gets verified. Full detail and citations are in the sections above.

DimensionCMMC 2.0NIST SP 800-171NIST CSF 2.0FISMA / SP 800-53FedRAMPISO/IEC 27001
PurposeVerify defense contractors meet 800-171 (and selected 800-172) controls.Protect Controlled Unclassified Information on non-federal systems.Voluntary risk-management framework for any organization.Mandatory security program for federal agencies and systems run on their behalf.Standardize security authorization of cloud services used by federal agencies.International standard for an information security management system (ISMS).
Who it applies toDoD prime and sub contractors handling FCI or CUI.Any non-federal entity handling CUI under federal contract.Anyone, voluntarily — often a baseline private-sector reference.Federal agencies and contractors operating systems on their behalf.Cloud service providers selling to federal agencies, and their agency customers.Any organization worldwide; often required by commercial or international partners.
Mandatory?Yes, by DFARS clause, phasing in from Nov 2025.Yes, when DFARS 252.204-7012 or equivalent applies.No (voluntary).Yes, by statute.Yes, for cloud services used by federal agencies.No (voluntary), but frequently required by contract.
VerificationSelf-attestation (L1, some L2), C3PAO (L2), DIBCAC (L3).Self-assessment with SPRS score; auditable.Self-assessment.Agency authorization to operate (ATO); continuous monitoring.3PAO assessment + agency/PMO authorization; continuous monitoring.Accredited third-party certification audit; ~3-year cycle with surveillance.
Control basis17 (L1) / 110 (L2) / 110 + selected 800-172 (L3).110 controls in 14 families (Rev 2; DoD baseline).6 functions (Govern, Identify, Protect, Detect, Respond, Recover).Full NIST SP 800-53 catalog, tailored by FIPS 199 impact level.NIST SP 800-53 baselines by impact level (Low / Moderate / High).93 Annex A controls in 4 themes (2022 revision).

Which applies to me?

Quick decision tree

Start with the federal contracting layer, then check the industry and international triggers that apply to your business.

Federal contracting layer

  1. Step 1

    Do you hold or pursue a federal contract?

    If no, the FAR/DFARS layer does not apply yet — focus on the legal baseline (FTC Act, state breach laws, sector statutes) and any industry framework below.

  2. Step 2

    Does the contract touch FCI?

    If yes, FAR 52.204-21 (the 15 basic safeguards) applies. This is the floor for any contractor that creates non-public information for the government.

  3. Step 3

    Does the contract touch CUI?

    If yes, NIST SP 800-171 controls apply. For DoD work, that means DFARS 252.204-7012 plus the relevant CMMC level.

  4. Step 4

    Are you hosting a federal system or cloud service?

    If yes, you fall under FISMA / NIST SP 800-53, and any cloud service typically needs FedRAMP authorization at the matching impact level.

Beyond federal contracts

  1. Payment data

    Do you handle payment cards?

    PCI DSS v4.0.1 applies to any organization that stores, processes, or transmits cardholder data — enforced by the card brands and your acquiring bank.

  2. Health data

    Do you handle health information (ePHI)?

    The HIPAA Security Rule applies to covered entities and business associates. Vendors often also pursue HITRUST CSF certification or a SOC 2 report.

  3. Cloud to government

    Do you sell cloud services to government?

    Federal customers require FedRAMP authorization; state, local, education, and tribal customers increasingly require GovRAMP (formerly StateRAMP).

  4. International

    Do you operate in or sell to the EU?

    GDPR governs EU personal data, with NIS2 or DORA possible for critical sectors. ISO/IEC 27001 is the common international security baseline customers ask for.