<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="https://www.jain.com/assets/img/6adafce5-1.1"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cybersecurity Framework &#8211; Jain.com</title>
	<atom:link href="/tag/cybersecurity-framework/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Data centers, connectivity, and security — news and analysis</description>
	<lastBuildDate>Tue, 12 May 2026 16:00:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>/wp-content/uploads/2026/08/jain-com-icon-512-150x150.png</url>
	<title>Cybersecurity Framework &#8211; Jain.com</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>NIST Rewrites PNT Cybersecurity Guidance for the CSF 2.0 Era</title>
		<link>/nist-pnt-cybersecurity-guidance-csf-2-0-gps-jamming-spoofing/</link>
		
		<dc:creator><![CDATA[Deepak Jain]]></dc:creator>
		<pubDate>Tue, 12 May 2026 16:00:00 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[Cybersecurity Framework]]></category>
		<category><![CDATA[GPS]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[PNT]]></category>
		<category><![CDATA[supply chain security]]></category>
		<category><![CDATA[Timing and Synchronization]]></category>
		<guid isPermaLink="false">/nist-pnt-cybersecurity-guidance-csf-2-0-gps-jamming-spoofing/</guid>

					<description><![CDATA[NIST has revised its PNT cybersecurity guidance under CSF 2.0 to cover GPS jamming and spoofing, AI risk and supply-chain threats. Data center, grid and telecom operators depend on precise time and position sync, and the refresh turns that quiet dependency into an auditable set of controls.]]></description>
										<content:encoded><![CDATA[<div class="jain-post-grid">
<div class="jain-post-main">
<p>The U.S. National Institute of Standards and Technology (NIST) has revised its cybersecurity guidance for positioning, navigation and timing (PNT) services, realigning it to version 2.0 of the NIST Cybersecurity Framework and expanding its treatment of GPS disruption, artificial-intelligence risk and supply-chain threats, according to trade coverage published on 12 May 2026.</p>
<p>PNT services are the satellite and terrestrial systems that tell equipment where it is and, more importantly for infrastructure operators, what time it is to within billionths of a second. The revision is guidance rather than regulation: it gives operators of data centers, power grids, financial systems and telecom networks a structured way to inventory their dependence on those signals and to defend the systems that consume them.</p>
<h2>Executive Summary</h2>
<p>NIST&#8217;s foundational PNT profile was written to satisfy Executive Order 13905, signed in February 2020, which directed the federal government to help critical-infrastructure owners use PNT services more responsibly. That original profile was built on the first-generation Cybersecurity Framework (CSF 1.1). CSF 2.0, published in February 2024, added a sixth core function — Govern — alongside Identify, Protect, Detect, Respond and Recover, and pushed supply-chain risk management from a subcategory into a first-class concern. A PNT profile pinned to the older framework was, over time, going to drift out of step with how organizations actually structure their security programs.</p>
<p>The substantive additions matter more than the renumbering. Deliberate GPS jamming and spoofing have moved from a theoretical concern to a routinely reported operating condition in several regions, particularly for aviation and maritime users, and the same interference affects any fixed receiver in range. Adding explicit treatment of AI risk acknowledges that machine-learning systems are increasingly used both to detect anomalous timing signals and, on the other side, to generate more convincing spoofed ones. Supply-chain coverage addresses a quieter problem: most operators do not buy PNT directly, they buy it embedded inside a network switch, a phasor measurement unit or a timing appliance from a vendor they have never audited on this dimension.</p>
<p>For infrastructure buyers, the practical value is leverage. Voluntary NIST profiles tend to become procurement language, insurance questionnaires and audit checklists within a few budget cycles, which is usually how they change behaviour.</p>
<h2>Timing Is Infrastructure, Even When Nobody Owns It</h2>
<p>Precise time is the least-discussed dependency in modern digital infrastructure. Distributed databases use timestamps to order transactions and resolve conflicts; if clocks in two availability zones diverge, writes can be applied out of order or reject each other. Mobile networks use tight synchronization to keep adjacent cells from interfering, and time-division and 5G radio schemes are particularly unforgiving of drift. Electrical grids use time-stamped phasor measurements — sampled tens of times per second across hundreds of miles — to detect instability, which only works if every sampler agrees on the moment of sampling. Financial venues are required to timestamp orders to prove sequence. In each case the clock is not a feature of the system; it is a precondition for the system being correct.</p>
<p>The awkward part is that most of this timing arrives free, from space, via GPS and its counterparts. A rooftop antenna the size of a coffee mug feeds a receiver that disciplines a local oscillator, and the resulting signal is distributed inside the building over NTP or the more precise Precision Time Protocol. Nobody is billed for it, so it rarely appears on a dependency map, and it is frequently owned by facilities or network engineering rather than by security. A NIST profile that forces the question — which of our systems fail, and how visibly, if this signal degrades — is doing useful work before it recommends a single control.</p>
<p>Degradation is also the hard case. An antenna that goes dark is easy to detect and fail over. A receiver that is being spoofed reports a confident, plausible, wrong time, and a good spoof walks the clock slowly enough that naive threshold alarms never fire. That failure mode propagates silently into logs, transaction ordering and forensic timelines, which is precisely why it belongs in a cybersecurity framework rather than a facilities runbook.</p>
<h2>What CSF 2.0 Actually Changes for a PNT Program</h2>
<p>The addition of the Govern function is not cosmetic. Under CSF 1.1, an operator could describe technical PNT controls without ever assigning accountability for them. Govern asks who owns the risk, how it is expressed in policy, what the risk tolerance is, and how third-party dependencies are managed. For timing, that maps onto a real organizational gap: the team that installs the GPS antenna, the team that runs the NTP servers and the team that would be blamed for a corrupted transaction log are usually three different teams with no shared document.</p>
<p>The supply-chain emphasis lands on a genuinely under-examined surface. PNT capability is overwhelmingly delivered as a component — a receiver module, a timing card, an oscillator, firmware that parses satellite messages. Buyers evaluating a timing appliance typically compare holdover specifications and price, not the provenance of the receiver chipset or the vendor&#8217;s firmware-update practices. Asking suppliers to document that lineage is the kind of requirement that is trivial to write and expensive to satisfy, and it will surface differences between vendors who have anticipated the question and those who have not.</p>
<p>The AI dimension is the newest and, on the evidence available in the headline alone, the least defined. There are at least three distinct concerns worth separating: machine-learning models used to classify anomalous PNT signals, which can be evaded or poisoned; AI-assisted generation of spoofing waveforms, which lowers the skill required to mount an attack; and AI systems that consume PNT data as an input, where corrupted timing quietly corrupts inference. Guidance that treats these as one topic would be less useful than guidance that treats them as three.</p>
<h2>Who Benefits, and What It Costs to Comply</h2>
<p>The clearest commercial beneficiaries are vendors of resilient timing: makers of rubidium and cesium clocks and high-quality oven-controlled oscillators that let a facility ride out signal loss in holdover for hours or days, suppliers of multi-constellation receivers that can fall back from GPS to Galileo, GLONASS or BeiDou, providers of terrestrial and fibre-delivered time services, and the smaller field of anti-spoofing and signal-authentication products. None of these are new categories. What a widely cited framework profile changes is the buyer&#8217;s ability to justify the line item, because &#8220;NIST&#8217;s profile asks us to demonstrate holdover capability&#8221; is a more durable argument than an engineer&#8217;s professional unease.</p>
<p>The cost falls unevenly. Large hyperscale and carrier operators have generally engineered timing redundancy already, often with multiple antennas, atomic holdover and diverse distribution; for them the work is documentation, governance and supplier attestation rather than capital equipment. Regional colocation providers, industrial operators and mid-sized utilities are the ones more likely to discover a single receiver feeding a single time server with no holdover behind it. That asymmetry is worth naming plainly: guidance of this kind tends to raise the floor, and raising the floor is more expensive for whoever is standing on it.</p>
<p>It is also worth being precise about what this announcement is and is not. It is a revision to voluntary guidance, aligned to a voluntary framework, from a standards body with no enforcement authority. It does not compel any operator to buy anything or meet any deadline. The realistic mechanism of influence is indirect — contract language, insurer questionnaires, sector regulators who cite NIST documents by reference — and that mechanism works on a timescale of years, not quarters. Readers should treat the substantive question as open until the document text itself is examined: alignment to CSF 2.0 is a structural claim, and whether the underlying technical recommendations have materially advanced is something only the revised profile can answer.</p>
<h2>Background</h2>
<p>NIST is the U.S. federal standards body whose cybersecurity publications are used far beyond the federal government, both domestically and internationally, as a common vocabulary for security programs. Its Cybersecurity Framework, first issued in 2014 and revised as CSF 2.0 in February 2024, is descriptive rather than prescriptive: it organizes outcomes into core functions and lets each sector write a &#8220;profile&#8221; mapping those outcomes to its own risks. The PNT profile is one such sector-style profile, created after Executive Order 13905 in February 2020 identified over-reliance on satellite timing as a national infrastructure risk.</p>
<p>That concern has only sharpened. GPS and its peer constellations broadcast extremely weak signals from roughly 20,000 kilometres away, which makes them inherently easy to overpower locally with modest equipment. Widespread interference has been reported around several conflict zones in recent years, affecting aviation and maritime navigation, and the same physics applies to any fixed rooftop receiver. Meanwhile the number of systems that silently depend on nanosecond-accurate time — cloud databases, 5G radio networks, grid phasor measurement, financial timestamping — has grown considerably faster than the redundancy protecting it.</p>
<p>Source: <a href="https://news.google.com/rss/articles/CBMi5gFBVV95cUxOQ2dvZml2UzMxeG5qY2RUcXZKbWF4RlhsU0RWbnI4V0pra2trNnBxX1VxVnFtMzVWTUxWTFl5WHBUMEt2SnE0WXhOTnJQYndtM3Z1dGlyc2JiVGVhYTJiOVd1NjR4TVU2bW5BTkFCLWNJZmFpaVdyZHQ5NVh0eHFYMDU4aEdjcUllQ3N2MFVyWld6ZE9uSGJKZTBqV3ZoYkNvTThTQkE0YUJpTkdxOVhwbWpxR29XcWtQYTdpbUNxQ3VRQVJWNWNfLTI1a294dDI2blFoc2RrZ28tODdvVTlaYkxYcW9vdw?oc=5">NIST revises PNT services cybersecurity guidance under CSF 2.0 to address GPS disruption, AI risks, supply chain threats</a> — Industrial Cyber, 12 May 2026, reporting NIST&#8217;s realignment of its positioning, navigation and timing profile to version 2.0 of the Cybersecurity Framework.</p>
</div>
<aside class="jain-rail">
<section class="jain-gaps" aria-label="What the release does not say">
<p class="jain-gaps-kicker"><img src="https://www.jain.com/assets/img/dbaaff79-26a0.png" alt="⚠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> What They Aren’t Saying</p>
<h2>What the Release Doesn&#8217;t Say</h2>
<p>The available source is a single trade-press headline and summary, which leaves the most important details unresolved. It does not identify the document number or revision level, state whether the release is a draft issued for public comment or a final publication, or give a comment deadline or effective date. Anyone planning work against this guidance needs that status first, because a draft can change materially before it is finalized.</p>
<ul>
<li><strong>Scope of the AI content:</strong> whether the profile addresses AI-assisted spoofing, adversarial attacks on ML-based signal monitoring, AI systems that consume PNT data, or all three — and at what level of specificity.</li>
<li><strong>Supply-chain expectations:</strong> whether suppliers are expected to provide component-level provenance, a software bill of materials covering receiver firmware, or only general assurance statements.</li>
<li><strong>Prescriptiveness:</strong> whether the revision recommends measurable outcomes — holdover duration, spoof-detection capability, multi-constellation support — or remains outcome-neutral in the usual CSF style.</li>
<li><strong>Sector applicability:</strong> whether data centers and cloud providers are addressed as a distinct profile audience alongside the transport, energy and financial sectors that have historically dominated PNT discussion.</li>
<li><strong>Alternatives to GNSS:</strong> whether terrestrial backup approaches are treated as recommended architecture or merely acknowledged, given the long-running and unresolved policy debate over a national terrestrial timing backup in the United States.</li>
<li><strong>Adoption path:</strong> whether any sector regulator or federal acquisition authority intends to reference the revised profile, which is what would convert voluntary guidance into practical obligation.</li>
</ul>
</section>
<section class="jain-faq">
<h2>Frequently Asked Questions</h2>
<h3>What did NIST announce?</h3>
<p>NIST revised its cybersecurity guidance for positioning, navigation and timing services, realigning it to the CSF 2.0 framework and expanding coverage of GPS disruption, AI-related risk and supply-chain threats. The change was reported on 12 May 2026.</p>
<h3>What are PNT services?</h3>
<p>Positioning, navigation and timing services are the systems — mostly satellite constellations such as GPS — that tell equipment where it is, how it is moving and, critically for infrastructure, what the exact time is to within nanoseconds.</p>
<h3>Why does a data center care about GPS?</h3>
<p>Not for location. Data centers use GPS as a free, highly accurate clock source. That time signal orders database transactions, synchronizes distributed systems, timestamps logs and keeps network protocols consistent across sites.</p>
<h3>What is the NIST Cybersecurity Framework?</h3>
<p>A voluntary, widely adopted structure for organizing security programs. Version 1.1 had five core functions: Identify, Protect, Detect, Respond, Recover. Version 2.0, published in February 2024, added a sixth: Govern.</p>
<h3>What does CSF 2.0 add that matters here?</h3>
<p>The Govern function forces organizations to assign accountability, set risk tolerance and manage third-party dependencies rather than only listing technical controls. CSF 2.0 also elevates supply-chain risk management to a first-class concern.</p>
<h3>Why did NIST have PNT guidance in the first place?</h3>
<p>Executive Order 13905, signed in February 2020, directed the U.S. government to promote responsible use of PNT services by critical infrastructure. NIST&#8217;s foundational PNT profile was produced to meet that direction and was built on CSF 1.1.</p>
<h3>What is the difference between GPS jamming and spoofing?</h3>
<p>Jamming drowns the satellite signal in noise so the receiver loses lock — disruptive but obvious. Spoofing feeds the receiver a counterfeit signal so it reports a confident but wrong position or time, which is far harder to detect.</p>
<h3>Why is spoofing worse than losing the signal entirely?</h3>
<p>A dead antenna triggers alarms and failover. A slowly drifting spoofed clock looks healthy while quietly corrupting transaction ordering, log timelines and any system that assumes its peers agree on the time.</p>
<h3>How does AI enter the picture?</h3>
<p>In at least three ways: machine learning is used to detect anomalous PNT signals and can be evaded; AI can help generate more convincing spoofed signals; and AI systems that consume timing data inherit any corruption in it.</p>
<h3>What is the supply-chain concern for timing equipment?</h3>
<p>Most operators never buy PNT directly. It arrives embedded in switches, timing cards, measurement units and firmware from vendors who are rarely audited on receiver provenance or update practices. The revision pushes buyers to ask.</p>
<h3>Is this guidance mandatory?</h3>
<p>No. NIST profiles are voluntary and NIST has no enforcement authority. Influence comes indirectly, through procurement language, insurer questionnaires and sector regulators that cite NIST documents by reference — typically over years.</p>
<h3>What should an infrastructure operator do first?</h3>
<p>Inventory the dependency: which systems consume time or position data, where those signals originate, how many independent sources exist, and what each system does when the signal degrades rather than disappears.</p>
<h3>What is holdover, and why does it matter?</h3>
<p>Holdover is how long a local oscillator keeps accurate time after losing its satellite reference. A cheap oscillator drifts within minutes; rubidium or cesium clocks hold accuracy for hours or days, turning an outage into a non-event.</p>
<h3>Who benefits commercially from this update?</h3>
<p>Vendors of atomic and high-stability oscillators, multi-constellation receivers, fibre-delivered and terrestrial time services, and anti-spoofing products. The categories are not new; the framework mainly makes the budget easier to justify.</p>
<h3>Which operators face the biggest compliance burden?</h3>
<p>Not the hyperscalers and large carriers, who generally already run redundant, atomic-backed timing. Regional colocation providers, mid-sized utilities and industrial operators are likelier to find a single receiver with no backup behind it.</p>
<h3>What is still unknown about this revision?</h3>
<p>The source headline does not give the document number, whether it is a draft for comment or final, any comment deadline, or how prescriptive the technical recommendations are. Those details determine what operators should actually do next.</p>
</section>
</aside>
</div>
<p><script type="application/ld+json">{"@context": "https://schema.org", "@graph": [{"@type": "NewsArticle", "headline": "NIST Rewrites PNT Cybersecurity Guidance for the CSF 2.0 Era", "description": "NIST has revised its PNT cybersecurity guidance under CSF 2.0 to cover GPS jamming and spoofing, AI risk and supply-chain threats. Data center, grid and telecom operators depend on precise time and position sync, and the refresh turns that quiet dependency into an auditable set of controls.", "image": ["/wp-content/uploads/2026/08/nist-pnt-cybersecurity-guidance-csf-2-0-gps-timing.png"], "author": {"@type": "Organization", "name": "jain.com Editorial"}, "datePublished": "2026-08-30T01:32:39.754223+00:00"}, {"@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "What did NIST announce?", "acceptedAnswer": {"@type": "Answer", "text": "NIST revised its cybersecurity guidance for positioning, navigation and timing services, realigning it to the CSF 2.0 framework and expanding coverage of GPS disruption, AI-related risk and supply-chain threats. The change was reported on 12 May 2026."}}, {"@type": "Question", "name": "What are PNT services?", "acceptedAnswer": {"@type": "Answer", "text": "Positioning, navigation and timing services are the systems \u2014 mostly satellite constellations such as GPS \u2014 that tell equipment where it is, how it is moving and, critically for infrastructure, what the exact time is to within nanoseconds."}}, {"@type": "Question", "name": "Why does a data center care about GPS?", "acceptedAnswer": {"@type": "Answer", "text": "Not for location. Data centers use GPS as a free, highly accurate clock source. That time signal orders database transactions, synchronizes distributed systems, timestamps logs and keeps network protocols consistent across sites."}}, {"@type": "Question", "name": "What is the NIST Cybersecurity Framework?", "acceptedAnswer": {"@type": "Answer", "text": "A voluntary, widely adopted structure for organizing security programs. Version 1.1 had five core functions: Identify, Protect, Detect, Respond, Recover. Version 2.0, published in February 2024, added a sixth: Govern."}}, {"@type": "Question", "name": "What does CSF 2.0 add that matters here?", "acceptedAnswer": {"@type": "Answer", "text": "The Govern function forces organizations to assign accountability, set risk tolerance and manage third-party dependencies rather than only listing technical controls. CSF 2.0 also elevates supply-chain risk management to a first-class concern."}}, {"@type": "Question", "name": "Why did NIST have PNT guidance in the first place?", "acceptedAnswer": {"@type": "Answer", "text": "Executive Order 13905, signed in February 2020, directed the U.S. government to promote responsible use of PNT services by critical infrastructure. NIST's foundational PNT profile was produced to meet that direction and was built on CSF 1.1."}}, {"@type": "Question", "name": "What is the difference between GPS jamming and spoofing?", "acceptedAnswer": {"@type": "Answer", "text": "Jamming drowns the satellite signal in noise so the receiver loses lock \u2014 disruptive but obvious. Spoofing feeds the receiver a counterfeit signal so it reports a confident but wrong position or time, which is far harder to detect."}}, {"@type": "Question", "name": "Why is spoofing worse than losing the signal entirely?", "acceptedAnswer": {"@type": "Answer", "text": "A dead antenna triggers alarms and failover. A slowly drifting spoofed clock looks healthy while quietly corrupting transaction ordering, log timelines and any system that assumes its peers agree on the time."}}, {"@type": "Question", "name": "How does AI enter the picture?", "acceptedAnswer": {"@type": "Answer", "text": "In at least three ways: machine learning is used to detect anomalous PNT signals and can be evaded; AI can help generate more convincing spoofed signals; and AI systems that consume timing data inherit any corruption in it."}}, {"@type": "Question", "name": "What is the supply-chain concern for timing equipment?", "acceptedAnswer": {"@type": "Answer", "text": "Most operators never buy PNT directly. It arrives embedded in switches, timing cards, measurement units and firmware from vendors who are rarely audited on receiver provenance or update practices. The revision pushes buyers to ask."}}, {"@type": "Question", "name": "Is this guidance mandatory?", "acceptedAnswer": {"@type": "Answer", "text": "No. NIST profiles are voluntary and NIST has no enforcement authority. Influence comes indirectly, through procurement language, insurer questionnaires and sector regulators that cite NIST documents by reference \u2014 typically over years."}}, {"@type": "Question", "name": "What should an infrastructure operator do first?", "acceptedAnswer": {"@type": "Answer", "text": "Inventory the dependency: which systems consume time or position data, where those signals originate, how many independent sources exist, and what each system does when the signal degrades rather than disappears."}}, {"@type": "Question", "name": "What is holdover, and why does it matter?", "acceptedAnswer": {"@type": "Answer", "text": "Holdover is how long a local oscillator keeps accurate time after losing its satellite reference. A cheap oscillator drifts within minutes; rubidium or cesium clocks hold accuracy for hours or days, turning an outage into a non-event."}}, {"@type": "Question", "name": "Who benefits commercially from this update?", "acceptedAnswer": {"@type": "Answer", "text": "Vendors of atomic and high-stability oscillators, multi-constellation receivers, fibre-delivered and terrestrial time services, and anti-spoofing products. The categories are not new; the framework mainly makes the budget easier to justify."}}, {"@type": "Question", "name": "Which operators face the biggest compliance burden?", "acceptedAnswer": {"@type": "Answer", "text": "Not the hyperscalers and large carriers, who generally already run redundant, atomic-backed timing. Regional colocation providers, mid-sized utilities and industrial operators are likelier to find a single receiver with no backup behind it."}}, {"@type": "Question", "name": "What is still unknown about this revision?", "acceptedAnswer": {"@type": "Answer", "text": "The source headline does not give the document number, whether it is a draft for comment or final, any comment deadline, or how prescriptive the technical recommendations are. Those details determine what operators should actually do next."}}]}]}</script></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
