U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

National Online Informative References Program OLIR

Informative Reference Catalog

The Online Informative Reference Catalog contains all the Reference Data—Informative References and Derived Relationship Mappings (DRMs)—for the National Online Informative References (OLIR) Program. All Reference Data in the Informative Reference Catalog has been validated against the requirements of NIST Interagency Report (IR) 8278A, National Online Informative References (OLIR) Program: Submission Guidance for OLIR Developers. If interested in participating in the OLIR program, please refer to the Informative Reference submission page.

The OLIR Catalog provides an interface for Developers and Users to view Informative References and analyze Reference Data. The Catalog includes links to draft content that is being evaluated during a 30-day public comment period and final versions that have completed the public comment period.

For more information on the National Online Informative References (OLIR) Program, refer to NISTIR 8278, National Online Informative References (OLIR) Program: Program Overview and OLIR Uses which describes the OLIR Program, focusing on explaining what OLIRs are, how they can be beneficial, and how subject matter experts can contribute OLIRs.


The status field is used to indicate the level of completion an OLIR is currently in. The following is a description of each stage of completion and what each stage represents, for more information, please see the status FAQ:

Status Definition
Work-in-progress The document is currently under development. This draft is not yet complete, and organizations should not attempt to implement it.
Preliminary Draft The content is considered to be stable, but changes are expected to occur. There are gaps in the content and the overall document is still incomplete.
Draft The document represents a complete draft. Early adopters may attempt to implement the guidelines in a test or development environment.
Final The document is final. Relevant content will continue to be linked from or hosted on csrc.nist.gov or nccoe.nist.gov, as appropriate.

Derived Relationship Mapping

Advanced Search

Showing 5 matching records.
Final NISTIR_8259A_Eurofins_SCD_Logo_OLIR (1.1.0) (More Details) EIOTS-2011 Secure Connected Devices Logo Requirements 01.001 11/10/21 IoT Device Cybersecurity Capability Core Baseline Eurofins Cyber Security Owner Private Sector
Final IoTSF-Framework-to-IR8259A (1.0.0) (1.0.0) (More Details) IoTSF IoT Security Compliance Framework v2.1 11/10/21 IoT Device Cybersecurity Capability Core Baseline IoTSF Owner Private Sector
Final NIST-8259A-to-SESIP-v1.2 (1.0.0) (1.0.0) (More Details) Security Evaluation Standard for IoT Platform (SESIP), Version 1.0, Ref. GP_FST_070 08/17/21 IoT Device Cybersecurity Capability Core Baseline GlobalPlatform Owner Private Sector
Final TUVSUD-17003-to-NISTIR-8259A (1.0.0) (More Details) TÜV SÜD Testing Guidelines for NISTIR 8259 07/29/21 IoT Device Cybersecurity Capability Core Baseline TÜV SÜD Owner Private Sector
Final CTA-2088-to-NISTIR-8259A (1.0.0) (More Details) CTA-2088 Baseline Cybersecurity Standard for Devices and Device Systems (November 2020) 01/21/21 IoT Device Cybersecurity Capability Core Baseline Consumer Technology Association Owner Private Sector

Representations and Warranties

Certain commercial entities, equipment, or materials may be identified in this Web site or linked Web sites in order to support OLIR understanding and use. Such identification is not intended to imply recommendation or endorsement by NIST, nor is it intended to imply that the entities, materials, or equipment are necessarily the best available for the purpose.


National Online Informative References Program


Security and Privacy: testing & validation

Applications: cybersecurity framework

Created September 08, 2020, Updated August 08, 2022