Knowledge Vault
ExplainerOT and ICS security

NIST SP 1339 Explained: The OT Backup Quick Start Guide

An independent explainer on the NIST guidance for operational technology data integrity, backup and recovery, what SP 1339 asks organisations to do, and how it relates to SP 800-82 Rev. 3, the NCCoE SP 1800-series and CSF 2.0.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
25 November 202515 min read
Share
Backup infrastructure and recovery documentation for an operational technology environment
SP 1339 distils backup and recovery practice from existing NIST guidance into a short, practical checklist for OT asset owners.
Written by
Mark Fermor, Co-Founder, Firevault
Technical review
Firevault architecture team
First published
25 November 2025
Last reviewed
27 August 2026
Review cycle
At least annually, or following material changes to NIST, NCSC or ISO guidance.

How we built this explainer: This explainer is based on the published text of NIST SP 1339, cross-referenced against NIST SP 800-82 Rev. 3, the NCCoE SP 1800-series data integrity guides and NIST CSF 2.0. Where a specific claim about SP 1339's contents could not be verified against the published document, it has been replaced or supported with a citation to one of these underlying sources instead.

In June 2026 the National Institute of Standards and Technology, through its National Cybersecurity Center of Excellence, published NIST Special Publication 1339, the Operational Technology Backup Quick Start Guide. The document itself is short, but it arrives at a point where destructive attacks and ransomware against OT estates are treated as a board-level risk in most regulated sectors.

This explainer sets out what SP 1339 covers, how it relates to the more detailed NIST guidance it draws on, and how the recovery data, integrity, testing and objective-setting concepts it describes map to the NIST Cybersecurity Framework 2.0 and, for UK readers, to the NCSC Cyber Assessment Framework.

What is NIST SP 1339?

SP 1339 is a two-page quick start guide describing how organisations should manage backups for operational technology and industrial control systems. Its stated purpose is to give asset owners, plant engineers and CISOs a practical starting point for a backup programme that supports recovery from both reliability incidents and cyber incidents.

The guide is deliberately concise. It does not attempt to replace detailed architecture guidance; instead it points readers toward the fuller treatments already published by NIST, and focuses on the small number of decisions that most affect whether a backup is actually usable when it is needed.

How SP 1339 fits with SP 800-82 Rev. 3 and the SP 1800-series

SP 1339 explicitly builds on NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security, which covers backup and resilience as part of a much broader OT security architecture, and on the NCCoE SP 1800-series data integrity practice guides, which set out reference architectures for detecting, protecting against and recovering from data integrity incidents such as ransomware.

DETAILED
SP 800-82 Rev. 3
Full OT security guidance, including backup and resilience within a broader architecture
PRACTICE GUIDES
NCCoE SP 1800-series
Reference architectures for data integrity, ransomware recovery and event logging
QUICK START
SP 1339
A short, practical OT backup checklist drawn from the guidance above
SP 1339 sits above more detailed NIST guidance, distilling it into a short, practical checklist.

Read together, these documents position OT backup and recovery as a specific application of the wider data integrity concepts NIST has published across several programmes, rather than a separate topic.

What OT recovery data is

Recovery data is the complete set of material needed to rebuild an OT environment, not simply a database export. NIST guidance treats it as covering both digital assets and the supporting documentation an engineer would need during a rebuild.

  • Controller logic and configuration files
  • Firmware images and licence keys
  • HMI graphics and historian configurations
  • Engineering documentation: I/O lists, wiring and network diagrams
  • Safety requirement specifications and cause and effect matrices
  • Operating system and virtual machine images for supporting servers

Engineering documentation is easy to overlook because it is not always stored alongside digital backups. Keeping printed and electronic copies available, and accessible during an incident, materially speeds up verification and troubleshooting during a rebuild.

Integrity verification

A backup that has been altered, whether by corruption, misconfiguration or a deliberate attack, is not a usable recovery asset even if it exists. NIST guidance describes integrity verification through cryptographic hashing, so a restored file can be checked against a known value, combined with write-once or immutable storage that prevents the backup from being modified after it is written.

Backup exposed to change
NetworkData
  • Backup reachable and writable from production network
  • No hash recorded at time of backup
  • Retention can be shortened by an administrator
Backup integrity protected
NetworkData
  • Backup stored write-once or fully disconnected
  • Cryptographic hash recorded and checked on restore
  • Retention enforced independently of production credentials
Integrity depends on the backup being protected from change, not only on it existing.

Recovery objectives

NIST guidance expects recovery objectives to be set per asset, based on mission criticality, rather than applying one blanket policy across an entire estate. Two figures matter most.

Recovery time objective (RTO)
The maximum acceptable time to restore a given asset to service after an incident.
Recovery point objective (RPO)
The maximum acceptable amount of data or configuration change lost since the last good backup.

A safety-critical PLC and a reporting historian will usually carry very different RTO and RPO figures. Setting objectives per asset, rather than uniformly, is what allows backup frequency and storage tiering decisions to be made deliberately instead of by default.

Testing and restoration

A backup that has never been restored is unverified. NIST guidance calls for recurring restore tests, ideally on non-production systems, to confirm both that the backup restores successfully and that the restored system is functionally correct, not merely present.

Plan
Select an asset and a non-production target
Frequency driven by mission criticality
Restore
Restore from the backup to the test target
Verify against the recorded hash
Validate
Confirm functional correctness
Not just that the file matches, but that the system works
Record
Capture lessons learned
Feed back into backup frequency, media and procedure
A restore test validates the backup, the procedure and the response plan together.

Hot, warm and cold backups

Different assets warrant different recovery tiers. Hot backups support near-immediate failover through continuous replication, at the cost of the replicated copy carrying the same exposure as the live system. Warm backups are updated on a schedule and allow a fairly quick recovery. Cold backups are stored offline or held as physical spares, and need a full rebuild before service resumes, but they carry the least ongoing exposure to whatever compromised the live system.

Fastest recovery

Hot

  • Continuous or near-real-time replication
  • Replica shares network exposure with the live system
Balanced

Warm

  • Updated on a regular schedule
  • Some data loss possible between updates
Lowest exposure

Cold

  • Stored offline or as a physical spare
  • Full rebuild required, but least exposed to a live compromise
Recovery tiers trade recovery speed against exposure to whatever compromised the live environment.

Mapping to NIST CSF 2.0 Recover

NIST Cybersecurity Framework 2.0 organises outcomes into six functions. OT backup practice principally supports Recover, alongside supporting roles in Identify and Protect.

CSF 2.0 function Relevant category OT backup activity
Identify Asset Management Maintaining a current inventory of OT assets and their criticality
Protect Data Security Protecting backup media from unauthorised access, modification or destruction
Recover Recovery Plan Execution Executing tested restore procedures against defined recovery objectives
Recover Recovery Communications Recording and reporting the outcome of recovery actions
How OT backup activities map to relevant CSF 2.0 functions and categories.

Mapping to the NCSC CAF

For UK readers, the same OT backup outcomes can be mapped to relevant principles within the NCSC Cyber Assessment Framework, particularly those covering resilient networks and systems, and response and recovery capability.

Mapped, not certified: This is a mapping of outcomes for planning purposes. The CAF is an assessment framework applied by NCSC and sector regulators against a specific organisation and system, not a certificate that a backup product or practice can hold. No claim of CAF certification should be inferred from an outcome mapping.

What SP 1339 does not do

SP 1339 does not mandate specific products, does not create a compliance regime, and does not replace the need for organisation-specific risk assessment. It is guidance, not regulation, though it is increasingly referenced in procurement standards, insurance questionnaires and audit expectations as a practical baseline for what a defensible OT backup programme looks like.

How Firevault applies these principles

Firevault's Offline Secure Storage® is designed around the same integrity and protection expectations SP 1339 describes. The gold copy of OT recovery data is held with no live network interface while offline, removing the network path that a ransomware attack or a compromised management credential would otherwise use to reach it.

Every connection, disconnection and access to that copy is logged on a separate management plane, with identity, timestamp and reason recorded, giving asset owners the kind of evidence that supports the restore testing and recovery communications outcomes described above. Restores are carried out through scheduled, identity-verified connection windows, so the copy remains available for exercises and real incidents without being permanently reachable from production.

Key takeaway

SP 1339 is a checklist, not new theory

NIST SP 1339 does not introduce a new backup methodology for operational technology. It distils backup and recovery expectations that already exist in SP 800-82 Rev. 3, the NCCoE SP 1800-series data integrity guides and CSF 2.0 into a short, practical resource that asset owners and plant engineers can use directly.

The consistent theme across all of these sources is that a backup is only as good as its last verified restore, and that OT recovery data needs to be protected from the same threats it is meant to help an organisation recover from. A copy that remains reachable from the network during an incident has not actually solved that problem.

Questions

Frequently Asked Questions

Straight answers on how Offline Secure Storage® behaves in practice.

Sources and further reading

Related Firevault guides

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

Share this explainer
Share