Date Published: April 14, 2026
Comments Due: May 14, 2026 (public comment period is CLOSED)
Email Questions to:
[email protected]
According to the U.S. Small Business Administration Office of Advocacy, there are 34.8 million small businesses in the United States. Of those, 81.9% have no paid employees other than the owner or owners—termed “non-employer firms.” These include sole proprietors, freelancers, single-member limited liability companies (LLCs), independent contractors, gig economy workers, and others. This publication helps small firms with no employees and with minimal IT complexity use the NIST Cybersecurity Framework 2.0 to manage their cybersecurity risks. To make this information applicable to a broader audience, cybersecurity risk management considerations are included for businesses as they grow and hire employees—acknowledging that some non-employer firms may never hire additional employees. Many small businesses rely upon consultants, who are also a key audience for this report. While the guide is developed for a U.S. audience, it is recognized that many small businesses engage in international commerce or collaborations, and this document can be adapted to support the cybersecurity risk management of those efforts.
Cybersecurity White Paper (CSWP) 50 was initially published in 2009 as NIST IR 7621, Small Business Information Security: The Fundamentals. The publication underwent an initial revision in 2016 (NIST IR 7621, Rev.1). A pre-draft call for comments was issued in 2024, followed by an initial public draft and comment period on NIST IR 7621, Rev. 2. During the revision process, the publication was converted to CSWP 50, Small Business Cybersecurity: Non-Employer Firms.
Key Updates within CSWP 50:
None selected
Publication:
https://doi.org/10.6028/NIST.CSWP.50.ipd
Download URL
Supplemental Material:
Comment template (xlsx)
Small Business Cybersecurity Corner
Document History:
03/18/24: IR 7621 Rev. 2 (Draft)
05/01/25: IR 7621 Rev. 2 (Draft)
04/14/26: CSWP 50 (Draft)