1. Home
  2. |Insights
  3. |NIST Updates Cybersecurity Framework (CSF)

NIST Updates Cybersecurity Framework (CSF)

Client Alert | 1 min read | 01.18.17

Last week, the National Institute of Standards and Technology (NIST) issued a draft update to the Framework for Improving Critical Infrastructure, also known as the “Cybersecurity Framework” or CSF. This Version 1.1 update includes (i) a new section addressing measurement and demonstration of cybersecurity; (ii) considerations regarding Cyber Supply Chain Risk Management (SCRM) added throughout the CSF; and (iii) clarification of existing key terms and concepts.

The proposed additions regarding cybersecurity measurement are intended to “get the conversation started” and help companies map their business outcomes to their cyber risk management practices. The update aims to enable organizations to produce meaningful cyber risk information to use in enterprise-level risk management decisions, which can also be conveyed to dependents, partners and customers as applicable. Supply chain-focused updates are intended to bolster existing sections of the CSF as well as develop a common vocabulary for cyber supply chain risk management across industries and project types.

Version 1.1 of the CSF is intended to be “fully compatible” with the existing Version 1.0. Comments on Version 1.1 must be submitted by April 10, 2017, and NIST intends to publish a final Framework Version 1.1 in the fall of 2017.

Contacts

Insights

Client Alert | 4 min read | 06.25.26

Twin Executive Orders Seek to Spur Quantum Leap in Technology and Cybersecurity

On June 22, 2026, President Trump signed two executive orders, “Securing the Nation Against Advanced Cryptographic Attacks” (Quantum Security EO) and “Ushering in the Next Frontier of Quantum Innovation” (Quantum Innovation EO), marking the most significant federal action on quantum technology since the Quantum Computing Cybersecurity Preparedness Act of 2022, which directed agencies to harden their information systems against quantum-enabled hacking. The orders seek to speed the development of quantum computers, which are advanced processors that can calculate multiple possibilities simultaneously and thus solve problems exponentially faster than traditional computers. At the same time, the orders look to protect against the danger that quantum technology can “break” traditional encryption by easily decoding it. Of particular note for government contractors, the Quantum Security EO directs agencies to update federal acquisition regulations to require contractors by 2031 to adopt information processing standards that resist quantum-enabled codebreaking....