NIST SP 1339 Explained: The OT Backup Quick Start Guide
An independent explainer on the NIST guidance for operational technology data integrity, backup and recovery, what SP 1339 asks organisations to do, and how it relates to SP 800-82 Rev. 3, the NCCoE SP 1800-series and CSF 2.0.

- Written by
- Mark Fermor, Co-Founder, Firevault
- Technical review
- Firevault architecture team
- First published
- 25 November 2025
- Last reviewed
- 27 August 2026
- Review cycle
- At least annually, or following material changes to NIST, NCSC or ISO guidance.
How we built this explainer: This explainer is based on the published text of NIST SP 1339, cross-referenced against NIST SP 800-82 Rev. 3, the NCCoE SP 1800-series data integrity guides and NIST CSF 2.0. Where a specific claim about SP 1339's contents could not be verified against the published document, it has been replaced or supported with a citation to one of these underlying sources instead.
In June 2026 the National Institute of Standards and Technology, through its National Cybersecurity Center of Excellence, published NIST Special Publication 1339, the Operational Technology Backup Quick Start Guide. The document itself is short, but it arrives at a point where destructive attacks and ransomware against OT estates are treated as a board-level risk in most regulated sectors.
This explainer sets out what SP 1339 covers, how it relates to the more detailed NIST guidance it draws on, and how the recovery data, integrity, testing and objective-setting concepts it describes map to the NIST Cybersecurity Framework 2.0 and, for UK readers, to the NCSC Cyber Assessment Framework.
What is NIST SP 1339?
SP 1339 is a two-page quick start guide describing how organisations should manage backups for operational technology and industrial control systems. Its stated purpose is to give asset owners, plant engineers and CISOs a practical starting point for a backup programme that supports recovery from both reliability incidents and cyber incidents.
The guide is deliberately concise. It does not attempt to replace detailed architecture guidance; instead it points readers toward the fuller treatments already published by NIST, and focuses on the small number of decisions that most affect whether a backup is actually usable when it is needed.
How SP 1339 fits with SP 800-82 Rev. 3 and the SP 1800-series
SP 1339 explicitly builds on NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security, which covers backup and resilience as part of a much broader OT security architecture, and on the NCCoE SP 1800-series data integrity practice guides, which set out reference architectures for detecting, protecting against and recovering from data integrity incidents such as ransomware.
Read together, these documents position OT backup and recovery as a specific application of the wider data integrity concepts NIST has published across several programmes, rather than a separate topic.
What OT recovery data is
Recovery data is the complete set of material needed to rebuild an OT environment, not simply a database export. NIST guidance treats it as covering both digital assets and the supporting documentation an engineer would need during a rebuild.
- Controller logic and configuration files
- Firmware images and licence keys
- HMI graphics and historian configurations
- Engineering documentation: I/O lists, wiring and network diagrams
- Safety requirement specifications and cause and effect matrices
- Operating system and virtual machine images for supporting servers
Engineering documentation is easy to overlook because it is not always stored alongside digital backups. Keeping printed and electronic copies available, and accessible during an incident, materially speeds up verification and troubleshooting during a rebuild.
Integrity verification
A backup that has been altered, whether by corruption, misconfiguration or a deliberate attack, is not a usable recovery asset even if it exists. NIST guidance describes integrity verification through cryptographic hashing, so a restored file can be checked against a known value, combined with write-once or immutable storage that prevents the backup from being modified after it is written.
- Backup reachable and writable from production network
- No hash recorded at time of backup
- Retention can be shortened by an administrator
- Backup stored write-once or fully disconnected
- Cryptographic hash recorded and checked on restore
- Retention enforced independently of production credentials
Recovery objectives
NIST guidance expects recovery objectives to be set per asset, based on mission criticality, rather than applying one blanket policy across an entire estate. Two figures matter most.
- Recovery time objective (RTO)
- The maximum acceptable time to restore a given asset to service after an incident.
- Recovery point objective (RPO)
- The maximum acceptable amount of data or configuration change lost since the last good backup.
A safety-critical PLC and a reporting historian will usually carry very different RTO and RPO figures. Setting objectives per asset, rather than uniformly, is what allows backup frequency and storage tiering decisions to be made deliberately instead of by default.
Testing and restoration
A backup that has never been restored is unverified. NIST guidance calls for recurring restore tests, ideally on non-production systems, to confirm both that the backup restores successfully and that the restored system is functionally correct, not merely present.
Hot, warm and cold backups
Different assets warrant different recovery tiers. Hot backups support near-immediate failover through continuous replication, at the cost of the replicated copy carrying the same exposure as the live system. Warm backups are updated on a schedule and allow a fairly quick recovery. Cold backups are stored offline or held as physical spares, and need a full rebuild before service resumes, but they carry the least ongoing exposure to whatever compromised the live system.
Hot
- Continuous or near-real-time replication
- Replica shares network exposure with the live system
Warm
- Updated on a regular schedule
- Some data loss possible between updates
Cold
- Stored offline or as a physical spare
- Full rebuild required, but least exposed to a live compromise
Mapping to NIST CSF 2.0 Recover
NIST Cybersecurity Framework 2.0 organises outcomes into six functions. OT backup practice principally supports Recover, alongside supporting roles in Identify and Protect.
| CSF 2.0 function | Relevant category | OT backup activity |
|---|---|---|
| Identify | Asset Management | Maintaining a current inventory of OT assets and their criticality |
| Protect | Data Security | Protecting backup media from unauthorised access, modification or destruction |
| Recover | Recovery Plan Execution | Executing tested restore procedures against defined recovery objectives |
| Recover | Recovery Communications | Recording and reporting the outcome of recovery actions |
Mapping to the NCSC CAF
For UK readers, the same OT backup outcomes can be mapped to relevant principles within the NCSC Cyber Assessment Framework, particularly those covering resilient networks and systems, and response and recovery capability.
Mapped, not certified: This is a mapping of outcomes for planning purposes. The CAF is an assessment framework applied by NCSC and sector regulators against a specific organisation and system, not a certificate that a backup product or practice can hold. No claim of CAF certification should be inferred from an outcome mapping.
What SP 1339 does not do
SP 1339 does not mandate specific products, does not create a compliance regime, and does not replace the need for organisation-specific risk assessment. It is guidance, not regulation, though it is increasingly referenced in procurement standards, insurance questionnaires and audit expectations as a practical baseline for what a defensible OT backup programme looks like.
How Firevault applies these principles
Firevault's Offline Secure Storage® is designed around the same integrity and protection expectations SP 1339 describes. The gold copy of OT recovery data is held with no live network interface while offline, removing the network path that a ransomware attack or a compromised management credential would otherwise use to reach it.
Every connection, disconnection and access to that copy is logged on a separate management plane, with identity, timestamp and reason recorded, giving asset owners the kind of evidence that supports the restore testing and recovery communications outcomes described above. Restores are carried out through scheduled, identity-verified connection windows, so the copy remains available for exercises and real incidents without being permanently reachable from production.
SP 1339 is a checklist, not new theory
NIST SP 1339 does not introduce a new backup methodology for operational technology. It distils backup and recovery expectations that already exist in SP 800-82 Rev. 3, the NCCoE SP 1800-series data integrity guides and CSF 2.0 into a short, practical resource that asset owners and plant engineers can use directly.
The consistent theme across all of these sources is that a backup is only as good as its last verified restore, and that OT recovery data needs to be protected from the same threats it is meant to help an organisation recover from. A copy that remains reachable from the network during an incident has not actually solved that problem.
Frequently Asked Questions
Straight answers on how Offline Secure Storage® behaves in practice.
Sources and further reading
- NIST SP 1339, OT Backup Quick Start Guide
The primary source for this explainer, published by the NCCoE in June 2026.
- NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security
The detailed OT security guidance that SP 1339 draws its backup and recovery expectations from.
- NIST SP 1800-11, Data Integrity: Recovering from Ransomware and Other Destructive Events
An NCCoE practice guide on recovery architectures for data integrity incidents, part of the SP 1800 series referenced in SP 1339.
- NIST Cybersecurity Framework (CSF) 2.0
The framework functions, including Recover, that SP 1339's backup guidance maps to.
- NCSC, Cyber Assessment Framework (CAF)
The UK outcomes-based framework used here to show how OT backup practice maps to CAF, without implying certification.
Related Firevault guides
