Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

The NMFTA Cybersecurity Best Practices Guidebook, Explained in Plain English

August 11, 2026
hero-nmfta-guidebook-explained-1.png

The NMFTA cybersecurity best practices guidebook is a free, voluntary security guide published by the National Motor Freight Traffic Association. It gives trucking companies a tiered set of controls, sized to fit owner-operators, small fleets, and mid-sized carriers. This page breaks it down, tier by tier, in plain English.

NMFTA is a nonprofit standards group for trucking and supply chain companies. Since 2025, NMFTA’s cybersecurity guidebook program has published guidebooks tailored by fleet size.

The guidebooks are free to download, and using them is voluntary. Think of this page as a plain-English map, not a replacement. Read the original NMFTA document before acting on any specific control.

Key Takeaways

  • The NMFTA guidebook is free and voluntary, not a law or a certification.
  • There are separate editions for Owner Operator/Small Fleet, Mid-Sized Fleet, and (soon) Large Fleet operations.
  • Controls are grouped into four tiers, from foundational (Tier One) to advanced (Tier Four).
  • Tier One covers the basics: passwords, MFA, backups, patching, EDR, wireless security, least privilege, and phishing training.
  • No government agency fines a carrier for skipping it, but brokers and insurers increasingly ask about it.

Which Guidebook Edition Fits Your Fleet

NMFTA publishes three editions, split by fleet size. Match yours before you start reading.

EditionFleet SizePublishedBest For
Owner Operator / Small FleetFewer than 50 assetsJanuary 16, 2025Independent owner-operators and small fleets without dedicated IT staff
Mid-Sized FleetRoughly 50 to 3,000 assetsMarch 13, 2025 (Version 1.0)Fleets with more established operations and some IT support
Large FleetOver 3,000 assetsAnnounced, not yet publishedLarge carriers (edition still forthcoming)

NMFTA announced the Owner Operator and Small Fleet guidebook on January 16, 2025. It targets fleets with fewer than 50 assets. The Mid-Sized Fleet guidebook, Version 1.0, followed on March 13, 2025. It’s built for fleets running roughly 50 to 3,000 assets. A Large Fleet edition for carriers over 3,000 assets was announced but hadn’t published yet as of the Mid-Sized release.

If your fleet sits near the 50-asset line, NMFTA says either edition may work, depending on how complex your operations already are.

Why It’s Four Tiers, Not One Checklist

The guidebook isn’t a single master checklist you pass or fail. It’s organized into four progressive tiers. Each tier builds on the one before it.

The Mid-Sized Fleet guidebook lays out four tiers: Prerequisites (Tier One), Initial (Tier Two), Intermediate (Tier Three), and Advanced (Tier Four). The first two tiers map to specific NIST Cybersecurity Framework maturity levels.

TierNIST Maturity LevelWhat It’s For
Tier One: PrerequisitesPartialFoundational controls every fleet needs first
Tier Two: InitialRisk InformedIncident response planning, vendor security, email authentication
Tier Three: IntermediateNot NIST-mapped in the guidebookMonitoring and trucking-specific technical controls
Tier Four: AdvancedNot NIST-mapped in the guidebookFormal risk management and business continuity

The stated end goal isn’t a certificate or a passing grade. It’s a security-minded culture, one that’s accepted across the whole organization, from dispatch to drivers.

What’s Actually in Tier One (Read This Part First)

Tier One is the foundation. If you read only one section of the real guidebook, make it this one. Most of it is achievable without a dedicated IT department.

Tier One’s foundational controls, in plain language:

  • Passwords and MFA. Use strong, unique passwords of at least 12 characters. Turn on multi-factor authentication, especially on admin accounts. Replace every default manufacturer password on day one.
  • The 3-2-1 backup rule. Keep 3 copies of your data, on 2 different media types, with 1 copy offsite. Test that backups actually restore, don’t just assume they do.
  • Patching. Turn on auto-updates wherever you can. Retire software the vendor no longer supports.
  • Endpoint detection and response (EDR). Run real EDR software on your devices, not just basic antivirus.
  • Wireless security. Lock down Wi-Fi with WPA2 encryption or stronger. Turn off insecure setup shortcuts on routers and access points.
  • Least privilege. Give people access to only what their job requires. Nothing more.
  • Basic phishing training. Teach dispatch, billing, and drivers to recognize phishing attempts. Make sure they know how to report one safely.
  • Device authentication. Require a password or biometric login on every device that touches company data.
  • Hardware and software inventory. Keep a documented list of what you’re running, so nothing slips through unpatched or forgotten.

Later tiers add incident response planning, vendor security, and network monitoring on top of this base. That’s what comes next.

What Comes After Tier One

Numbered process showing what NMFTA guidebook tiers two through four add: an incident response plan, security monitoring, and a prioritized risk register, each tier building on the one before.

Most fleets working through the guidebook for the first time are still on Tier One. Here’s a quick look at what’s ahead.

Tiers Two through Four move from foundational controls toward a more mature security program:

TierKey Additions
Tier Two: InitialWritten incident response plan and team, vendor security requirements, data classification, SPF/DMARC email authentication, network segmentation, device encryption, security logging
Tier Three: IntermediateA SIEM (security information and event management) tool, network intrusion detection, secure communication between telematics systems and providers
Tier Four: AdvancedA prioritized risk register, a formal vendor management program, mobile device management, disaster recovery and business continuity plans

It’s specific to trucking. You won’t find it in a general-purpose framework like NIST CSF on its own.

If Tier One feels manageable and you’re ready for more, that’s the order to tackle it in. Don’t skip ahead. Each tier assumes the one before it is already in place.

Where the Guidebook Fits with Cargo Theft

The guidebook’s controls exist because cyber-enabled cargo theft is real money walking out the door. NMFTA’s DOT cargo crime filing names fraudulent-carrier setups, FMCSA account takeovers, and load-board exploitation as the leading methods criminals use. Much of that risk runs through vendors, not your own network. That’s why NMFTA also publishes a separate vendor risk assessment framework for vetting telematics and TMS providers.

This page’s job is the guidebook document itself, not the full threat picture. For that, read the trucking cybersecurity guide for small fleets and owner-operators or the guide to cyber-enabled cargo theft and how to protect your fleet.

What the Guidebook Is Not

Clear up a common misunderstanding before you go further:

  • Not a certification. There’s no “NMFTA certified” status a trucking company can earn or display.
  • Not a law. No federal or state statute requires you to follow it.
  • Not fined. No government agency penalizes a carrier for skipping it.

There’s no regulator behind the NMFTA guidebook. The real enforcement is market pressure: brokers, shippers, and insurers increasingly ask about your cybersecurity posture during onboarding.

Skipping the guidebook won’t get you fined. It might get you a harder conversation with your next broker or insurer, or a costlier one if a load gets diverted. Read it as a signal you can use, not a mandate you can ignore.

See Where You Stand

Reading the full guidebook PDF takes time most fleet owners don’t have lying around. If you want the short version, see where your fleet stands against the Tier One controls in about two minutes. No sign-up required to see your result.

Take the free 2-minute Trucking Cybersecurity Risk-Check

Frequently Asked Questions

It’s a free cybersecurity guide published by the National Motor Freight Traffic Association for trucking companies. It adapts the NIST Cybersecurity Framework and CIS Controls into tiered, trucking-specific guidance. There are separate editions by fleet size, and it’s entirely voluntary.

No. It’s voluntary industry guidance, not a law or a federal regulation. No government agency fines a trucking company for not following it. That said, brokers and insurers increasingly ask about cybersecurity practices, so ignoring it can carry a business cost even without a legal one.

Fleets with fewer than 50 assets should use the Owner Operator and Small Fleet edition, published January 16, 2025. Fleets with roughly 50 to 3,000 assets should use the Mid-Sized Fleet edition, published March 13, 2025. A Large Fleet edition for carriers over 3,000 assets was announced but hadn’t published yet as of the Mid-Sized release. If you’re near the 50-asset line, either edition may work depending on how complex your operations are.

Four. Tier One (Prerequisites) covers foundational controls like passwords, MFA, and backups. Tier Two (Initial) adds incident response and vendor security. Tier Three (Intermediate) adds monitoring tools. Tier Four (Advanced) adds formal risk management and business continuity planning.

No. The National Motor Freight Traffic Association is a nonprofit standards-setting organization for the trucking and supply chain industry. Its guidebooks are best-practice guidance, not government rules.

Get Help Putting the Guidebook’s Controls in Place

Reading the guidebook is one thing. Implementing MFA across every dispatch and billing account, setting up tested backups, and configuring email authentication is another, especially without an in-house IT team. LeadingIT’s managed IT services for trucking and logistics cover the Tier One and Tier Two technical controls directly, from EDR and patch management to incident response planning.

We work with Chicagoland fleets every day who are starting exactly where you are. Book a call to talk through your fleet’s setup, or contact us with questions.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.