---
title: "NIST SP 1339: The OT Backup Quick Start Guide Explained"
description: "An independent explainer on NIST SP 1339, the OT Backup Quick Start Guide, and how it maps to SP 800-82 Rev. 3, the NCCoE SP 1800-series and CSF 2.0. Covers…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/nist-sp-1339-ot-backup-guide#webpage",
      "url": "https://fire-vault.com/learn/nist-sp-1339-ot-backup-guide",
      "name": "NIST SP 1339: The OT Backup Quick Start Guide Explained",
      "description": "An independent explainer on NIST SP 1339, the OT Backup Quick Start Guide, and how it maps to SP 800-82 Rev. 3, the NCCoE SP 1800-series and CSF 2.0. Covers…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-learn.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/nist-sp-1339-ot-backup-guide#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/nist-sp-1339-ot-backup-guide#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Home",
          "item": "https://fire-vault.com/"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "NIST SP 1339 Explained: The OT Backup Quick Start Guide",
          "item": "https://fire-vault.com/learn/nist-sp-1339-ot-backup-guide"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "NIST SP 1339: The OT Backup Quick Start Guide Explained",
      "description": "An independent explainer on NIST SP 1339, the OT Backup Quick Start Guide, and how it maps to SP 800-82 Rev. 3, the NCCoE SP 1800-series and CSF 2.0. Covers…",
      "image": "https://fire-vault.com/images/og/og-base-learn.jpg",
      "author": {
        "@type": "Organization",
        "name": "Firevault"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png"
        }
      },
      "datePublished": "2025-11-25",
      "dateModified": "2026-08-27",
      "mainEntityOfPage": "https://fire-vault.com/learn/nist-sp-1339-ot-backup-guide"
    },
    {
      "@context": "https://schema.org",
      "@type": "TechArticle",
      "@id": "https://fire-vault.com/learn/nist-sp-1339-ot-backup-guide#article",
      "headline": "NIST SP 1339 Explained: The OT Backup Quick Start Guide",
      "description": "An independent explainer on NIST SP 1339, the OT Backup Quick Start Guide, and how it maps to SP 800-82 Rev. 3, the NCCoE SP 1800-series and CSF 2.0. Covers recovery data, integrity verification, recovery objectives, testing and NCSC CAF mapping.",
      "about": [
        {
          "@type": "Thing",
          "name": "NIST SP 1339"
        },
        {
          "@type": "Thing",
          "name": "NIST SP 800-82 Rev. 3"
        },
        {
          "@type": "Thing",
          "name": "NIST CSF 2.0"
        },
        {
          "@type": "Thing",
          "name": "OT data integrity"
        },
        {
          "@type": "Thing",
          "name": "NCSC CAF"
        }
      ],
      "keywords": "NIST SP 1339, OT Backup Quick Start Guide, NIST SP 800-82 Rev 3, OT data integrity, OT backup and recovery, NIST CSF 2.0 recover, NCSC CAF, NCCoE SP 1800",
      "articleSection": "OT and ICS security",
      "inLanguage": "en-GB",
      "isAccessibleForFree": true,
      "wordCount": 2300,
      "image": [
        "https://fire-vault.com/assets/explainer-nist-sp-1339-ot-backup-BSWRcoFZ.jpg"
      ],
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "url": "https://fire-vault.com/about",
        "jobTitle": "Director and Co-Founder, Firevault"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Firevault",
        "url": "https://fire-vault.com"
      },
      "datePublished": "2025-11-25",
      "dateModified": "2026-08-27",
      "url": "https://fire-vault.com/learn/nist-sp-1339-ot-backup-guide",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/nist-sp-1339-ot-backup-guide"
      },
      "citation": [
        {
          "@type": "CreativeWork",
          "name": "NIST SP 1339, OT Backup Quick Start Guide",
          "url": "https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1339.pdf"
        },
        {
          "@type": "CreativeWork",
          "name": "NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security",
          "url": "https://csrc.nist.gov/pubs/sp/800/82/r3/final"
        },
        {
          "@type": "CreativeWork",
          "name": "NIST SP 1800-11, Data Integrity: Recovering from Ransomware and Other Destructive Events",
          "url": "https://www.nccoe.nist.gov/projects/data-integrity-recovering-ransomware-and-other-destructive-events"
        },
        {
          "@type": "CreativeWork",
          "name": "NIST Cybersecurity Framework (CSF) 2.0",
          "url": "https://doi.org/10.6028/NIST.CSWP.29"
        },
        {
          "@type": "CreativeWork",
          "name": "NCSC, Cyber Assessment Framework (CAF)",
          "url": "https://www.ncsc.gov.uk/collection/cyber-assessment-framework"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is NIST SP 1339?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "NIST SP 1339 is the Operational Technology Backup Quick Start Guide, published by the National Cybersecurity Center of Excellence in June 2026. It is a short, two-page resource that gives asset owners a practical starting point for managing OT backups and recovery, built on more detailed NIST guidance published previously."
          }
        },
        {
          "@type": "Question",
          "name": "Is NIST SP 1339 mandatory?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. NIST Special Publications are guidance rather than regulation in most sectors. They are, however, widely used to shape audit expectations, insurance requirements and procurement standards, so SP 1339 is best treated as a practical baseline rather than an optional reference."
          }
        },
        {
          "@type": "Question",
          "name": "How does SP 1339 relate to NIST SP 800-82 Rev. 3?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "SP 800-82 Rev. 3 is NIST's detailed guide to OT security and includes backup, recovery and resilience considerations within a much broader scope. SP 1339 distils the backup-specific parts of that guidance, along with material from the NCCoE SP 1800-series, into a short checklist that plant engineers and asset owners can act on directly."
          }
        },
        {
          "@type": "Question",
          "name": "What is OT recovery data?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "OT recovery data is the set of files, configurations and documentation needed to rebuild an operational technology environment after an incident. It typically includes controller logic and configuration files, firmware, HMI graphics, licence keys, engineering documentation such as I/O lists and network diagrams, and virtual machine or operating system images for supporting servers."
          }
        },
        {
          "@type": "Question",
          "name": "How is OT backup integrity verified?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Integrity is typically verified using cryptographic hashing, so that a restored file can be checked against a known-good value, combined with write-once or immutable storage that prevents a backup from being altered after it is created. NIST guidance also expects periodic restore testing to confirm that the backup restores to a working state, not only that the file itself is unchanged."
          }
        },
        {
          "@type": "Question",
          "name": "What are recovery objectives in OT backup planning?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Recovery objectives define how quickly a system needs to be restored (recovery time objective) and how much data loss is tolerable, expressed as the maximum acceptable gap since the last good backup (recovery point objective). OT recovery objectives are set per asset, based on that asset's mission criticality and its role in the physical process."
          }
        },
        {
          "@type": "Question",
          "name": "How often should OT backups be tested?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "NIST guidance calls for recurring restore tests on non-production systems, with frequency driven by how critical the asset is and how often its configuration changes. The purpose of testing is to validate that the backup is reliable, to practise the restoration procedure itself, and to capture lessons that improve both the backup and the response plan."
          }
        },
        {
          "@type": "Question",
          "name": "How does OT backup guidance map to the NIST Cybersecurity Framework 2.0?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "OT backup practice principally supports the Recover function of CSF 2.0, including recovery plan execution and recovery communications, alongside Identify for asset inventory and Protect for data security controls. SP 1339 is explicitly built to align with these existing CSF 2.0 categories rather than introduce new ones."
          }
        },
        {
          "@type": "Question",
          "name": "Does OT backup guidance map to the NCSC Cyber Assessment Framework?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "The outcomes described in NIST OT backup guidance, such as maintaining backups, protecting them from unauthorised change, and testing restoration, align with several outcomes in the NCSC Cyber Assessment Framework, particularly those concerned with resilient networks, systems and response and recovery capability. This is a mapping of outcomes for planning purposes; it is not a certification against the CAF, which is an assessment framework applied by NCSC and sector regulators, not a certificate an organisation can hold."
          }
        },
        {
          "@type": "Question",
          "name": "Does OT backup guidance require a physical air gap?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "NIST OT guidance asks organisations to protect backup media from unauthorised access, modification and destruction, and describes mechanisms such as hashing, encryption and write-once media. It does not mandate a specific technology, but a physical air gap, meaning no live network interface, is one of the strongest ways to meet that protection requirement because it removes the network path an attacker would otherwise use."
          }
        },
        {
          "@type": "Question",
          "name": "What is the difference between hot, warm and cold OT backups?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "A hot backup supports near-immediate failover through continuous or near-real-time replication. A warm backup is updated on a regular schedule and allows a relatively quick recovery. A cold backup is stored offline or as a physical spare and requires a full rebuild before service resumes. NIST guidance expects organisations to choose an appropriate mix across these tiers for each OT asset, based on its recovery objectives."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

[Knowledge Vault](/learn/knowledge)

Explainer OT and ICS security 

# NIST SP 1339 Explained: The OT Backup Quick Start Guide

An independent explainer on the NIST guidance for operational technology data integrity, backup and recovery, what SP 1339 asks organisations to do, and how it relates to SP 800-82 Rev. 3, the NCCoE SP 1800-series and CSF 2.0.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

25 November 2025 15 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fnist-sp-1339-ot-backup-guide)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fnist-sp-1339-ot-backup-guide&text=NIST%20SP%201339%20Explained%3A%20The%20OT%20Backup%20Quick%20Start%20Guide%0A%0AAn%20independent%20explainer%20on%20the%20NIST%20guidance%20for%20operational%20technology%20data%20integrity%2C%20backup%20and%20recovery%2C%20what%20SP%201339%20asks%20organisations%20to%20do%2C%20and%20how%20it%20relates%20to%20SP%20800-82%20Rev.%203%2C%20the%20NCCoE%20SP%201800-series%20and%20CSF%202.0.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fnist-sp-1339-ot-backup-guide)[](mailto:?subject=NIST%20SP%201339%20Explained%3A%20The%20OT%20Backup%20Quick%20Start%20Guide&body=An%20independent%20explainer%20on%20the%20NIST%20guidance%20for%20operational%20technology%20data%20integrity%2C%20backup%20and%20recovery%2C%20what%20SP%201339%20asks%20organisations%20to%20do%2C%20and%20how%20it%20relates%20to%20SP%20800-82%20Rev.%203%2C%20the%20NCCoE%20SP%201800-series%20and%20CSF%202.0.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fnist-sp-1339-ot-backup-guide)

![Backup infrastructure and recovery documentation for an operational technology environment](/assets/explainer-nist-sp-1339-ot-backup-BSWRcoFZ.jpg)

SP 1339 distils backup and recovery practice from existing NIST guidance into a short, practical checklist for OT asset owners.

Written by

Mark Fermor, Co-Founder, Firevault

Technical review

Firevault architecture team

First published

25 November 2025

Last reviewed

27 August 2026

Review cycle

At least annually, or following material changes to NIST, NCSC or ISO guidance.

How we built this explainer:  This explainer is based on the published text of NIST SP 1339, cross-referenced against NIST SP 800-82 Rev. 3, the NCCoE SP 1800-series data integrity guides and NIST CSF 2.0. Where a specific claim about SP 1339's contents could not be verified against the published document, it has been replaced or supported with a citation to one of these underlying sources instead.

**On this page**[What is NIST SP 1339?](#what-is)[How SP 1339 fits with SP 800-82 Rev. 3 and the SP 1800-series](#standing)[What OT recovery data is](#recovery-data)[Integrity verification](#integrity)[Recovery objectives](#objectives)[Testing and restoration](#testing)[Hot, warm and cold backups](#tiers)[Mapping to NIST CSF 2.0 Recover](#csf-mapping)[Mapping to the NCSC CAF](#caf-mapping)[What SP 1339 does not do](#limits)[How Firevault applies these principles](#firevault)

On this page

1.  [What is NIST SP 1339?](#what-is)
2.  [How SP 1339 fits with SP 800-82 Rev. 3 and the SP 1800-series](#standing)
3.  [What OT recovery data is](#recovery-data)
4.  [Integrity verification](#integrity)
5.  [Recovery objectives](#objectives)
6.  [Testing and restoration](#testing)
7.  [Hot, warm and cold backups](#tiers)
8.  [Mapping to NIST CSF 2.0 Recover](#csf-mapping)
9.  [Mapping to the NCSC CAF](#caf-mapping)
10.  [What SP 1339 does not do](#limits)
11.  [How Firevault applies these principles](#firevault)

In June 2026 the National Institute of Standards and Technology, through its National Cybersecurity Center of Excellence, published [NIST Special Publication 1339, the Operational Technology Backup Quick Start Guide](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1339.pdf). The document itself is short, but it arrives at a point where destructive attacks and ransomware against OT estates are treated as a board-level risk in most regulated sectors.

This explainer sets out what SP 1339 covers, how it relates to the more detailed NIST guidance it draws on, and how the recovery data, integrity, testing and objective-setting concepts it describes map to the NIST Cybersecurity Framework 2.0 and, for UK readers, to the NCSC Cyber Assessment Framework.

## What is NIST SP 1339?

SP 1339 is a two-page quick start guide describing how organisations should manage backups for operational technology and industrial control systems. Its stated purpose is to give asset owners, plant engineers and CISOs a practical starting point for a backup programme that supports recovery from both reliability incidents and cyber incidents.

The guide is deliberately concise. It does not attempt to replace detailed architecture guidance; instead it points readers toward the fuller treatments already published by NIST, and focuses on the small number of decisions that most affect whether a backup is actually usable when it is needed.

## How SP 1339 fits with SP 800-82 Rev. 3 and the SP 1800-series

SP 1339 explicitly builds on [NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security](https://csrc.nist.gov/pubs/sp/800/82/r3/final), which covers backup and resilience as part of a much broader OT security architecture, and on the [NCCoE SP 1800-series data integrity practice guides](https://www.nccoe.nist.gov/projects/data-integrity-recovering-ransomware-and-other-destructive-events), which set out reference architectures for detecting, protecting against and recovering from data integrity incidents such as ransomware.

DETAILED

SP 800-82 Rev. 3

Full OT security guidance, including backup and resilience within a broader architecture

PRACTICE GUIDES

NCCoE SP 1800-series

Reference architectures for data integrity, ransomware recovery and event logging

QUICK START

SP 1339

A short, practical OT backup checklist drawn from the guidance above

SP 1339 sits above more detailed NIST guidance, distilling it into a short, practical checklist.

Read together, these documents position OT backup and recovery as a specific application of the wider data integrity concepts NIST has published across several programmes, rather than a separate topic.

## What OT recovery data is

Recovery data is the complete set of material needed to rebuild an OT environment, not simply a database export. NIST guidance treats it as covering both digital assets and the supporting documentation an engineer would need during a rebuild.

-   Controller logic and configuration files
-   Firmware images and licence keys
-   HMI graphics and historian configurations
-   Engineering documentation: I/O lists, wiring and network diagrams
-   Safety requirement specifications and cause and effect matrices
-   Operating system and virtual machine images for supporting servers

Engineering documentation is easy to overlook because it is not always stored alongside digital backups. Keeping printed and electronic copies available, and accessible during an incident, materially speeds up verification and troubleshooting during a rebuild.

## Integrity verification

A backup that has been altered, whether by corruption, misconfiguration or a deliberate attack, is not a usable recovery asset even if it exists. NIST guidance describes integrity verification through cryptographic hashing, so a restored file can be checked against a known value, combined with write-once or immutable storage that prevents the backup from being modified after it is written.

Backup exposed to change

Network Data 

-   Backup reachable and writable from production network
-   No hash recorded at time of backup
-   Retention can be shortened by an administrator

Backup integrity protected

Network Data 

-   Backup stored write-once or fully disconnected
-   Cryptographic hash recorded and checked on restore
-   Retention enforced independently of production credentials

Integrity depends on the backup being protected from change, not only on it existing.

## Recovery objectives

NIST guidance expects recovery objectives to be set per asset, based on mission criticality, rather than applying one blanket policy across an entire estate. Two figures matter most.

Recovery time objective (RTO)

The maximum acceptable time to restore a given asset to service after an incident.

Recovery point objective (RPO)

The maximum acceptable amount of data or configuration change lost since the last good backup.

A safety-critical PLC and a reporting historian will usually carry very different RTO and RPO figures. Setting objectives per asset, rather than uniformly, is what allows backup frequency and storage tiering decisions to be made deliberately instead of by default.

## Testing and restoration

A backup that has never been restored is unverified. NIST guidance calls for recurring restore tests, ideally on non-production systems, to confirm both that the backup restores successfully and that the restored system is functionally correct, not merely present.

Plan

Select an asset and a non-production target

Frequency driven by mission criticality

Restore

Restore from the backup to the test target

Verify against the recorded hash

Validate

Confirm functional correctness

Not just that the file matches, but that the system works

Record

Capture lessons learned

Feed back into backup frequency, media and procedure

A restore test validates the backup, the procedure and the response plan together.

## Hot, warm and cold backups

Different assets warrant different recovery tiers. Hot backups support near-immediate failover through continuous replication, at the cost of the replicated copy carrying the same exposure as the live system. Warm backups are updated on a schedule and allow a fairly quick recovery. Cold backups are stored offline or held as physical spares, and need a full rebuild before service resumes, but they carry the least ongoing exposure to whatever compromised the live system.

Fastest recovery

Hot

-   Continuous or near-real-time replication
-   Replica shares network exposure with the live system

Balanced

Warm

-   Updated on a regular schedule
-   Some data loss possible between updates

Lowest exposure

Cold

-   Stored offline or as a physical spare
-   Full rebuild required, but least exposed to a live compromise

Recovery tiers trade recovery speed against exposure to whatever compromised the live environment.

## Mapping to NIST CSF 2.0 Recover

[NIST Cybersecurity Framework 2.0](https://doi.org/10.6028/NIST.CSWP.29) organises outcomes into six functions. OT backup practice principally supports Recover, alongside supporting roles in Identify and Protect.

CSF 2.0 function

Relevant category

OT backup activity

Identify

Asset Management

Maintaining a current inventory of OT assets and their criticality

Protect

Data Security

Protecting backup media from unauthorised access, modification or destruction

Recover

Recovery Plan Execution

Executing tested restore procedures against defined recovery objectives

Recover

Recovery Communications

Recording and reporting the outcome of recovery actions

How OT backup activities map to relevant CSF 2.0 functions and categories.

## Mapping to the NCSC CAF

For UK readers, the same OT backup outcomes can be mapped to relevant principles within the [NCSC Cyber Assessment Framework](https://www.ncsc.gov.uk/collection/cyber-assessment-framework), particularly those covering resilient networks and systems, and response and recovery capability.

Mapped, not certified:  This is a mapping of outcomes for planning purposes. The CAF is an assessment framework applied by NCSC and sector regulators against a specific organisation and system, not a certificate that a backup product or practice can hold. No claim of CAF certification should be inferred from an outcome mapping.

## What SP 1339 does not do

SP 1339 does not mandate specific products, does not create a compliance regime, and does not replace the need for organisation-specific risk assessment. It is guidance, not regulation, though it is increasingly referenced in procurement standards, insurance questionnaires and audit expectations as a practical baseline for what a defensible OT backup programme looks like.

## How Firevault applies these principles

Firevault's Offline Secure Storage® is designed around the same integrity and protection expectations SP 1339 describes. The gold copy of OT recovery data is held with no live network interface while offline, removing the network path that a ransomware attack or a compromised management credential would otherwise use to reach it.

Every connection, disconnection and access to that copy is logged on a separate management plane, with identity, timestamp and reason recorded, giving asset owners the kind of evidence that supports the restore testing and recovery communications outcomes described above. Restores are carried out through scheduled, identity-verified connection windows, so the copy remains available for exercises and real incidents without being permanently reachable from production.

Key takeaway 

## SP 1339 is a checklist, not new theory

NIST SP 1339 does not introduce a new backup methodology for operational technology. It distils backup and recovery expectations that already exist in SP 800-82 Rev. 3, the NCCoE SP 1800-series data integrity guides and CSF 2.0 into a short, practical resource that asset owners and plant engineers can use directly.

The consistent theme across all of these sources is that a backup is only as good as its last verified restore, and that OT recovery data needs to be protected from the same threats it is meant to help an organisation recover from. A copy that remains reachable from the network during an incident has not actually solved that problem.

Questions 

## Frequently Asked Questions

Straight answers on how Offline Secure Storage® behaves in practice.

### What is NIST SP 1339?

### Is NIST SP 1339 mandatory?

### How does SP 1339 relate to NIST SP 800-82 Rev. 3?

### What is OT recovery data?

### How is OT backup integrity verified?

### What are recovery objectives in OT backup planning?

### How often should OT backups be tested?

### How does OT backup guidance map to the NIST Cybersecurity Framework 2.0?

### Does OT backup guidance map to the NCSC Cyber Assessment Framework?

### Does OT backup guidance require a physical air gap?

### What is the difference between hot, warm and cold OT backups?

## Sources and further reading

-   [NIST SP 1339, OT Backup Quick Start Guide](https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.1339.pdf)
    
    The primary source for this explainer, published by the NCCoE in June 2026.
    
-   [NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security](https://csrc.nist.gov/pubs/sp/800/82/r3/final)
    
    The detailed OT security guidance that SP 1339 draws its backup and recovery expectations from.
    
-   [NIST SP 1800-11, Data Integrity: Recovering from Ransomware and Other Destructive Events](https://www.nccoe.nist.gov/projects/data-integrity-recovering-ransomware-and-other-destructive-events)
    
    An NCCoE practice guide on recovery architectures for data integrity incidents, part of the SP 1800 series referenced in SP 1339.
    
-   [NIST Cybersecurity Framework (CSF) 2.0](https://doi.org/10.6028/NIST.CSWP.29)
    
    The framework functions, including Recover, that SP 1339's backup guidance maps to.
    
-   [NCSC, Cyber Assessment Framework (CAF)](https://www.ncsc.gov.uk/collection/cyber-assessment-framework)
    
    The UK outcomes-based framework used here to show how OT backup practice maps to CAF, without implying certification.
    

Related Firevault guides

[The Purdue Model for OT/ICS security](/news/the-purdue-model-everything-you-need-to-know) [What is OT security](/learn/what-is-ot-security) [OT and ICS security air gap storage](/learn/ot-ics-security-air-gap-storage) [NCSC ransomware-resistant backup principles](/compliance/ncsc-ransomware-resistant-backups)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

Share this explainer 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fnist-sp-1339-ot-backup-guide)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fnist-sp-1339-ot-backup-guide&text=NIST%20SP%201339%20Explained%3A%20The%20OT%20Backup%20Quick%20Start%20Guide%0A%0AAn%20independent%20explainer%20on%20the%20NIST%20guidance%20for%20operational%20technology%20data%20integrity%2C%20backup%20and%20recovery%2C%20what%20SP%201339%20asks%20organisations%20to%20do%2C%20and%20how%20it%20relates%20to%20SP%20800-82%20Rev.%203%2C%20the%20NCCoE%20SP%201800-series%20and%20CSF%202.0.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fnist-sp-1339-ot-backup-guide)[](mailto:?subject=NIST%20SP%201339%20Explained%3A%20The%20OT%20Backup%20Quick%20Start%20Guide&body=An%20independent%20explainer%20on%20the%20NIST%20guidance%20for%20operational%20technology%20data%20integrity%2C%20backup%20and%20recovery%2C%20what%20SP%201339%20asks%20organisations%20to%20do%2C%20and%20how%20it%20relates%20to%20SP%20800-82%20Rev.%203%2C%20the%20NCCoE%20SP%201800-series%20and%20CSF%202.0.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fnist-sp-1339-ot-backup-guide)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)