﻿<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title type="text">NIST Draft Publications Open for Comment</title>
  <subtitle type="text">Many of NIST's cybersecurity and privacy publications are posted as drafts for public comment. Comment periods are still open for the following publications. Visit the links for downloads, related content, and instructions for submitting comments. Your thoughtful reviews and comments are greatly appreciated and help us to improve our standards and guidance.</subtitle>
  <id>https://csrc.nist.gov/CSRC/media/feeds/pubs/drafts-open-for-comment.xml</id>
  <updated>2026-09-12T09:00:42Z</updated>
  <logo>https://csrc.nist.gov/CSRC/Media/images/CSRC-white-134-38.png</logo>
  <link rel="alternate" href="https://csrc.nist.gov/publications/drafts-open-for-comment" />
  <entry>
    <id>https://csrc.nist.gov/pubs/sp/800/73/pt1/6/iwd</id>
    <title type="text">SP 800-73-6, Interfaces for Personal Identity Verification: Part 1 – PIV Card Application Namespace, Data Model and RepresentationInitial Working Draft</title>
    <summary type="text">&lt;p&gt;NIST has released &lt;a href="https://pages.nist.gov/piv-standards"&gt;initial working drafts&lt;/a&gt; of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism with PIV.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://pages.nist.gov/piv-standards"&gt;current draft set&lt;/a&gt; comprises:&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;SP 800-73 Part 2: PIV Card Application Card Command Interface&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;SP 800-78: Cryptographic Algorithms and Key Sizes for PIV&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A supporting PQC Overview accompanies the drafts to present a working gap analysis of the specification changes needed across the PIV algorithm profile, command interface, and data model, and outline the general approach under consideration. This approach centers on a dual-stack model that preserves existing classical PIV keys and data objects; adds new key references, certificate containers, and data objects for PQC credentials; and supports backward compatibility and incremental deployment during the transition.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;These are preliminary working materials, not formal public drafts. By collaborating with implementers and users to develop these guidelines and specifications, NIST hopes to accelerate the standardization and implementation of PQC in PIV credentials.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;NIST welcomes feedback throughout the development process. Interested parties can follow the work and participate by:&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Joining the public mailing list&lt;/strong&gt; &amp;mdash; Subscribe at &lt;a href="mailto:piv-standards+subscribe@list.nist.gov"&gt;piv-standards+subscribe@list.nist.gov&lt;/a&gt;,&amp;nbsp;and take part in discussions at &lt;a href="mailto:piv-standards@list.nist.gov"&gt;piv-standards@list.nist.gov&lt;/a&gt;&amp;nbsp;(&lt;a href="https://groups.google.com/a/list.nist.gov/g/piv-standards"&gt;archive&lt;/a&gt;).&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/usnistgov/piv-standards"&gt;&lt;strong&gt;Engaging on GitHub&lt;/strong&gt;&lt;/a&gt; &amp;mdash; Review the drafts, file issues, or open pull requests at the project repository.&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;/ul&gt;</summary>
    <published>2026-06-12T00:00:00-04:00</published>
    <updated>2026-06-12T00:00:00-04:00</updated>
    <link href="https://csrc.nist.gov/pubs/sp/800/73/pt1/6/iwd" />
    <content type="text">No Due Date: Comment Period Remains Open</content>
  </entry>
  <entry>
    <id>https://csrc.nist.gov/pubs/sp/800/73/pt2/6/iwd</id>
    <title type="text">SP 800-73-6, Interfaces for Personal Identity Verification: Part 2 – PIV Card Application Card Command InterfaceInitial Working Draft</title>
    <summary type="text">&lt;p&gt;NIST has released &lt;a href="https://pages.nist.gov/piv-standards"&gt;initial working drafts&lt;/a&gt; of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism with PIV.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://pages.nist.gov/piv-standards"&gt;current draft set&lt;/a&gt; comprises:&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;SP 800-73 Part 2: PIV Card Application Card Command Interface&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;SP 800-78: Cryptographic Algorithms and Key Sizes for PIV&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A supporting PQC Overview accompanies the drafts to present a working gap analysis of the specification changes needed across the PIV algorithm profile, command interface, and data model, and outline the general approach under consideration. This approach centers on a dual-stack model that preserves existing classical PIV keys and data objects; adds new key references, certificate containers, and data objects for PQC credentials; and supports backward compatibility and incremental deployment during the transition.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;These are preliminary working materials, not formal public drafts. By collaborating with implementers and users to develop these guidelines and specifications, NIST hopes to accelerate the standardization and implementation of PQC in PIV credentials.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;NIST welcomes feedback throughout the development process. Interested parties can follow the work and participate by:&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Joining the public mailing list&lt;/strong&gt; &amp;mdash; Subscribe at &lt;a href="mailto:piv-standards+subscribe@list.nist.gov"&gt;piv-standards+subscribe@list.nist.gov&lt;/a&gt;,&amp;nbsp;and take part in discussions at &lt;a href="mailto:piv-standards@list.nist.gov"&gt;piv-standards@list.nist.gov&lt;/a&gt;&amp;nbsp;(&lt;a href="https://groups.google.com/a/list.nist.gov/g/piv-standards"&gt;archive&lt;/a&gt;).&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/usnistgov/piv-standards"&gt;&lt;strong&gt;Engaging on GitHub&lt;/strong&gt;&lt;/a&gt; &amp;mdash; Review the drafts, file issues, or open pull requests at the project repository.&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;/ul&gt;</summary>
    <published>2026-06-12T00:00:00-04:00</published>
    <updated>2026-06-12T00:00:00-04:00</updated>
    <link href="https://csrc.nist.gov/pubs/sp/800/73/pt2/6/iwd" />
    <content type="text">No Due Date: Comment Period Remains Open</content>
  </entry>
  <entry>
    <id>https://csrc.nist.gov/pubs/sp/800/78/6/iwd</id>
    <title type="text">SP 800-78-6, Cryptographic Algorithms and Key Sizes for Personal Identity VerificationInitial Working Draft</title>
    <summary type="text">&lt;p&gt;NIST has released &lt;a href="https://pages.nist.gov/piv-standards"&gt;initial working drafts&lt;/a&gt; of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism with PIV.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://pages.nist.gov/piv-standards"&gt;current draft set&lt;/a&gt; comprises:&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;SP 800-73 Part 2: PIV Card Application Card Command Interface&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;SP 800-78: Cryptographic Algorithms and Key Sizes for PIV&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A supporting PQC Overview accompanies the drafts to present a working gap analysis of the specification changes needed across the PIV algorithm profile, command interface, and data model, and outline the general approach under consideration. This approach centers on a dual-stack model that preserves existing classical PIV keys and data objects; adds new key references, certificate containers, and data objects for PQC credentials; and supports backward compatibility and incremental deployment during the transition.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;These are preliminary working materials, not formal public drafts. By collaborating with implementers and users to develop these guidelines and specifications, NIST hopes to accelerate the standardization and implementation of PQC in PIV credentials.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;NIST welcomes feedback throughout the development process. Interested parties can follow the work and participate by:&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Joining the public mailing list&lt;/strong&gt; &amp;mdash; Subscribe at &lt;a href="mailto:piv-standards+subscribe@list.nist.gov"&gt;piv-standards+subscribe@list.nist.gov&lt;/a&gt;,&amp;nbsp;and take part in discussions at &lt;a href="mailto:piv-standards@list.nist.gov"&gt;piv-standards@list.nist.gov&lt;/a&gt;&amp;nbsp;(&lt;a href="https://groups.google.com/a/list.nist.gov/g/piv-standards"&gt;archive&lt;/a&gt;).&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/usnistgov/piv-standards"&gt;&lt;strong&gt;Engaging on GitHub&lt;/strong&gt;&lt;/a&gt; &amp;mdash; Review the drafts, file issues, or open pull requests at the project repository.&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;/ul&gt;</summary>
    <published>2026-06-12T00:00:00-04:00</published>
    <updated>2026-06-12T00:00:00-04:00</updated>
    <link href="https://csrc.nist.gov/pubs/sp/800/78/6/iwd" />
    <content type="text">No Due Date: Comment Period Remains Open</content>
  </entry>
  <entry>
    <id>https://csrc.nist.gov/pubs/sp/800/239/ipd</id>
    <title type="text">SP 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven ApproachInitial Public Draft</title>
    <summary type="text">&lt;p&gt;Building upon established principles from high-performance computing (HPC) threat analyses and security overlays, this publication delivers a thorough threat and security gap analysis for purpose-built AI infrastructure used in model training, inference, and applications. By contrasting AI data centers with traditional HPC systems across architecture, hardware, software stacks, workflows, and storage systems, the publication pinpoints critical security threats and outlines possible solutions to safeguard next-generation AI environments.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;&lt;em&gt;NOTE: A call for patent claims is included in this draft.&lt;/em&gt;&amp;nbsp;&lt;em&gt;For additional information, see the&amp;nbsp;&lt;/em&gt;&lt;a href="https://gcc02.safelinks.protection.outlook.com/?url=https%3A%2F%2Flinks-1.govdelivery.com%2FCL0%2Fhttps%3A%252F%252Fwww.nist.gov%252Fitl%252Fpublications-0%252Fitl-patent-policy-inclusion-patents-itl-publications%2F1%2F0100019ed26e96a2-1ebdd07a-5e88-4a54-b805-31d702b17faf-000000%2FoAwD9AzzSSCkdHoKcbNNgMyym6ozi1KPbgIyvJBEJtA%3D452&amp;amp;data=05%7C02%7Cisabel.vanwyk%40nist.gov%7Cfeb9938caeba493248d808decbf2de19%7C2ab5d82fd8fa4797a93e054655c61dec%7C0%7C0%7C639172441123942040%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=b1jTDPbNrTuL8SGJDkMBQrY%2Ftpzs1qhRqS8HQ6nxdDg%3D&amp;amp;reserved=0"&gt;&lt;em&gt;Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/span&gt;&lt;/p&gt;</summary>
    <published>2026-07-27T00:00:00-04:00</published>
    <updated>2026-07-27T00:00:00-04:00</updated>
    <link href="https://csrc.nist.gov/pubs/sp/800/239/ipd" />
    <content type="text">Comments Due 09/25/2026</content>
  </entry>
  <entry>
    <id>https://csrc.nist.gov/pubs/ir/8613/ipd</id>
    <title type="text">IR 8613, Multi-Cloud Architecture Challenges: Security and Compliance ImplicationsInitial Public Draft</title>
    <summary type="text">&lt;p&gt;NIST Internal Report (IR) 8613 ipd (initial public draft), &lt;i&gt;Multi-Cloud Architecture Challenges&lt;/i&gt;, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis by the NIST Multi-Cloud Security Public Working Group (MCSPWG) addresses security and Authorization to Operate (ATO) challenges&amp;nbsp;and highlights areas where additional community research could meaningfully reduce risk.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;The MCSPWG identified 23 consolidated challenge areas that represent novel friction points and architectural misalignments that emerge when orchestrating control across autonomous cloud silos. The most significant structural challenge areas are:&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Security-significant differences in cloud-native services across providers&lt;/li&gt;
&lt;li&gt;Organizational logistics and staffing complexity across heterogeneous environments&lt;/li&gt;
&lt;li&gt;Difficulty in implementing centralized security capabilities across provider boundaries&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These structural gaps are most acute in five areas: (1) identity and access management, (2) telemetry and logging, (3) configuration and change management, (4) data protection, and (5) compliance and authorization. &lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Submit Your Comments:&lt;/b&gt;&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;NIST invites input from federal agencies, industry partners, researchers, and the broader cybersecurity community. The public comment period is open through &lt;b&gt;October 5, 2026&lt;/b&gt;.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;How to Participate:&lt;/b&gt;&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;Email your completed template to &lt;a href="mailto:ir8613-comments@nist.gov?Subject=NIST.IR.8613%20Comments"&gt;ir8613-comments@nist.gov&lt;/a&gt;&amp;nbsp;with the subject line&amp;nbsp;"&lt;b&gt;NIST.IR.8613 Comments&lt;/b&gt;."&lt;/p&gt;
&lt;ul&gt;&lt;/ul&gt;</summary>
    <published>2026-08-21T00:00:00-04:00</published>
    <updated>2026-08-21T00:00:00-04:00</updated>
    <link href="https://csrc.nist.gov/pubs/ir/8613/ipd" />
    <content type="text">Comments Due 10/05/2026</content>
  </entry>
  <entry>
    <id>https://csrc.nist.gov/pubs/sp/1353/ipd</id>
    <title type="text">SP 1353, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and ReportingInitial Public Draft</title>
    <summary type="text">&lt;p&gt;This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing,&amp;nbsp;and monitoring an organization&amp;rsquo;s progress toward achieving CSF 2.0 outcomes. &lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;The document&amp;rsquo;s purpose is to:&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;Provide structured AI prompts&lt;/b&gt; &lt;b&gt;as tools&lt;/b&gt; for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Identify current state of practice&lt;/b&gt; for AI prompt engineering in CSF implementation and analysis&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;While the focus was not to write about AI best practices or to provide cybersecurity guidelines thereof, there are places where specific precautions are denoted with the /!\ notation.&amp;nbsp; &lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;This guide includes three notional use cases, examples of prompts for structuring natural language inputs to produce&amp;nbsp;specified CSF 2.0 outputs from a generative AI model, simulated organizational files for a fictitious company, tips for getting started, and more. &lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;b&gt;USE CASE 1&lt;/b&gt; illustrates the use of an AI-assisted review to evaluate organization cybersecurity policy, strategy, and &lt;b&gt;risk governance in alignment with the CSF 2.0 outcomes.&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;USE CASE 2&amp;nbsp;&lt;/b&gt;illustrates how to &lt;b&gt;produce a draft Organization Current State Profile &amp;ndash;&amp;nbsp;&lt;/b&gt;mapping artifacts and personnel interview notes to CSF 2.0 outcomes, documenting any assumptions, and recording observed gaps in the interviews and evidence.&lt;/li&gt;
&lt;li&gt;&lt;b&gt;USE CASE 3&amp;nbsp;&lt;/b&gt;illustrates how to draw upon internal and industry references to &lt;b&gt;create a draft CSF target state profile &lt;/b&gt;describing desired outcomes to meet mission objectives, stakeholder expectations, address the risk landscape, and fulfill requirements.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Use case examples illustrate a&amp;nbsp;possible approach and are not prescriptive assessment or assurance methodologies.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;o&gt;&lt;/o&gt;&lt;em&gt;Note: The README file in the Supplemental Materials List contains the ZIP file checksums.&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Submit Your Comments: &lt;o&gt;&lt;/o&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;The comment period is open through October 15, 2026, at 11:59 PM. Email comments to: &lt;a href="mailto:csf@nist.gov"&gt;csf@nist.gov&lt;/a&gt;.&amp;nbsp;&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;Note: NIST is only seeking comments on the quick-start guide and supplied AI prompts. NIST is not seeking comment on the fictional organizational documents. Those are for illustrative purposes only. &lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;This publication is the most recent within a portfolio of CSF 2.0&amp;nbsp;quick-start&amp;nbsp;guides released by the CSF 2.0 project team since February 26, 2024. These resources&amp;nbsp;offer tailored pathways for different audiences to engage with the CSF 2.0, making the Framework easier to implement. View all&amp;nbsp;&lt;a href="https://www.nist.gov/cyberframework/navigating-nists-csf-20-quick-start-guides"&gt;CSF 2.0 quick-start guides&lt;/a&gt;.&lt;b&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;o&gt;&amp;nbsp;&lt;/o&gt;&lt;/p&gt;</summary>
    <published>2026-08-19T00:00:00-04:00</published>
    <updated>2026-08-19T00:00:00-04:00</updated>
    <link href="https://csrc.nist.gov/pubs/sp/1353/ipd" />
    <content type="text">Comments Due 10/15/2026</content>
  </entry>
  <entry>
    <id>https://csrc.nist.gov/pubs/sp/800/213/a/r1/iprd</id>
    <title type="text">SP 800-213A Rev. 1, PRE-DRAFT Call for Comments: IoT Device Cybersecurity Requirement CatalogInitial Preliminary Draft</title>
    <summary type="text">&lt;p&gt;Following the publication of draft revision&amp;nbsp;&lt;i&gt;IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, &lt;/i&gt;NIST &lt;a data-csrc-link="true" data-node-guid="4931def3-45b2-4e86-a17f-6945ba0662fb" href="/pubs/sp/800/213/r1/ipd"&gt;SP 800-213 Rev. 1&lt;/a&gt;, NIST has initiated the process of revising the companion document &lt;strong&gt;&lt;i&gt;IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog&lt;/i&gt;, &amp;nbsp;NIST &lt;a data-csrc-link="true" data-node-guid="3cb0c4fe-7843-4d69-985a-d9beca88d5ea" href="/pubs/sp/800/213/a/final"&gt;SP 800-213A&lt;/a&gt;&lt;/strong&gt;, to incorporate lessons learned, align with relevant NIST guidance (e.g., &lt;a data-csrc-link="true" data-node-guid="99708dc3-cd81-4c6e-962f-5f3319de95bd" href="/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final"&gt;Cybersecurity Framework (CSF) 2.0&lt;/a&gt;, &lt;a href="https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home"&gt;NIST SP 800-53 Rev. 5.2.0&lt;/a&gt;)&amp;mdash;as well as IoT cybersecurity standards and practices, and address changes in the IoT threat landscape.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;We welcome any valuable perspectives on potential revisions to the current SP 800-213A to maximize the document&amp;rsquo;s effectiveness, relevance, and usability in helping the community understand and manage cybersecurity risk. To help guide this input, NIST has included specific questions below, though reviewers are encouraged to address any, all, or additional topics in their comments.&lt;/p&gt;
&lt;p&gt;The public comment period is open through October 15, 2026. Submit comments via email to &lt;a href="mailto:iotsecurity@nist.gov"&gt;iotsecurity@nist.gov&lt;/a&gt; with the subject line &amp;ldquo;Comments on SP 800-213A.&amp;rdquo;&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;Specifically, NIST asks for input on the following questions to help us plan and produce an initial revision of NIST SP 800-213A:&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;b&gt;Addressing IoT Products&lt;/b&gt;. Given that draft NIST SP 800-213 Rev. 1 discusses IoT products while NIST SP 800-213A was written for IoT devices, how should we align NIST SP 800-213A with NIST SP 800-213 Rev. 1 in relation to IoT products? For example, the scope of SP 800-213A could be expanded to IoT products, or the scope of SP 800-213A could remain IoT devices with additional guidelines used for IoT product components other than the IoT device (e.g., mobile applications, backends). We welcome suggestions of other paths forward as well.&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Novel and Unique IoT Adoption and Use Cases&lt;/b&gt;. How is your organization using IoT and are there novel IoT use cases we should consider in the update?&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Addressing Unique and Tailored IoT Deployments.&lt;/b&gt; How can the NIST SP 800-213A guidelines appropriately handle situations in which an organization combines multiple off-the-shelf components (e.g., Raspberry Pi, sensors) to create an IoT sub-system akin to an IoT product? &lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Foundational Guidelines to Base our Work Upon&lt;/b&gt;. The content in NIST SP 800-213A was sourced primarily from NIST SP 800-53 Rev. 5, as well as the NIST Cybersecurity Framework (CSF). What other sources should we look to?&lt;o&gt;&lt;/o&gt;&lt;/li&gt;
&lt;li&gt;&lt;b&gt;Document Usability&lt;/b&gt;. How can descriptions and discussions for each capability in NIST SP 800-213A best help practitioners identify appropriate IoT product cybersecurity capabilities in different operational environments?&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Submitted comments, including attachments and other supporting materials, will become part of the public record and are subject to public disclosure. Personally identifiable information and confidential business information should not be included (e.g., account numbers, Social Security numbers, names of other individuals). Comments that contain profanity, vulgarity, threats, or other inappropriate language will not be posted or considered.&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;</summary>
    <published>2026-08-31T00:00:00-04:00</published>
    <updated>2026-08-31T00:00:00-04:00</updated>
    <link href="https://csrc.nist.gov/pubs/sp/800/213/a/r1/iprd" />
    <content type="text">Comments Due 10/15/2026</content>
  </entry>
  <entry>
    <id>https://csrc.nist.gov/pubs/sp/800/38/e/r1/ipd</id>
    <title type="text">SP 800-38E Rev. 1, Recommendation for Block Cipher Modes of Operation: XTS-AES Mode for Confidentiality on Storage DevicesInitial Public Draft</title>
    <summary type="text">&lt;p&gt;Revision 1 updates the referenced specification to &lt;b&gt;IEEE Std. 1619-2025&lt;/b&gt; and clarifies NIST&amp;rsquo;s requirements for the approved use of XTS-AES, including its scope of use, data-unit and key-scope limits, key requirements, and the ordering convention for ciphertext stealing.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;Rather than reproducing the XTS-AES specification, this recommendation incorporates&amp;nbsp;&lt;b&gt;IEEE Std. 1619-2025&lt;/b&gt; by reference. To facilitate review of the draft SP, &lt;a href="https://app.box.com/s/l7v69bw75kit5exqr13vgzhlwf0hg0kh"&gt;IEEE Std. 1619-2025 is publicly available&lt;/a&gt; during the public comment period.&lt;o&gt;&lt;/o&gt;&lt;/p&gt;
&lt;p&gt;The public comment period is open through &lt;b&gt;October 16, 2026&lt;/b&gt;.&lt;i&gt;&lt;o&gt;&amp;nbsp;&lt;/o&gt;&lt;/i&gt;&lt;/p&gt;
&lt;p&gt;&lt;span style="font-size: 10pt;"&gt;&lt;i&gt;NOTE: A call for patent claims is included in this draft. For additional information, see the &lt;/i&gt;&lt;a href="https://www.nist.gov/itl/publications-0/itl-patent-policy-inclusion-patents-itl-publications"&gt;Information Technology Laboratory (ITL)&amp;nbsp;Patent Policy &lt;i&gt;&amp;ndash;&lt;/i&gt; Inclusion of Patents in ITL Publications&lt;/a&gt;&lt;i&gt;.&lt;/i&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt;&lt;i&gt;&lt;/i&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt;&lt;i&gt;&lt;/i&gt;&lt;/span&gt;&lt;span style="font-size: 10pt;"&gt;&lt;i&gt;&lt;/i&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;</summary>
    <published>2026-09-03T00:00:00-04:00</published>
    <updated>2026-09-03T00:00:00-04:00</updated>
    <link href="https://csrc.nist.gov/pubs/sp/800/38/e/r1/ipd" />
    <content type="text">Comments Due 10/16/2026</content>
  </entry>
</feed>