﻿{
  "title": "NIST Draft Publications Open for Comment",
  "subtitle": "Many of NIST's cybersecurity and privacy publications are posted as drafts for public comment. Comment periods are still open for the following publications. Visit the links for downloads, related content, and instructions for submitting comments. Your thoughtful reviews and comments are greatly appreciated and help us to improve our standards and guidance.",
  "updated": "2026-08-12T05:00:39.4952179-04:00",
  "id": "https://csrc.nist.gov/csrc/media/feeds/pubs/drafts-open-for-comment.xml",
  "link": "https://csrc.nist.gov/publications/drafts-open-for-comment",
  "entries": [
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/73/pt1/6/iwd",
      "title": "SP 800-73-6, Interfaces for Personal Identity Verification: Part 1 – PIV Card Application Namespace, Data Model and RepresentationInitial Working Draft",
      "summary": "<p>NIST has released <a href=\"https://pages.nist.gov/piv-standards\">initial working drafts</a> of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism with PIV.<o></o></p>\n<p>The <a href=\"https://pages.nist.gov/piv-standards\">current draft set</a> comprises:<o></o></p>\n<ul>\n<li>SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation<o></o></li>\n<li>SP 800-73 Part 2: PIV Card Application Card Command Interface<o></o></li>\n<li>SP 800-78: Cryptographic Algorithms and Key Sizes for PIV<o></o></li>\n</ul>\n<p>A supporting PQC Overview accompanies the drafts to present a working gap analysis of the specification changes needed across the PIV algorithm profile, command interface, and data model, and outline the general approach under consideration. This approach centers on a dual-stack model that preserves existing classical PIV keys and data objects; adds new key references, certificate containers, and data objects for PQC credentials; and supports backward compatibility and incremental deployment during the transition.<o></o></p>\n<p>These are preliminary working materials, not formal public drafts. By collaborating with implementers and users to develop these guidelines and specifications, NIST hopes to accelerate the standardization and implementation of PQC in PIV credentials.<o></o></p>\n<p>NIST welcomes feedback throughout the development process. Interested parties can follow the work and participate by:<o></o></p>\n<ul>\n<li><strong>Joining the public mailing list</strong> &mdash; Subscribe at <a href=\"mailto:piv-standards+subscribe@list.nist.gov\">piv-standards+subscribe@list.nist.gov</a>,&nbsp;and take part in discussions at <a href=\"mailto:piv-standards@list.nist.gov\">piv-standards@list.nist.gov</a>&nbsp;(<a href=\"https://groups.google.com/a/list.nist.gov/g/piv-standards\">archive</a>).<o></o></li>\n<li><a href=\"https://github.com/usnistgov/piv-standards\"><strong>Engaging on GitHub</strong></a> &mdash; Review the drafts, file issues, or open pull requests at the project repository.<o></o></li>\n</ul>",
      "published": "2026-06-12T00:00:00",
      "updated": "2026-06-12T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/73/pt1/6/iwd",
      "content": "No Due Date: Comment Period Remains Open"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/73/pt2/6/iwd",
      "title": "SP 800-73-6, Interfaces for Personal Identity Verification: Part 2 – PIV Card Application Card Command InterfaceInitial Working Draft",
      "summary": "<p>NIST has released <a href=\"https://pages.nist.gov/piv-standards\">initial working drafts</a> of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism with PIV.<o></o></p>\n<p>The <a href=\"https://pages.nist.gov/piv-standards\">current draft set</a> comprises:<o></o></p>\n<ul>\n<li>SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation<o></o></li>\n<li>SP 800-73 Part 2: PIV Card Application Card Command Interface<o></o></li>\n<li>SP 800-78: Cryptographic Algorithms and Key Sizes for PIV<o></o></li>\n</ul>\n<p>A supporting PQC Overview accompanies the drafts to present a working gap analysis of the specification changes needed across the PIV algorithm profile, command interface, and data model, and outline the general approach under consideration. This approach centers on a dual-stack model that preserves existing classical PIV keys and data objects; adds new key references, certificate containers, and data objects for PQC credentials; and supports backward compatibility and incremental deployment during the transition.<o></o></p>\n<p>These are preliminary working materials, not formal public drafts. By collaborating with implementers and users to develop these guidelines and specifications, NIST hopes to accelerate the standardization and implementation of PQC in PIV credentials.<o></o></p>\n<p>NIST welcomes feedback throughout the development process. Interested parties can follow the work and participate by:<o></o></p>\n<ul>\n<li><strong>Joining the public mailing list</strong> &mdash; Subscribe at <a href=\"mailto:piv-standards+subscribe@list.nist.gov\">piv-standards+subscribe@list.nist.gov</a>,&nbsp;and take part in discussions at <a href=\"mailto:piv-standards@list.nist.gov\">piv-standards@list.nist.gov</a>&nbsp;(<a href=\"https://groups.google.com/a/list.nist.gov/g/piv-standards\">archive</a>).<o></o></li>\n<li><a href=\"https://github.com/usnistgov/piv-standards\"><strong>Engaging on GitHub</strong></a> &mdash; Review the drafts, file issues, or open pull requests at the project repository.<o></o></li>\n</ul>",
      "published": "2026-06-12T00:00:00",
      "updated": "2026-06-12T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/73/pt2/6/iwd",
      "content": "No Due Date: Comment Period Remains Open"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/78/6/iwd",
      "title": "SP 800-78-6, Cryptographic Algorithms and Key Sizes for Personal Identity VerificationInitial Working Draft",
      "summary": "<p>NIST has released <a href=\"https://pages.nist.gov/piv-standards\">initial working drafts</a> of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism with PIV.<o></o></p>\n<p>The <a href=\"https://pages.nist.gov/piv-standards\">current draft set</a> comprises:<o></o></p>\n<ul>\n<li>SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation<o></o></li>\n<li>SP 800-73 Part 2: PIV Card Application Card Command Interface<o></o></li>\n<li>SP 800-78: Cryptographic Algorithms and Key Sizes for PIV<o></o></li>\n</ul>\n<p>A supporting PQC Overview accompanies the drafts to present a working gap analysis of the specification changes needed across the PIV algorithm profile, command interface, and data model, and outline the general approach under consideration. This approach centers on a dual-stack model that preserves existing classical PIV keys and data objects; adds new key references, certificate containers, and data objects for PQC credentials; and supports backward compatibility and incremental deployment during the transition.<o></o></p>\n<p>These are preliminary working materials, not formal public drafts. By collaborating with implementers and users to develop these guidelines and specifications, NIST hopes to accelerate the standardization and implementation of PQC in PIV credentials.<o></o></p>\n<p>NIST welcomes feedback throughout the development process. Interested parties can follow the work and participate by:<o></o></p>\n<ul>\n<li><strong>Joining the public mailing list</strong> &mdash; Subscribe at <a href=\"mailto:piv-standards+subscribe@list.nist.gov\">piv-standards+subscribe@list.nist.gov</a>,&nbsp;and take part in discussions at <a href=\"mailto:piv-standards@list.nist.gov\">piv-standards@list.nist.gov</a>&nbsp;(<a href=\"https://groups.google.com/a/list.nist.gov/g/piv-standards\">archive</a>).<o></o></li>\n<li><a href=\"https://github.com/usnistgov/piv-standards\"><strong>Engaging on GitHub</strong></a> &mdash; Review the drafts, file issues, or open pull requests at the project repository.<o></o></li>\n</ul>",
      "published": "2026-06-12T00:00:00",
      "updated": "2026-06-12T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/78/6/iwd",
      "content": "No Due Date: Comment Period Remains Open"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/219/r2/ipd",
      "title": "SP 800-219 Rev. 2, Automated Secure Configuration Guidance from the macOS Security Compliance Project (mSCP)Initial Public Draft",
      "summary": "<p>This publication provides resources for assessing macOS desktop and laptop, iOS, and visionOS system security in an automated way, including up-to-date and practical recommendations (i.e., secure baselines and associated rules) that are available on the mSCP GitHub site. It also describes use cases for leveraging the mSCP content. Updates from the previous version of this publication highlight the mSCP&rsquo;s next generation of improvements, including simpler OS version and rule management as well as an expanded audience.<o></o></p>\n<p><strong>The public comment period is open from June 22 through August 14, 2026.</strong>&nbsp;See the publication details for a copy of the draft and instructions for submitting comments.<o></o></p>\n<p><br><em>NOTE: A call for patent claims is included on page ii of this draft.</em>&nbsp;<em>For additional information, see the&nbsp;</em><a href=\"https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Flinks-1.govdelivery.com%2FCL0%2Fhttps%3A%252F%252Fwww.nist.gov%252Fitl%252Fpublications-0%252Fitl-patent-policy-inclusion-patents-itl-publications%2F1%2F0100019ed26e96a2-1ebdd07a-5e88-4a54-b805-31d702b17faf-000000%2FoAwD9AzzSSCkdHoKcbNNgMyym6ozi1KPbgIyvJBEJtA%3D452&amp;data=05%7C02%7Cisabel.vanwyk%40nist.gov%7Cfeb9938caeba493248d808decbf2de19%7C2ab5d82fd8fa4797a93e054655c61dec%7C0%7C0%7C639172441123942040%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=b1jTDPbNrTuL8SGJDkMBQrY%2Ftpzs1qhRqS8HQ6nxdDg%3D&amp;reserved=0\"><em>Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications</em></a><em>.</em><o></o></p>",
      "published": "2026-06-22T00:00:00",
      "updated": "2026-06-22T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/219/r2/ipd",
      "content": "Comments Due 08/14/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/213/r1/ipd",
      "title": "SP 800-213 Rev. 1, IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity RequirementsInitial Public Draft",
      "summary": "<p>Organizations increasingly use Internet of Things (IoT) products for the mission benefits they offer, but care must be taken in acquiring and implementing this equipment.&nbsp;<o></o></p>\n<p>NIST is updating guidelines for establishing cybersecurity requirements for IoT products to support necessary security controls. Understanding that an IoT product is a system element facilitates an understanding of how it must be considered in the risk management process. The acquisition and integration of an IoT product into an information system may alter the system&rsquo;s risk assessment based on new risks introduced by the product. An updated risk assessment may require additional or new controls to be selected and implemented in the system. This publication provides general considerations of how IoT products may impact an information system&rsquo;s risk assessment and subsequent allocation of controls that may be necessary.<o></o></p>\n<p></p>\n<p><em>NOTE: A call for patent claims is included on page iii of this draft.</em>&nbsp;<em>For additional information, see the&nbsp;</em><a href=\"https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Flinks-1.govdelivery.com%2FCL0%2Fhttps%3A%252F%252Fwww.nist.gov%252Fitl%252Fpublications-0%252Fitl-patent-policy-inclusion-patents-itl-publications%2F1%2F0100019ed26e96a2-1ebdd07a-5e88-4a54-b805-31d702b17faf-000000%2FoAwD9AzzSSCkdHoKcbNNgMyym6ozi1KPbgIyvJBEJtA%3D452&amp;data=05%7C02%7Cisabel.vanwyk%40nist.gov%7Cfeb9938caeba493248d808decbf2de19%7C2ab5d82fd8fa4797a93e054655c61dec%7C0%7C0%7C639172441123942040%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=b1jTDPbNrTuL8SGJDkMBQrY%2Ftpzs1qhRqS8HQ6nxdDg%3D&amp;reserved=0\"><em>Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications</em></a><em>.</em></p>",
      "published": "2026-06-24T00:00:00",
      "updated": "2026-06-24T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/213/r1/ipd",
      "content": "Comments Due 08/24/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/cswp/36/f/initial-nas-message-security-applying-5g-cybersecu/ipd",
      "title": "CSWP 36F, Initial NAS Message Security: Applying 5G Cybersecurity and Privacy CapabilitiesInitial Public Draft",
      "summary": "<p>This NIST Cybersecurity White Paper describes a 5G security feature that protects sensitive information in the Initial Non-Access Stratum (NAS) Message and explains how organizations can verify these protections in deployed 5G networks.<o></o></p>\n<p>This white paper is part of the NCCoE&rsquo;s work to accelerate the adoption of 5G security features by demonstrating their implementation on our operational 5G security testbed and providing actionable implementation guidelines to help network operators enhance the cybersecurity and privacy of 5G systems and supporting infrastructures.&nbsp;<o></o></p>\n<h5><b>Background<o></o></b></h5>\n<p>Current 5G standards include specifications to address cybersecurity and privacy challenges present in previous generations of cellular systems. In 4G, the initial handshake message used to establish a connection between the device and the network&mdash;the Initial NAS Message&mdash;was sent without encryption or integrity protection. This leaves the 4G user device and the core network vulnerable to man-in-the-middle attacks.<o></o></p>\n<p>Current 5G specifications allow the device to send the security-sensitive contents of the initial NAS message in an encrypted and integrity protected form.<o></o></p>\n<p>This White Paper describes how the NCCoE demonstrated these capabilities and explains how organizations can verify these protections in deployed 5G networks to protect the security and privacy on their networks.&nbsp;<o></o></p>\n<p>By demonstrating security features on our operational 5G Testbed, we aim to deliver real-world implementation insights to advance 5G security and inform the next generation of wireless security.&nbsp; <o></o></p>\n<h5><b>Submit Your Feedback!<o></o></b></h5>\n<p>This White Paper is available for public comment through <strong>September 7, 2026</strong>. Visit the <a href=\"https://www.nccoe.nist.gov/5g-cybersecurity\">NCCoE 5G Cybersecurity</a> project page to learn more and download the White Paper today!</p>",
      "published": "2026-08-06T00:00:00",
      "updated": "2026-08-06T00:00:00",
      "link": "https://csrc.nist.gov/pubs/cswp/36/f/initial-nas-message-security-applying-5g-cybersecu/ipd",
      "content": "Comments Due 09/07/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/209/r1/ipd",
      "title": "SP 800-209 Rev. 1, Security Guidelines for Storage InfrastructureInitial Public Draft",
      "summary": "<p>Storage technology has evolved in two primary directions: (1) increased media storage capacity and (2) architectural changes that provide a software-based abstraction over all forms of background storage technologies. However, the latter evolution has increased management complexity and the probability of configuration errors and associated security threats. This document traces the evolution of the storage technology landscape and analyzes current security threats and resultant risks to provide a comprehensive set of security recommendations in the form of storage security controls.&nbsp;</p>\n<p>Important updates in this revision of SP 800-209 include:</p>\n<ul>\n<li><strong>Section 2</strong> &mdash; Removal of content associated with obsolete and/or proprietary technologies.</li>\n<li><strong>Section 3 </strong>&mdash; Completely revised to primarily focus on threats and risks that are specific to storage systems and ecosystems. References to other NIST publications are provided for generic ICT threats and risks. Two notable focus areas were also added:\n<ul>\n<li>&ldquo;Platform Security Compromises&rdquo; &mdash; Focuses on threats associated with the underlying/supporting infrastructure for data storage</li>\n<li>&ldquo;Compromised Data Resilience/Protection&rdquo; &mdash; Focuses on threats to secondary data assets and the secondary data asset generation process (i.e., backups)</li>\n</ul>\n</li>\n<li><strong>Section 4</strong> &mdash; Retitled as &ldquo;Storage Security Controls.&rdquo; The security recommendations have been reorganized from nine categories into seven formalized control families with standardized control acronyms.\n<ul>\n<li>Several new control families have been added, and some existing controls have been consolidated under new control families to provide coverage for all threats and risks covered in previous sections.</li>\n</ul>\n</li>\n<li><strong>Appendix C</strong> &mdash; Added to provide a complete list of the storage security controls described in Sec. 4 as well as a mapping of mitigating controls for the storage-oriented threats identified in Sec. 3.</li>\n</ul>\n<p><span style=\"font-size: 10pt;\"><i>NOTE: A call for patent claims is included in this draft. For additional information, see the </i><a href=\"https://www.nist.gov/itl/publications-0/itl-patent-policy-inclusion-patents-itl-publications\"><i>Information Technology Laboratory (ITL)&nbsp;Patent Policy &ndash; Inclusion of Patents in ITL Publications</i></a>.</span></p>",
      "published": "2026-07-22T00:00:00",
      "updated": "2026-07-22T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/209/r1/ipd",
      "content": "Comments Due 09/08/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/239/ipd",
      "title": "SP 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven ApproachInitial Public Draft",
      "summary": "<p>Building upon established principles from high-performance computing (HPC) threat analyses and security overlays, this publication delivers a thorough threat and security gap analysis for purpose-built AI infrastructure used in model training, inference, and applications. By contrasting AI data centers with traditional HPC systems across architecture, hardware, software stacks, workflows, and storage systems, the publication pinpoints critical security threats and outlines possible solutions to safeguard next-generation AI environments.<o></o></p>\n<p><span style=\"font-size: 10pt;\"><em>NOTE: A call for patent claims is included in this draft.</em>&nbsp;<em>For additional information, see the&nbsp;</em><a href=\"https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Flinks-1.govdelivery.com%2FCL0%2Fhttps%3A%252F%252Fwww.nist.gov%252Fitl%252Fpublications-0%252Fitl-patent-policy-inclusion-patents-itl-publications%2F1%2F0100019ed26e96a2-1ebdd07a-5e88-4a54-b805-31d702b17faf-000000%2FoAwD9AzzSSCkdHoKcbNNgMyym6ozi1KPbgIyvJBEJtA%3D452&amp;data=05%7C02%7Cisabel.vanwyk%40nist.gov%7Cfeb9938caeba493248d808decbf2de19%7C2ab5d82fd8fa4797a93e054655c61dec%7C0%7C0%7C639172441123942040%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;sdata=b1jTDPbNrTuL8SGJDkMBQrY%2Ftpzs1qhRqS8HQ6nxdDg%3D&amp;reserved=0\"><em>Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications</em></a><em>.</em></span></p>",
      "published": "2026-07-27T00:00:00",
      "updated": "2026-07-27T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/239/ipd",
      "content": "Comments Due 09/25/2026"
    }
  ]
}