News & Updates
Stay informed as the Information Technology Laboratory’s Cybersecurity and Privacy Program releases publications, schedules virtual and in-person events, and announces other important developments.
Subscribe to our email updates.
Visit these additional NIST sites to learn more about:
- NVD: National Vulnerability Database news and status updates
- NICE: National Initiative for Cybersecurity Education news and events
- NCCoE: National Cybersecurity Center of Excellence news and events
- NIST-wide cybersecurity and privacy news and events
NIST has published Special Publication (SP) 800-189, "Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation," which superseded SP 800-54, "Border Gateway Protocol Security."
NIST has released Draft NIST Special Publication (SP) 800-208, "Recommendation for Stateful Hash-Based Signature Schemes." The public comment period ends February 28, 2020.
NIST has released Special Publication (SP) 800-160 Volume 2, "Developing Cyber Resilient Systems: A Systems Security Engineering Approach."
NIST has released Draft NISTIR 8011 Volume 4, "Automation Support for Security Control Assessments: Software Vulnerability Management," for public comment. The comment period ends December 20, 2019.
NIST has released Draft NISTIR 8214A, "Towards NIST Standards for Threshold Schemes for Cryptographic Primitives: A Preliminary Roadmap," for public comment. The comment period closes February 10, 2020.
Digital signature algorithms and elliptic curves: NIST is requesting comments on two drafts that specify digital signature algorithms (Draft FIPS 186-5) and NIST-recommended elliptic curves (Draft SP 800-186). The public comment period ends January 29, 2020.
The NCCoE has released Draft NISTIR 8269, "A Taxonomy and Terminology of Adversarial Machine Learning," for public comment. Comments are due by January 30, 2020.
NIST has released a second public draft of Special Publication 800-189, "Resilient Interdomain Traffic Exchange: BGP Security and DDoS Mitigation." The public comment period closes November 15, 2019.
NIST has updated Special Publication (SP) 800-128, "Guide for Security-Focused Configuration Management of Information Systems"
NIST has released the Draft Special Publication (SP) 800-140x subseries for public comment. They directly support FIPS 140-3 and the Cryptographic Module Validation Program (CMVP). Comments are due by December 9, 2019.
NIST releases Draft SP 800-57 Part 1 Revision 5, "Recommendation for Key Management: Part 1 – General," for public comment. Comments are due by December 6, 2019.
NIST publishes NISTIR 8268, "Status Report on the First Round of the NIST Lightweight Cryptography Standardization Process."
NIST has released a draft of NISTIR 8267, "Security Review of Consumer Home Internet of Things (IoT) Products," for public comment. The comment period closes November 1, 2019.
NIST has published NISTIR 8183A (3 volumes), "Cybersecurity Framework Manufacturing Profile Low Impact Level Example Implementations Guide."
The NCCoE has released Draft SP 1800-23, "Energy Sector Asset Management," for public comment. The comment period ends November 25, 2019.
NIST has released Draft Special Publication (SP) 800-207, Zero Trust Architecture. Public comments are due by November 22, 2019.
The NCCoE has released Draft SP 1800-24, "Securing Picture Archiving and Communication System (PACS): Cybersecurity for the Healthcare Sector," for public comment. The comment period ends November 18, 2019.
NIST seeks comments on the Preliminary Draft of the "NIST Privacy Framework: A Tool for Improving Privacy through Enterprise Risk Management." The comment period closes October 24, 2019.
NIST has released the Final Public Draft of Special Publication (SP) 800-160 Volume 2, "Developing Cyber Resilient Systems: A Systems Security Engineering Approach." Public comment are due by November 1, 2019.
NIST announces thirty-two (32) candidates for Round 2 of the Lightweight Cryptography (LWC) Standardization project.
NIST has published Special Publication (SP) 800-52 Revision 2, "Guidelines for the Selection, Configuration, and Use of Transport Layer Security (TLS) Implementations."
NIST has published NIST SP 800-204, Security Strategies for Microservices-based Application Systems.
NIST has published Cybersecurity Practice Guide Special Publication (SP) 1800-7, "Situational Awareness for Electric Utilities."
NIST has released Draft NISTIR 8259, "Core Cybersecurity Feature Baseline for Securable IoT Devices: A Starting Point for IoT Device Manufacturers," for public comment. The comment period closes on September 30, 2019.
NIST has published Cybersecurity Practice Guide Special Publication (SP) 1800-17, "Multifactor Authentication for E-Commerce: Risk-Based, FIDO Universal Second Factor Implementations for Purchasers"
NIST has published Special Publication 800-133 Revision 1, "Recommendation for Cryptographic Key Generation."
The NCCoE has released Draft SP 1800-21, "Mobile Device Security: Corporate-Owned Personally-Enabled (COPE)," for public comment. The comment period ends September 23, 2019.
The NCCoE has released Draft SP 1800-16, "Securing Web Transactions: Transport Layer Security (TLS) Server Certificate Management," for public comment. The comment period ends September 13, 2019.
A draft NIST Cybersecurity White Paper, "A Taxonomic Approach to Understanding Emerging Blockchain Identity Management Systems," is available for public comment until August 9, 2019.
NIST has released Draft NIST Special Publication 800-175B Revision 1 for comment. The public comment period ends September 5, 2019.
NIST has released Draft Special Publication 800-77 Revision 1 for public comment. The comment period is open until October 8, 2019.
NIST has published Special Publication 1800-14, Protecting the Integrity of Internet Routing: Border Gateway Protocol (BGP) Route Origin Validation.
NIST has published NIST Interagency/Internal Report 8228, "Considerations for Managing Internet of Things (IoT) Cybersecurity and Privacy Risks."
The NCCoE at NIST has posted to data confidentiality draft project descriptions for public comment. Comments are due by July 29, 2019.
NIST is pleased to announce the first official release of the Open Security Controls Assessment Language (OSCAL), Version 1.0.0 - Milestone 1. The release.....
NIST has released two draft publications for comment: SP 800-171 Rev. 2 and SP 800-171B. The comment period for both drafts ends on July 19, 2019.
NIST has published Special Publication 800-205, "Attribute Considerations for Access Control Systems."
The NCCoE has posted two draft Project Descriptions for public comment. Detecting and protecting against data integrity attacks in industrial control systems (ICS) closes July 25th. Continuous Monitoring (for small and medium businesses) is closes on July 26th.
A draft white paper, "Mitigating the Risk of Software Vulnerabilities by Adopting a Secure Software Development Framework (SSDF)," is available for public comment until August 5, 2019.
NIST announces the publication of NISTIR 8221, "A Methodology for Enabling Forensic Analysis Using Hypervisor Vulnerabilities Data."
NIST has withdrawn Special Publication 800-64 Revision 2, "Security Considerations in the System Development Life Cycle."
NCCoE has released a second draft of SP 1800-13, "Mobile Application Single Sign-On: Improving Authentication for Public Safety First Responders." Public comments are due by June 28, 2019.
NIST has released Draft NISTIR 8183A (3 volumes), "Cybersecurity Framework Manufacturing Profile Low Security Level Example Implementations Guide," for public comment. Comments are due by July 8, 2019.
NIST has published SP 800-57 Part 2 Rev. 1, "Recommendation for Key Management: Part 2 – Best Practices for Key Management Organizations."
NIST has release a draft white paper for public comment: "An Application of Combinatorial Methods for Explainability in Artificial Intelligence and Machine Learning." Comments are due by July 3, 2019.
A new release of the Access Control Policy Tool (ACPT) is now available for download.
FIPS 140-3, "Security Requirements for Cryptographic Modules," was approved on March 22, 2019 and announced in the Federal Register on May 1, 2019. FIPS 140-3 supersedes FIPS 140-2.
NIST publishes NIST Internal Report (NISTIR) 8204, "Cybersecurity Framework Online Informative References (OLIR) Submissions: Specification for Completing the OLIR Template."
The NCCoE has release a preliminary draft of Special Publication (SP) 1800-15 for public comment. Comments are due by June 24, 2019.
NIST publishes Special Publication (SP) 800-163 Revision 1, "Vetting the Security of Mobile Applications."
NIST announces fifty-six (56) candidates for Round 1 of the Lightweight Cryptography (LWC) Standardization project.
Cybersecurity and usability must coexist. Systems that prioritize usability over a .....
NIST is releasing Draft Special Publication (SP) 800-204, "Security Strategies for Microservices-based Application Systems." Public comments are due by April 26, 2019.
NIST has published Special Publication 800-131A Rev. 2, "Transitioning the Use of Cryptographic Algorithms and Key Lengths."
NIST announces the publication of Special Publication (SP) 800-56B Revision 2, "Recommendation for Pair-Wise Key Establishment Schemes Using Integer Factorization Cryptography."
NIST has released Draft SP 800-133 Revision 1, "Recommendation for Cryptographic Key Generation," for public comment. Submit comments by May 8, 2019.
NIST announces the publication of NIST Internal Report (NISTIR) 8214, Threshold Schemes for Cryptographic Primitives.
NIST requests public comments on Draft SP 800-38G Revision 1, Recommendation for Block Cipher Modes of Operation: Methods for Format-Preserving Encryption. Comments are due by April 15, 2019.
NIST announces the publication of NIST Special Publication 800-177 Revision 1, "Trustworthy Email."
NIST publishes an errata update for SP 800-162, "Guide to Attribute Based Access Control (ABAC) Definition and Considerations."
Draft NIST Special Publication 800-205, "Attribute Considerations for Access Control Systems," is available for public comment. Please submit comments by April 1, 2019.
NIST currently intends to approve both LMS and XMSS stateful hash-based signature schemes, and is seeking public comments on that proposed action by April 1, 2019.
NIST publishes Internal Report (NISTIR) 8240, "Status Report on the First Round of the NIST Post-Quantum Cryptography Standardization Process"
After over a year of evaluation, NIST would like to announce the candidates that will be moving on to the 2nd round of the NIST PQC Standardization Process.
* "Relevance" merely indicates the search engine's score for a document. It is based on the search parameters and information in the document's detailed record.