Stay informed as the Information Technology Laboratory’s Cybersecurity and Privacy Program releases publications, schedules virtual and in-person events, and announces other important developments.
Subscribe to our email updates.
Visit these additional NIST sites to learn more about:
This Quick-Start Guide based on the widely adopted content in NIST SP 800-161r1 proposes an implementation-ready approach to conducting the minimum amount of reasonable research and investigative rigor on potential suppliers.
NIST has released Special Publication (SP) 800-18r2 (Revision 2), Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems. This revision broadens the scope of system planning to encompass three interconnected plan types that are collectively referred to as "system plans". Essential system plan elements are correlated with the steps and tasks of the NIST Risk Management Framework (RMF) to provide a streamlined approach to system plan development.
NIST has released the initial public draft of Special Publication (SP) 800-218r1 (Revision 1), Secure Software Development Framework (SSDF) Version 1.2: Recommendations for Mitigating the Risk of Software Vulnerabilities, per Executive Order 14306.
NIST's NCCoE has posted the second public draft of NIST IR 8536, "Supply Chain Traceability: Manufacturing Meta-Framework," for public comment. The comment period is open through October 3, 2025.