NIST Special Publication 800-234 is titled High-Performance Computing (HPC) Security Overlay. It went out as an initial public draft on 1 May 2025 and was published as final on 4 May 2026.
It answers the question SP 800-223 left open. The architecture publication describes what a cluster is and what threatens it, and then stops, by its own description a conceptual guide rather than a checklist. SP 800-234 is the checklist half: which controls apply to this machine, and what each one has to mean once the host is shared, the software is compiled by the person running it, and rebooting a node ends someone’s week of compute.
The publication does not define the word overlay. It borrows the definition, stating in its introduction that it “develops an overlay, as defined in NIST Special Publication (SP) 800-53B.” What it then does is the definition worth carrying in practice. It starts from an existing control baseline, works down it control by control, and adds supplemental guidance and discussion that say what that control means on an HPC system. The catalogue is not rewritten. The reading of it changes.
The base is stated three separate times inside the document, so there is no ambiguity about it: the overlay is built on the moderate baseline defined in SP 800-53B. Its abstract puts the whole thing in one line, that the overlay “tailors 60 security controls from NIST SP 800-53 with supplemental guidance and/or discussion to enhance their applicability in HPC contexts.”
Unlike SP 800-223, it names who it is written for: IT security managers, compliance officers, HPC system administrators, and agency program managers responsible for securing HPC environments. And it names its own ceiling. The abstract offers the overlay as “a robust foundation for securing HPC environments while also allowing for further customization to meet specific operational or mission needs.” A floor to build on, in other words, not the finished answer for every machine.
The author list is the operators again: NIST staff alongside contributors from Argonne, Los Alamos, Lawrence Livermore, Sandia, MIT Lincoln Laboratory, NASA, the Ohio Supercomputer Center, the DoD HPCMP, and the universities of Arkansas and Florida.