Stay informed as the Information Technology Laboratory’s Cybersecurity and Privacy Program releases publications, schedules virtual and in-person events, and announces other important developments.
Subscribe to our email updates.
Visit these additional NIST sites to learn more about:
To help strengthen the security and resilience of global supply chains, the NIST National Cybersecurity Center of Excellence (NCCoE) has released the finalized version of NIST Internal Report 8536, Supply Chain Traceability Principles: A Manufacturing Meta-Framework, which provides an interoperable, industry-neutral framework to securely exchange and verify traceability information across supply chains while enabling organizations to continue using existing industry standards.
NIST has released a draft revision of Special Publication (SP) 800-38E, which approves the XTS-AES mode of operation for protecting the confidentiality of data on storage devices. Revision 1 updates the referenced specification to IEEE Std. 1619-2025 and clarifies NIST’s requirements for the approved use of XTS-AES, including its scope of use, data-unit and key-scope limits, key requirements, and the ordering convention for ciphertext stealing.
NIST announces the publication of NIST Internal Report (IR) 8615, Workshop on Rolling Next-Generation Secure Hardware into Standards.
NIST is initiating a revision of Special Publication (SP) 800-213A, Internet of Things (IoT) Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, and has posted a Pre-Draft Call for Comments. This update aims to incorporate lessons learned, align with recent frameworks like CSF 2.0 and SP 800-53 Rev. 5.2.0, and address the evolving IoT threat landscape. This follows the draft update to SP 800-213 Rev. 1.
NIST has released Internal Report (IR) 8611, m-NGAC: Transcending Traditional Database Security Models.
The final version of NIST Special Publication (SP) 1347, NIST Cybersecurity Framework (CSF) 2.0: Informative References Quick-Start Guide, is now available
NIST IR 8613 ipd, Multi-Cloud Architecture Challenges, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis addresses security and ATO challenges and highlights areas where additional community research could meaningfully reduce risk.
NIST has released the initial public draft of Special Publication (SP) 1353, Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting. The public comment period is open through October 15, 2026.
The NIST National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft Cybersecurity White Paper (CSWP) 36F, Initial Non-Access Stratum (NAS) Message Security, which describes a 5G security feature that protects sensitive information in the Initial Non-Access Stratum (NAS) Message and explains how organizations can verify these protections in deployed 5G networks.
NIST's NCCoE announces the release of the final NIST Interagency Report (IR) 8576, Transit Cybersecurity Framework (CSF) Community Profile.
NIST invites public comments on the initial public draft (ipd) of Special Publication (SP) 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach. The public comment period is open through September 25, 2026.
The initial public draft (ipd) of NIST Special Publication (SP) 800-209r1, Security Guidelines for Storage Infrastructure, is now available for public comment through September 8, 2026.
This Quick-Start Guide based on the widely adopted content in NIST SP 800-161r1 proposes an implementation-ready approach to conducting the minimum amount of reasonable research and investigative rigor on potential suppliers.
NIST has released Special Publication (SP) 800-18r2 (Revision 2), Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems. This revision broadens the scope of system planning to encompass three interconnected plan types that are collectively referred to as "system plans". Essential system plan elements are correlated with the steps and tasks of the NIST Risk Management Framework (RMF) to provide a streamlined approach to system plan development.
The NCCoE is seeking feedback on the draft Project Description Asset Management as a Foundation for OT Cybersecurity , outlining the proposed scope, challenges, and technical approach for the project.
The NIST National Cybersecurity Center of Excellence (NCCoE) has released the final version of NIST Special Publication 1800-45, "Cybersecurity for the Water and Wastewater Sector: Build Architecture", demonstrating how to securely enable remote access to operational technology for critical infrastructure.
The NIST Cybersecurity for IoT Program has released the initial public draft of Special Publication (SP) 800-213r1 (Revision 1), "IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements." The public comment period ends August 24, 2026.
NIST requests comments on the initial public draft (ipd) of Special Publication (SP) 800-219r2 (Revision 2), Automated Secure Configuration Guidance From the macOS Security Compliance Project (mSCP).
NIST publishes NIST Internal Report (IR) 8618, Summary Report for “Cybersecurity for IoT Workshop: Future Directions”.
The NIST National Cybersecurity Center of Excellence (NCCoE) has published NIST Special Publication (SP) 1339, Operational Technology Backup Quick Start Guide
NIST has released initial working drafts of proposed updates to the PIV standards, including an overview of expected changes to support post-quantum cryptography in PIV credentials.
NIST IR 8374r1, "Ransomware Risk Management: A Cybersecurity Framework (CSF) 2.0 Community Profile," is now available.
NIST announces the release of Special Publication (SP) 800-126r4 (Revision 4), Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.4, and SP 800-126Ar4, SCAP 1.4 Component Specification Version Updates: An Annex to NIST SP 800-126r4.
NIST is revising Special Publication 800-38D, Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC. The public comment period is open through July 31, 2026.
NIST Interagency Report (NIST IR) 8320E ipd (initial public draft), Hardware-Enabled Security: Confidential Computing of Data in Cloud Workloads, is open for public comment through July 13, 2026.
* "Relevance" merely indicates the search engine's score for a document. It is based on the search parameters and information in the document's detailed record.