AWS and Cloudanix team co-authored this blog: Real-Time Threat and Anomaly Detection for Workloads on AWS

What Is NIST Compliance

Learn what NIST compliance means in 2026, including CSF 2.0's six core functions, SP 800-171 Rev 3, CMMC 2.0, and the AI Risk Management Framework.

NIST (National Institute of Standards and Technology) develops cybersecurity frameworks and best practices that help organizations manage and reduce cyber risk. NIST compliance refers to the practice of aligning your security program with these frameworks — whether mandated by regulation or adopted voluntarily to strengthen your security posture.

While NIST frameworks are not regulations themselves, they underpin many federal and industry requirements. For US federal contractors, compliance with specific NIST publications is contractually required. For private-sector organizations pursuing FedRAMP authorization, building governance programs, or demonstrating security maturity to customers, NIST provides a proven, structured approach to cybersecurity risk management.

Cloudanix Framework: NIST

Key NIST Frameworks in 2026

Before diving into the details, here’s a quick overview of the most relevant NIST publications for security leaders today:

FrameworkPurposePrimary Audience
NIST CSF 2.0Cybersecurity risk managementAll organizations
NIST SP 800-53 Rev 5Security & privacy controls for federal systemsFederal agencies
NIST SP 800-171 Rev 3Protecting CUI in non-federal systemsFederal contractors
NIST AI RMF (AI 100-1)AI/ML risk managementOrganizations building or deploying AI systems
CMMC 2.0DoD contractor cybersecurity maturityDefense industrial base

NIST Cybersecurity Framework 2.0: The Six Core Functions

The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, introduced a significant structural change from the previous CSF 1.1. The most notable addition is the Govern function, expanding the framework from five core functions to six.

CSF 2.0 also broadened its scope — it now explicitly applies to organizations of all sizes and sectors, not just critical infrastructure.

Govern (New in CSF 2.0)

The Govern function establishes and monitors the organization’s cybersecurity risk management strategy, expectations, and policies. It sits at the center of the framework, informing and being informed by the other five functions. Key activities include:

  • Organizational context: Understanding the organization’s mission, stakeholder expectations, and legal/regulatory requirements that shape cybersecurity risk decisions.
  • Risk management strategy: Establishing risk appetite and tolerance levels, and communicating them across the organization.
  • Roles and responsibilities: Defining cybersecurity roles, authorities, and accountability structures including board-level oversight.
  • Policy: Creating, communicating, and enforcing cybersecurity policies aligned with organizational strategy.
  • Oversight: Monitoring and reviewing cybersecurity risk management outcomes to adjust strategy as needed.
  • Supply chain risk management: Establishing processes to identify, assess, and manage cybersecurity risks across the supply chain.

Identify

The Identify function focuses on understanding your organizational assets, data, systems, and the cybersecurity risks associated with them. It involves activities like:

  • Asset management: Creating a comprehensive inventory of all hardware, software, data, services, and information systems within the organization.
  • Risk assessment: Identifying and evaluating threats, vulnerabilities, likelihood, and impact to prioritize risk response.
  • Improvement: Using assessment results to drive improvements in security policies, processes, and procedures.

Protect

The Protect function emphasizes implementing safeguards to prevent or reduce the likelihood and impact of cybersecurity events. Key activities include:

  • Identity management and access control: Implementing mechanisms to control who can access systems and data based on the principle of least privilege.
  • Awareness and training: Educating personnel about cybersecurity risks and their roles in mitigating them.
  • Data security: Employing encryption, data loss prevention (DLP), and other measures to safeguard sensitive information.
  • Platform security: Securing hardware, software, and services consistent with risk strategy, including patch management and system hardening.
  • Technology infrastructure resilience: Implementing security architectures that support availability and integrity.

Detect

The Detect function enables timely discovery of cybersecurity events through continuous monitoring and analysis. Key activities include:

  • Continuous monitoring: Employing security tools and processes to identify and log security events in real time across infrastructure, applications, and networks.
  • Adverse event analysis: Correlating and analyzing event data to identify anomalies, indicators of compromise, and potential security incidents.
  • Log management: Centralizing and retaining logs from various systems to support detection, investigation, and forensics.

Respond

The Respond function ensures the organization can take appropriate action once a cybersecurity incident is detected. Key activities include:

  • Incident management: Executing incident response processes including triage, escalation, and coordination with internal and external stakeholders.
  • Incident analysis: Investigating incidents to determine scope, root cause, and attribution.
  • Incident containment and eradication: Taking steps to isolate the threat, prevent further damage, and remove the adversary from affected systems.
  • Incident reporting: Communicating incident details to designated stakeholders, regulators, and law enforcement as required.

Recover

The Recover function ensures timely restoration of normal operations and minimizes the impact of a cybersecurity incident. Key activities include:

  • Incident recovery plan execution: Restoring affected systems, data, and services to operational state using documented recovery procedures.
  • Communication: Coordinating restoration activities and communicating progress with relevant stakeholders.
  • Improvements: Incorporating lessons learned from incidents into recovery planning and broader cybersecurity strategy.

NIST SP 800-171 Rev 3 and CMMC 2.0

What Changed in SP 800-171 Rev 3

NIST SP 800-171 Revision 3, released in May 2024, brought significant changes for organizations handling Controlled Unclassified Information (CUI):

  • Alignment with SP 800-53 Rev 5: Controls are now directly derived from and traceable to SP 800-53 Rev 5, making it easier to maintain consistency across compliance programs.
  • Reorganized control families: The structure now mirrors SP 800-53’s 20 control families (up from 14 in Rev 2), including new families like Supply Chain Risk Management and Personally Identifiable Information Processing.
  • Increased control specificity: More prescriptive requirements replace the previously flexible language, reducing ambiguity in implementation.
  • Enhanced assessment procedures: SP 800-171A Rev 3 provides updated assessment procedures that map directly to the new control structure.

The CMMC 2.0 Connection

The Cybersecurity Maturity Model Certification (CMMC 2.0) is the Department of Defense’s mechanism for verifying that defense contractors actually implement NIST SP 800-171 controls. For organizations in the defense industrial base, understanding this relationship is critical:

  • Level 1 (Foundational): 15 basic safeguarding requirements from FAR 52.204-21 — self-assessment.
  • Level 2 (Advanced): Aligns with the 110 controls in NIST SP 800-171 Rev 2 (transitioning to Rev 3) — requires third-party assessment for critical programs.
  • Level 3 (Expert): Incorporates additional controls from NIST SP 800-172 — requires government-led assessment.

CMMC 2.0 rulemaking was finalized in late 2024, with phased implementation beginning in 2025. Defense contractors should be actively preparing their compliance posture now.


NIST AI Risk Management Framework (AI RMF)

For organizations building or deploying AI/ML systems, the NIST AI Risk Management Framework (AI 100-1) provides structured guidance for managing AI-specific risks. Released in January 2023 and increasingly referenced in federal procurement and governance programs, the AI RMF defines four core functions:

  1. Govern: Establishing policies, processes, and accountability structures for AI risk management.
  2. Map: Understanding the context in which AI systems operate, including intended use, stakeholders, and potential impacts.
  3. Measure: Employing quantitative and qualitative methods to assess AI risks including bias, reliability, and security.
  4. Manage: Allocating resources and implementing controls to address identified AI risks on a priority basis.

Organizations pursuing FedRAMP or working with federal agencies are increasingly expected to demonstrate AI risk management practices aligned with this framework.


Who Needs to Follow NIST Compliance?

Mandatory Compliance

Organizations that must comply with NIST standards or face contractual/legal consequences:

  • Federal Government Agencies: All US federal agencies must comply with NIST SP 800-53 Rev 5, which provides comprehensive security and privacy controls for federal information systems.
  • Federal Contractors (CUI): Contractors handling Controlled Unclassified Information must comply with NIST SP 800-171 Rev 3, mandated through contract clauses like DFARS 252.204-7012.
  • Defense Industrial Base: DoD contractors must achieve the appropriate CMMC 2.0 certification level to bid on and maintain defense contracts.
  • FedRAMP Applicants: Cloud service providers seeking FedRAMP authorization must implement controls from NIST SP 800-53, mapped to their system’s impact level (Low, Moderate, or High).

Voluntary Adoption

Organizations that choose to adopt NIST frameworks for strategic advantage:

  • SaaS Companies: Adopting NIST CSF 2.0 demonstrates security maturity to enterprise customers and provides a pathway toward FedRAMP readiness.
  • Critical Infrastructure Providers: Organizations in healthcare, energy, financial services, and telecommunications are strongly encouraged to adopt NIST standards.
  • Mid-Market Enterprises: Companies building governance programs use NIST CSF 2.0 as a foundational structure because it maps cleanly to other frameworks (ISO 27001, SOC 2, CIS Controls).
  • Organizations Deploying AI: Companies building AI/ML systems benefit from the NIST AI RMF to demonstrate responsible AI governance.

Factors to Consider for Voluntary Adoption

  • Data sensitivity: Organizations handling personal data, financial records, or health information benefit from NIST’s structured approach to data protection.
  • Regulatory trajectory: If your industry is moving toward mandatory cybersecurity requirements, early NIST adoption reduces future compliance burden.
  • Customer requirements: Enterprise buyers increasingly require vendors to demonstrate alignment with recognized frameworks.
  • Cyber insurance: Insurers are increasingly referencing NIST CSF controls in underwriting and claims assessment.
  • Business continuity: NIST’s structured approach to resilience planning helps protect against operational disruption from cyber incidents.

Mapping NIST to Cloud Environments (AWS, Azure, GCP)

For organizations operating in public cloud, here’s how NIST CSF 2.0 functions map to native cloud security controls:

Govern

ActivityAWSAzureGCP
Policy managementAWS Organizations SCPs, AWS Config RulesAzure Policy, Management GroupsOrganization Policies, Resource Manager
Risk oversightAWS Audit ManagerMicrosoft Defender for Cloud Regulatory ComplianceSecurity Command Center Compliance
Supply chain riskAWS Artifact (vendor compliance reports)Azure Compliance ManagerAssured Workloads

Identify

ActivityAWSAzureGCP
Asset inventoryAWS Config, Systems ManagerAzure Resource Graph, Microsoft Defender CSPMCloud Asset Inventory, Security Command Center
Risk assessmentAWS Inspector, Security HubMicrosoft Defender Vulnerability ManagementSecurity Command Center Premium
Data classificationAmazon MacieMicrosoft PurviewCloud DLP

Protect

ActivityAWSAzureGCP
Identity & accessIAM, Identity Center, OrganizationsEntra ID, Conditional Access, PIMCloud IAM, Identity-Aware Proxy
Data protectionKMS, CloudHSM, S3 encryptionKey Vault, Azure Information ProtectionCloud KMS, CMEK, Confidential Computing
Network securitySecurity Groups, WAF, Network FirewallNSGs, Azure Firewall, Front Door WAFVPC Firewall Rules, Cloud Armor

Detect

ActivityAWSAzureGCP
Continuous monitoringGuardDuty, CloudTrail, Security HubMicrosoft Sentinel, Defender for CloudChronicle SIEM, Security Command Center
Anomaly detectionGuardDuty (ML-based), DetectiveMicrosoft Defender Threat IntelligenceChronicle detection rules, Threat Intelligence
Log managementCloudWatch Logs, CloudTrail LakeLog Analytics, MonitorCloud Logging, Log Analytics

Respond

ActivityAWSAzureGCP
Incident managementSecurity Hub findings, SSM Incident ManagerMicrosoft Sentinel SOAR, Defender incidentsChronicle SOAR, SCC findings
ContainmentSecurity Group isolation, Lambda automationLogic Apps automation, NSG isolationCloud Functions automation, VPC isolation

Recover

ActivityAWSAzureGCP
Data recoveryAWS Backup, S3 Versioning, RDS snapshotsAzure Backup, Site RecoveryCloud backup, persistent disk snapshots
Infrastructure recoveryCloudFormation, Elastic Disaster RecoveryARM templates, Azure Site RecoveryDeployment Manager, GKE backup

A platform like Cloudanix can automate the mapping and continuous monitoring of these cloud-native controls against NIST frameworks, providing real-time compliance posture visibility across multi-cloud environments.


10-Step Process to Achieve NIST Compliance

Here’s a structured approach businesses can follow to build and maintain their NIST compliance program:

  1. Identify applicable standards: Determine which NIST publications apply to your organization. Federal contractors typically need SP 800-171 Rev 3 and CMMC 2.0. Others may start with NIST CSF 2.0 as a governance framework.
  2. Inventory assets and data: Build a comprehensive inventory of hardware, software, data flows, cloud resources, and third-party services. You cannot protect what you do not know exists.
  3. Conduct a risk assessment: Identify threats, vulnerabilities, and potential business impact. Prioritize risks based on likelihood and severity, aligned with the Govern function’s risk appetite.
  4. Perform gap analysis: Compare your current security controls against the chosen NIST standard’s requirements. Identify gaps between your current state and target compliance posture.
  5. Develop a remediation plan: Prioritize gap closure based on risk. Define timelines, resource requirements, and responsibilities for implementing new or enhanced controls.
  6. Implement security controls: Execute the remediation plan — deploy technical controls, update policies, configure cloud security services, and establish operational procedures.
  7. Document everything: Maintain comprehensive documentation of your controls, policies, procedures, and risk decisions. This documentation is essential for both internal governance and external assessments.
  8. Train personnel: Conduct role-based security awareness training. Ensure personnel understand their responsibilities within the cybersecurity risk management program.
  9. Establish continuous monitoring: Deploy automated monitoring and assessment tools to maintain real-time visibility into your compliance posture. Cloud security posture management (CSPM) platforms can automate much of this.
  10. Conduct regular assessments: Perform internal audits and, where required, engage third-party assessors. Use findings to drive continuous improvement in your security program.

NIST Compliance Requirements by Standard

For Federal Contractors (SP 800-171 Rev 3)

  • Scope: Protecting Controlled Unclassified Information (CUI) in non-federal systems.
  • Structure: Controls organized across 20 families aligned with SP 800-53 Rev 5.
  • Assessment: Self-assessment or third-party assessment based on CMMC level requirements.
  • Key families: Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Risk Assessment, System and Communications Protection.

For FedRAMP Authorization

  • Scope: Cloud service providers offering services to federal agencies.
  • Baseline: Controls from NIST SP 800-53 Rev 5, tailored by impact level:
    • Low: ~156 controls — for systems with minimal impact from loss.
    • Moderate: ~325 controls — for systems where loss could have serious adverse effects.
    • High: ~421 controls — for systems where loss could be catastrophic.
  • Continuous monitoring: Ongoing assessment and authorization (ConMon) is required post-authorization.

General Cybersecurity Framework (CSF 2.0)

  • Scope: Any organization seeking to manage cybersecurity risk.
  • Structure: Six functions (Govern, Identify, Protect, Detect, Respond, Recover) with categories and subcategories.
  • Approach: Organizations create profiles (current state and target state) and prioritize actions to close gaps.
  • Flexibility: No mandated controls — organizations select controls appropriate to their risk context.

Cross-Cutting Requirements

Regardless of which specific NIST publication you follow, these principles apply broadly:

  • Risk-based approach: All security decisions should be informed by risk assessment, not checkbox compliance.
  • Continuous improvement: NIST frameworks assume iterative improvement, not one-time achievement.
  • Documentation and evidence: Controls must be documented and their effectiveness demonstrated through evidence.
  • Supply chain awareness: CSF 2.0 and SP 800-171 Rev 3 both emphasize third-party risk management.
  • Governance integration: Cybersecurity must be integrated into organizational governance, not siloed in IT.

How Cloudanix Helps with NIST Compliance

Cloudanix provides automated compliance monitoring and assessment across multi-cloud environments. Here’s how it maps to your NIST compliance journey:

  • Continuous compliance monitoring: Automated checks against NIST SP 800-53 and NIST CSF controls across AWS, Azure, and GCP.
  • Gap identification: Real-time visibility into which controls are met, partially met, or missing.
  • Evidence generation: Audit-ready reports and evidence packs for assessors and auditors.
  • Multi-framework mapping: Single control implementations mapped across NIST, SOC 2, ISO 27001, HIPAA, and other frameworks simultaneously.
  • Cloud-native integration: Direct integration with cloud provider APIs for accurate, real-time posture assessment.

Start your NIST compliance assessment with Cloudanix →


Additional Resources

What Our Users Are Saying

Customer Reviews

Cloudanix is trusted by security leaders worldwide to deliver proactive, reliable, and cutting-edge cloud security.

One day, I changed the password of a root account, and my CTO called me within less than a minute to confirm if I did so. I was not expecting a reaction this quick. He told me Cloudanix alerted him of this password change and that he wanted to confirm as it was a critical security notification. I couldn't believe it!

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Compliance is one way of staying secure, but what I want is the ability to go deeper and attain 'true security.' Cloudanix provides us the capability to do so.

Vishal Madan
Vishal Madan
Head of Engineering, iMocha

Cloudanix is building for the future of the cloud, which makes the product all the more desirable.

Ritesh Agarwal
Ritesh Agarwal
CEO, Airgap Networks

Cloudanix gave us the visibility we were missing. Being able to move from permanent access to a robust Just-In-Time (JIT) workflow has fundamentally changed our security posture without slowing down our engineering velocity.

Pavan Kumar Lekkala
Pavan Kumar Lekkala
SRE Lead, HugoHub

We are excited to leverage Cloudanix's comprehensive multi-cloud DevSecOps solution to secure our production workloads on AWS. Cloudanix has demonstrated that it can solve many challenges that DevSecOps teams face while continually adding new features such as SOC2 compliance and drift detection.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Managing third-party partner access was once a major concern for our security posture. With Cloudanix JIT Cloud, we've effectively achieved zero third-party risk. We can now grant access confidently, knowing that it is temporary, audited, and automatically revoked, resulting in a 100% reduction in our privileged access exposure.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

The snooze feature and responsible alerts have helped us save time and prioritize what to tackle first.

Satish Mohan
Satish Mohan
Co-founder & CTO, Airgap Networks

Implementing Cloudanix JIT internally allowed us to practice what we preach. By eliminating permanent access to our own clouds and databases, we've neutralized the risk of standing privileges, ensuring our own 'keys to the kingdom' are never left exposed.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

The problem with permissions is a lot of times, the gaps are left open due to oversights from inside the organization itself. With Cloudanix's CIEM, we get a complete view of user permissions and access. This enables us to update the permissions, reducing the attack surface.

Nilesh Pethani
Nilesh Pethani
Application Architect, iMocha

In the world of Fintech, trust is our currency. Cloudanix provided the frictionless visibility we needed to secure our EKS workloads across AWS, ensuring we stay audit-ready for SOC2 and GDPR without slowing down our engineering velocity.

Amol Naik
Amol Naik
Head of Security & Infrastructure, HugoHub

Cloudanix delivered value within 5 minutes of onboarding. Continuous monitoring, timely detection, and excellent documentation helped us attain a great cloud security posture.

Divyanshu Shukla
Senior DevSecOps, Meesho

Technology strategies and business strategies are in a state of constant change which includes centralization and decentralization of responsibilities. Regardless of strategic shift, we still have intellectual property to protect. Cloudanix are critical partners for us in our public cloud security posture across our three cloud providers.

Jerry Locke
Jerry Locke
Senior Director Global Solutions Engineering, Eversana

Cloudanix has been amazing. They opened up a common Slack channel with us — and it feels like we are talking to our own team and getting things done with Cloud security. The support team is always available, friendly, helpful, and ready to go out of their way.

Satish Mohan
Satish Mohan
CTO, Airgap Networks

Beyond just access management, Cloudanix CSPM has given us a unified view of our AWS environment. The real-time alerting and anomaly detection allow us to prevent any untoward activity before it happens, which is critical for a marketplace connecting 50+ financial institutions.

Okesh Badhiye
Okesh Badhiye
Head of Technical Engineering, Finfinity

For a Fintech company, data is our most valuable — and most sensitive — asset. Cloudanix DAM hasn't just improved our visibility; it has given us control. The ability to mask data and prevent unauthorized queries in real-time is a game-changer for our compliance and customer trust.

Jiten Gala
Jiten Gala
President Engineering and Product, Kapittx

Our clients, especially in the Middle East financial sector, demand absolute accountability. Cloudanix JIT Cloud has been a competitive differentiator for us, allowing us to provide secure, governed access to customer accounts that meet their strictest audit and compliance requirements.

Girish Manghnani
Girish Manghnani
Managing Partner, Tech Inspira

Cloudanix is always on my team's lips because of its exceptional support. Be it a small or big query, Cloudanix has gone above and beyond to resolve them. This one's a keeper for us.

Sujit Karpe
Sujit Karpe
CTO, iMocha

For a long-lasting partnership, great support goes a long way. Cloudanix has delivered exceptional support whenever required. Their edge is their team is always ready to go beyond to solve any issues that we have. This speaks volumes about the culture at Cloudanix.

Akash Maheshwari
Akash Maheshwari
Co-founder, MoveInSync

Beyond the technology, Cloudanix feels like an extension of our own team. Their willingness to stand up a dedicated Middle East tenant for us and provide exceptional support at a sensible price makes them a long-term partner for Hugosave.

Surya Tamada
Surya Tamada
CTO, HugoHub

The real-time notifications that Cloudanix provides are a real lifesaver. Their adaptive notifications ensure that my team stays productive and doesn't get interrupted all the time.

Digvijay Singh
Staff Security Engineer, Meesho

The whole point in technological evolution is to help improve the world we live in. We must protect that and to do so requires an effective and efficient security strategy. The Cloudanix team helped make our public cloud security posture management strategy a reality. The symbiotic relationship we have allows for a continuous feedback loop which is how business should operate.

Larry Wheat
Larry Wheat
Staff Solutions Engineer, Eversana

Ready to see your graph?

Connect a cloud account in under 30 minutes. See every finding rooted in identity, asset, and blast radius — with a fix path attached.

Book a Demo