Updated on September 29, 2026
SolvLegal Team
8 min read
0 Comments
Immigration & NRI Legal Services

EB-2 NIW for Cybersecurity and Critical Infrastructure Professionals: How to Build an Industry-Based National Interest Waiver Petition

By the SolvLegal Team

Published on: Sept. 29, 2026, 4:22 p.m.

EB-2 NIW for Cybersecurity and Critical Infrastructure Professionals: How to Build an Industry-Based National Interest Waiver Petition


Quick Answer

For an EB-2 NIW cybersecurity case, substantial industry experience can be relevant even where the professional is not primarily an academic researcher, but cybersecurity as a field does not by itself establish national importance. The petitioner must first satisfy the underlying EB-2 classification and then the three-prong NIW framework. The task is to define a specific U.S. proposed endeavor, show its merit and national importance, establish that the professional is well positioned to advance it, and explain why the waiver would benefit the United States.

Introduction

Consider a senior security architect with twelve years of experience in identity controls, incident response and cloud security. Another professional may have spent a decade securing industrial control systems for utilities, manufacturers or transport operators. Both may have strong résumés and certifications. Yet the difficult NIW question is not whether cybersecurity matters. It is how the individual’s proposed U.S. work will satisfy the NIW framework.

That distinction matters because the NIW analysis is not a recognition program for an important occupation. USCIS evaluates the proposed endeavor, meaning the specific work the noncitizen proposes to undertake in the United States, rather than simply the importance of the profession or industry. Recent AAO decisions involving IT, cybersecurity and other STEM professionals illustrate that field-level importance does not automatically establish national importance of one person’s proposed work.

What the EB-2 NIW Does

The EB-2 category is created bySection 203(b)(2)(A) of the Immigration and Nationality Act. It covers qualified immigrants who are members of the professions holding advanced degrees, or who possess exceptional ability in the sciences, arts or business and who fall within the statutory benefit structure. The regulation at8 C.F.R. § 204.5(k)supplies the principal evidentiary framework for the underlying classification.

The National Interest Waiver is a separate inquiry.Section 203(b)(2)(B)(i) of the INAallows the job-offer requirement to be waived when the waiver is in the national interest. In the NIW context, the petitioner may file Form I-140 without the ordinary employer-sponsored labor certification requirement, and USCIS permits the individual seeking the waiver to self-petition. The waiver does not eliminate the need to qualify for EB-2 first.USCIS’s January 15, 2025 policy guidanceconfirms that underlying EB-2 eligibility is considered before the NIW.

For an industry cybersecurity professional, this creates two stages that should remain separate. First, establish the EB-2 threshold as an advanced-degree professional or individual of exceptional ability. Second, build the NIW case around the proposed endeavor and Dhanasar. Evidence for the first stage does not automatically prove the second.

The Matter of Dhanasar Framework

Matter of Dhanasar provides the controlling administrative framework for NIW adjudication. USCIS may exercise discretion to grant the waiver when the petitioner establishes three elements: the proposed endeavor has substantial merit and national importance; the individual is well positioned to advance the proposed endeavor; and, on balance, it would be beneficial to the United States to waive the job-offer and labor-certification requirements.[1]

The first prong is endeavor-focused. Dhanasar recognises substantial merit in areas including business, science and technology. National importance turns on the endeavor’s prospective impact and broader implications, including effects beyond a particular employer or customer base.[2]

The second prong shifts the focus to the individual. USCIS considers education, skills, knowledge, success in related efforts, a plan for future activities, progress toward the endeavor and relevant third-party interest. The evidence need not resemble an academic curriculum vitae; it should show that the person is realistically equipped to advance the endeavor.[3]

The third prong asks why, considering the record as a whole, the United States would benefit from waiving the ordinary job-offer and labor-certification requirements. The analysis must therefore address the waiver itself, not merely the applicant’s talent or the importance of cybersecurity.[4]

Why Cybersecurity and Critical Infrastructure Matter to an EB-2 NIW Case

CISA describes critical infrastructureas the assets, systems and networks that provide functions necessary to American life and identifies sixteen critical infrastructure sectors. CISA also explains that disruption to these sectors can have potentially debilitating consequences for national security, economic security, public health or public safety. TheInformation Technology Sectoris itself identified as central to national security, the economy, public health and safety, with its services deeply interconnected with other sectors.[5]

The policy context becomes particularly concrete when the proposed endeavor concerns operational technology. NIST’s current final guidance,Special Publication 800-82 Revision 3, explains that OT systems interact directly with the physical environment and include systems such as industrial control systems, building automation, transportation systems and related control technologies. These environments have security requirements that must be balanced against performance, reliability and safety considerations.[6]

CISA’sCross-Sector Cybersecurity Performance Goalsidentify prioritized security practices across critical infrastructure, whileNIST’s Cybersecurity Framework 2.0provides a common structure for managing cybersecurity risk. These materials can document why a problem matters to the United States, but they do not replace the applicant-specific showing required by Dhanasar. Government recognition of cybersecurity’s importance is policy context, not proof of the national importance of one professional’s endeavor.[7]

Recent GAO work documents the dependence of critical infrastructure on computer-based systems and continuing cybersecurity and OT challenges. Such sources can establish the problem space, but the petition still must connect that national problem to the petitioner’s specific solution.[8]

Research literature can add depth without becoming a substitute for applicant-specific evidence. A 2024 ACM Computing Surveys review describes cyber resilience as the ability to prepare for, absorb, recover from and adapt to cyber attacks, while recent IT/OT literature identifies interoperability, legacy systems and convergence as recurring challenges. Such literature can corroborate the problem that an endeavor addresses; it does not establish the petitioner’s prospective impact by itself.[9]

Why “I Work in Cybersecurity” Is Not Enough

A cybersecurity professional may have an important occupation and still present an underdeveloped NIW endeavor. In a July 11, 2023 AAO non-precedent decision involving a STEM and cybersecurity-related professional, the AAO reiterated that job growth in a field does not itself establish national importance and that employment in STEM or cybersecurity does not automatically satisfy the first Dhanasar prong. The decision focused on insufficient specificity concerning the proposed endeavor.[10]

A 2024 AAO decision concerning an IT-oriented endeavor likewise acknowledged the value of strengthening cybersecurity and IT infrastructure but found that the record did not show an impact beyond the organization and clients served. The decision illustrates why a petition must connect the specific undertaking to broader implications rather than rely on the importance of the field.[11]

A March 11, 2025 AAO decision involving a cybersecurity entrepreneur likewise illustrates the distinction. The proposed business included cybersecurity consulting, but the national-importance analysis required evidence concerning the proposed endeavor itself rather than a generalized description of cybersecurity. For industry professionals, descriptions such as “improving cybersecurity” or “providing security consulting” may be too broad without a defined problem, activity and prospective reach.[12]

The most useful drafting question is therefore not “How important is cybersecurity?” It is “What, specifically, will this professional do in the United States, for whom, to address what defined problem, and with what plausible broader effect?” That question moves the petition from occupation-level description to endeavor-level analysis.

Building the Proposed Endeavor

The proposed endeavor should identify the work, the problem, intended beneficiaries and the mechanism through which broader impact could occur. “Cybersecurity consultant” is an occupational label. A defined activity, such as developing scalable security architecture and incident-response methods for regional healthcare providers, gives USCIS something concrete to evaluate. Its national importance would still depend on the evidence.

A well-developed endeavor should identify the problem, activities, relevant beneficiaries, expected results and the evidence supporting any claim of broader impact. The final question is often the hardest: what makes the claimed future effect more than an assertion?

The strongest endeavor statements distinguish ordinary job duties from broader professional activity. Performing vulnerability scans for one employer may be routine employment. Developing a reusable methodology for multiple critical-sector environments and demonstrating external adoption describes a broader activity that can be evaluated for prospective reach. Whether it satisfies Dhanasar remains case-specific.

IT Cybersecurity vs. OT, ICS and Critical Infrastructure

The legal standard does not change because a professional works in operational technology. The factual context can, however, make the proposed impact easier to define. IT work may concern identity, cloud security, software supply chains, application security, data protection, detection and response or security architecture. OT and ICS work can intersect with physical processes, safety, reliability and continuity of essential services.[13]

NIST’s OT guidance highlights unique performance, reliability and safety requirements. Research literature also identifies IT/OT convergence, legacy systems and interoperability as recurring security challenges. Those distinctions can help explain why a particular problem matters and why an intervention could have broader relevance.[14]

The distinction should not be overstated. “I worked on power-grid cybersecurity” describes past employment. A more developed endeavor might involve designing and disseminating a resilience architecture for utility operators, testing it across defined environments and developing methods capable of wider adoption. The legal issue remains the prospective national importance of that specific work.

As of September 2026, NIST has also released an initial public draft of SP 800-82 Revision 4. Revision 3 remains the final published version. The existence of a new draft is useful context for the continuing evolution of OT cybersecurity, but a petition should cite the status of the document accurately rather than treating a draft as a final technical standard.[15]

Evidence an Industry Professional May Use in an EB-2 NIW Cybersecurity Case

An industry professional’s evidence can be persuasive when it is tied tightly to the proposed endeavor and independently corroborated. The relevant record may include:

·        Significant security programs or projects, with documentation showing the professional’s role, scope of responsibility and concrete results.

·        Measured outcomes such as reduced incident response time, improved detection coverage, lower exposure, higher control maturity or documented resilience improvements, where the underlying data can be authenticated.

·        Architecture, engineering or implementation records, including diagrams, reports, project summaries or internal recognition that can be disclosed without violating confidentiality obligations.

·        Leadership evidence showing responsibility for teams, security programs, enterprise transformations or critical deployments, particularly where the role was central to the outcome.

·        Critical-sector projects involving energy, healthcare, transportation, finance, communications, manufacturing, water or other infrastructure, where the record shows why the work mattered and what the professional actually contributed.

·        Professional certifications such as CISSP, CISM, CISA or comparable credentials, treated as evidence of education, knowledge or professional standing rather than as automatic proof of NIW eligibility.

·        Patents, publications, conference speaking, training, standards participation, peer review, awards or professional recognition, where they genuinely relate to the proposed endeavor.

·        Expert or recommendation letters from people with direct knowledge of the work. The strongest letters explain specific projects, contribution, significance and prospective relevance rather than repeating conclusory praise.

·        Evidence of prospective U.S. activity, such as a credible implementation plan, identified projects, investor or customer interest where applicable, or other documentation showing that the proposed endeavor is more than a general career intention.

USCIS’s January 2025 guidance also addresses STEM professionals and entrepreneurs. It recognises that work involving critical or emerging technologies can be a positive consideration, but a STEM degree or occupation is not enough by itself. The evidence must still show that the individual is well positioned to advance the specific proposed endeavor and satisfy the other NIW requirements.[16]

Do Publications and Citations Matter?

They can matter, but they are not a universal requirement. The relevant question is what the publication or citation proves. A paper may support expertise and substantive contribution, while technical writing, speaking or standards work may show dissemination or professional influence. The connection to the proposed endeavor matters more than the mere existence of a publication.

USCIS does not impose a general citation-count requirement. The absence of academic citations should not automatically undermine an industry profile where the record shows deployed systems, measurable results, engineering responsibility or adoption. Publications and citations can nevertheless strengthen a case when they document influence connected to the proposed endeavor.

Common Weaknesses in Cybersecurity NIW Petitions

Several weaknesses recur in the record of industry-oriented cases.

·        Generic proposed endeavor. “Advancing cybersecurity in the United States” is too abstract to show what the petitioner actually intends to undertake.

·        Job title as evidence. A senior title, years of experience or employment at a respected company may help establish the person’s background, but they do not by themselves establish national importance.

·        Field-level importance substituted for endeavor-level impact. Government reports showing that cybersecurity is important are context, not a substitute for showing what this professional’s endeavor will accomplish.

·        Recommendation letters without independent detail. Praise is most useful when the writer explains specific work, results, expertise and why the proposed future activities matter beyond the immediate employer or client.

·        Vague future plans. Statements such as “I will build a nationwide cybersecurity platform” are difficult to evaluate unless the petition explains the technology, intended users, implementation pathway, resources and evidence supporting the plan.

·        A weak bridge between past and future. A strong employment record does not automatically establish that the individual is well positioned to pursue a different or materially broader endeavor. The petition should explain the continuity between prior achievements and the proposed work.

·        Claims of impact without objective support. Whenever the petition claims cost savings, adoption, job creation, improved resilience or sector-wide influence, the supporting record should show where those assertions come from.

Hypothetical Case Study: An OT Cybersecurity Professional

Assume a fictional professional, Maya Rao, with eleven years of OT cybersecurity experience. Her record includes securing industrial control environments, leading segmentation and incident-response work, and receiving recognition for a deployment. She proposes to improve the resilience of industrial control environments used in essential services in the United States.

Under the first Dhanasar prong, the case would need more than a statement that energy infrastructure is critical. The endeavor could be framed around developing and implementing interoperable resilience methods for a defined class of industrial environments, with evidence explaining the security problem, intended beneficiaries and plausible broader adoption. Government and technical sources could establish why the problem matters, but would not alone establish Maya’s endeavor as nationally important.[17]

Under the second prong, Maya could rely on project records showing comparable architecture work, implementation leadership, measurable security results and responsibility for complex deployments. Certifications and recognition may support the record, but the key is the connection between that history and the proposed U.S. work.

Under the third prong, the petition would need to explain why requiring a particular employer-sponsored position and labor certification could limit or delay the way Maya’s proposed work would be carried out, while avoiding the unsupported claim that the labor market lacks cybersecurity professionals. The focus should remain on the particular endeavor, its prospective value and the policy reason to permit the professional to pursue it without the ordinary job-offer requirement. None of these facts would guarantee approval. They would simply create a record capable of being assessed under Dhanasar.

Pre-Filing Information Checklist

Before filing, the record should be assembled around the proposed endeavor rather than around a generic collection of credentials.

·        Current CV and a clear chronology of relevant projects, roles and technical responsibilities.

·        Academic records and evidence supporting the underlying EB-2 classification.

·        Professional certifications, memberships and leadership roles that are relevant to the endeavor.

·        Detailed project evidence showing what the professional personally accomplished and what changed as a result.

·        A specific proposed endeavor narrative explaining the problem, activities, beneficiaries, prospective impact and implementation pathway.

·        Objective evidence supporting claimed outcomes, adoption, influence, economic effects, resilience improvements or other benefits.

·        Recommendation or expert evidence that is specific, sourced and tied to the proposed endeavor.

·        Awards, publications, patents, speaking, standards or similar evidence where genuinely relevant.

·        Prospective U.S. plans, including credible evidence of projects, collaborators, funding, commercialization or other implementation steps where available.

·        Government and industry sources that establish the problem being addressed, without relying on them as proof of the petitioner’s individual national importance.

What Should Be Done

The useful preparation step is to define the proposed endeavor before selecting evidence. Map the record to each Dhanasar prong, select past achievements for their connection to future work, and use independent evidence to corroborate claimed results. This avoids presenting an impressive résumé without a coherent national-interest theory.

The same discipline should apply to recommendation letters and supporting publications. A letter should identify the specific work, explain why it was significant, and connect that work to the proposed endeavor. A research paper or government report should be used to establish a proposition it actually supports. USCIS decisions repeatedly caution against generalized assertions that do not show how the petitioner’s specific endeavor produces the claimed broader effect.[18]

When Professional Advice Becomes Necessary

Case-specific legal review becomes particularly important where the underlying EB-2 classification is uncertain, the proposed endeavor differs substantially from past work, the future plan depends on entrepreneurship or multiple projects, or confidential employer material is involved. The legal and evidentiary issues should be assessed against current USCIS guidance and the facts available at filing.

Conclusion

For a cybersecurity professional, the central NIW question is not whether cybersecurity matters to the United States. Government and technical sources establish that context. The harder issue is applicant-specific: what is the proposed endeavor, what problem will it address, what prospective impact could it have, and why is this professional well positioned to advance it?

An industry-based profile need not resemble an academic résumé. Project results, engineering responsibility, critical-sector deployments, measurable outcomes, standards participation, professional recognition and credible plans may all be relevant. The stronger analytical approach is to connect them in one chain: a defined problem, a specific endeavor, the petitioner’s ability to advance it, and the reasons the waiver itself would benefit the United States.

FAQs

Can cybersecurity professionals qualify for EB-2 NIW?

Potentially, yes, but there is no occupation-based automatic entitlement. The professional must first satisfy the underlying EB-2 classification and then satisfy the Dhanasar framework. Cybersecurity experience may provide valuable evidence, but the proposed endeavor still has to be evaluated on its own terms.

Do I need publications or academic citations for a cybersecurity NIW?

No general rule requires publications or citations. They can be relevant where they demonstrate expertise, dissemination, influence or contribution connected to the proposed endeavor. For an operational professional, project evidence and measurable outcomes may be more directly probative.

Can an IT professional pursue an EB-2 NIW?

Yes, an IT professional may seek an NIW if the underlying EB-2 requirements and the Dhanasar framework are satisfied. USCIS has, however, repeatedly distinguished between the importance of information technology as a field and the national importance of a specific proposed endeavor.

Can an EB-2 NIW be filed without a U.S. employer?

Yes. The NIW framework can waive the ordinary job-offer and labor-certification requirements, and USCIS permits an individual seeking the NIW to file on their own behalf. The waiver still requires satisfaction of the underlying EB-2 classification and the Dhanasar criteria.

Does critical-infrastructure experience help in a cybersecurity NIW case?

It can help by providing relevant context and evidence of work addressing nationally significant systems. It does not automatically establish national importance. The petition should explain what the professional proposes to do, why the work has prospective impact and how the evidence shows that impact could extend beyond one employer or customer.

Can CISSP, CISM, CISA or similar certifications support a cybersecurity NIW case?

They can support the professional record, particularly on knowledge, training and professional standing. They are not, by themselves, proof that a proposed endeavor is nationally important or that the NIW should be granted.

What is a proposed endeavor for a cybersecurity professional?

It is the specific work the professional proposes to undertake in the United States. It should be more precise than an occupational label and should identify the problem, activities, intended beneficiaries and plausible prospective impact that USCIS can evaluate.

Does working in OT or ICS make an NIW case nationally important?

Not automatically. OT and ICS work can involve energy, manufacturing, transportation, water and other environments where cybersecurity intersects with safety and operational continuity. Those facts can strengthen the factual context, but the professional still must connect them to the specific proposed endeavor and the Dhanasar standard.

Disclaimer

This article is for general informational purposes only and does not constitute legal advice. EB-2 and National Interest Waiver eligibility depends on the individual facts, the evidence available and the U.S. immigration law and USCIS policy applicable at the time of filing and adjudication.


[1]Matter of Dhanasar, 26 I&N Dec. 884, 889-91 (AAO 2016).

[2]Matter of Dhanasar, 26 I&N Dec. 884, 889-90 (AAO 2016).

[3]Matter of Dhanasar, 26 I&N Dec. 884, 890 (AAO 2016).

[4]Matter of Dhanasar, 26 I&N Dec. 884, 890-91 (AAO 2016).

[5]Cybersecurity and Infrastructure Security Agency, Critical Infrastructure Security and Resilience; Information Technology Sector.

[6]Stouffer, K., Pease, M., Tang, C.Y., Zimmerman, T., Pillitteri, V., Lightman, S., Hahn, A., Saravia, S., Sherule, A., & Thompson, M., Guide to Operational Technology (OT) Security, NIST Special Publication 800-82 Rev. 3 (2023).

[7]Cybersecurity and Infrastructure Security Agency, Cross-Sector Cybersecurity Performance Goals; National Institute of Standards and Technology, The NIST Cybersecurity Framework (CSF) 2.0 (2024).

[8]U.S. Government Accountability Office, Cybersecurity Regulations: Additional Industry Perspectives on the Impact, Progress, Challenges, and Opportunities of Harmonization, GAO-26-108685 (Mar. 5, 2026); U.S. Government Accountability Office, Cybersecurity: Improvements Needed in Addressing Risks to Operational Technology, GAO-24-106576 (Mar. 7, 2024).

[9]M. S. Abou-Zeid et al., A Survey on Cyber Resilience: Key Strategies, Research Challenges, and Future Directions, ACM Computing Surveys, Vol. 56, Issue 8, Article 196 (2024), doi:10.1145/3649218; A. Kok, A. Martinetti & A. Braaksma, The Impact of Integrating Information Technology With Operational Technology in Physical Assets: A Literature Review, IEEE Access 12, 111832-111845 (2024), doi:10.1109/ACCESS.2024.3442443.

[10]U.S. Citizenship and Immigration Services, Administrative Appeals Office, Non-Precedent Decision, Form I-140, National Interest Waiver, July 11, 2023, JUL112023_06B5203.

[11]U.S. Citizenship and Immigration Services, Administrative Appeals Office, Non-Precedent Decision, Form I-140, National Interest Waiver, Apr. 3, 2024, APR032024_02B5203.

[12]U.S. Citizenship and Immigration Services, Administrative Appeals Office, Non-Precedent Decision, In Re: 37136795, Mar. 11, 2025, Form I-140, National Interest Waiver.

[13]Stouffer et al., Guide to Operational Technology (OT) Security, NIST Special Publication 800-82 Rev. 3 (2023).

[14]A. Kok, A. Martinetti & A. Braaksma, The Impact of Integrating Information Technology With Operational Technology in Physical Assets: A Literature Review, IEEE Access 12, 111832-111845 (2024), doi:10.1109/ACCESS.2024.3442443; V. Maslenkov, et al., A Systematic Literature Review of Current Research Trends in Operational and Related Technology Threats, Threat Detection, and Security Insurance, Applied Sciences 15(5), 2316 (2025).

[15]National Institute of Standards and Technology, SP 800-82 Rev. 4, Guide to Operational Technology (OT) Security, Initial Public Draft (Sept. 21, 2026).

[16]U.S. Citizenship and Immigration Services, PA-2025-03, Second Preference Eligibility for National Interest Waiver Petitions, at 19 (Jan. 15, 2025).

[17]See Cybersecurity and Infrastructure Security Agency, Cross-Sector Cybersecurity Performance Goals; U.S. Department of Energy, Cybersecurity for the Operational Technology Environment (CyOTE); National Institute of Standards and Technology, SP 800-82 Rev. 3.

[18]See U.S. Citizenship and Immigration Services, Administrative Appeals Office, Non-Precedent Decision, Sept. 26, 2023, SEP262023_06B5203.

Author
About the Author: SolvLegal Team

The SolvLegal Team is a collective of legal professionals dedicated to making legal information accessible and easy to understand. We provide expert advice and insights to help you navigate the complexities of the law with confidence.

Leave a Comment