NIST

acronym

securitygovernance & riskcryptography

Stands for: National Institute of Standards and Technology

The US standards agency whose cryptographic and security publications function as global engineering baselines.

NIST runs the FIPS standards and the SP 800 series this site cites constantly - SP 800-52r2 for TLS configuration, SP 800-38A for cipher modes - and ran the open competitions that selected AES and SHA-3. Its post-quantum standardization produced ML-KEM and ML-DSA, and its Cybersecurity Framework (CSF) anchors countless compliance programs. Not a regulator: adoption outside US federal systems is voluntary, which makes its influence the more remarkable.

NIST publishes the standards a great deal of security work is measured against: the cryptographic algorithms in FIPS, the control catalogue in SP 800-53, and the Cybersecurity Framework that many organizations use as their programme's skeleton. It is a United States agency, and its output is used internationally because the work is public, technically serious and free.

The distinction worth holding is between what NIST standardizes and what it recommends. A FIPS-approved algorithm is a requirement for US federal systems and a strong signal everywhere else; a special publication is guidance, and the good ones say plainly what evidence supports them. That matters because NIST reversed its own long-standing password rotation advice on evidence, which is a better argument for reading the reasoning than for treating any publication as settled.

Also known as: nist, sp 800, fips

All glossary entries