Many of NIST's cybersecurity and privacy publications are posted as drafts for public comment. Comment periods are still open for the following publications. Select the publication title to access downloads, related content, and instructions for submitting comments. Your thoughtful reviews and comments are greatly appreciated and help us to improve our standards and guidance.
Also see a complete list of public drafts that includes those whose comment periods have closed.
|
NIST has released initial working drafts of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM... |
|
NIST has released initial working drafts of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM... |
|
NIST has released initial working drafts of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM... |
|
Building upon established principles from high-performance computing (HPC) threat analyses and security overlays, this publication delivers a thorough threat and security gap analysis for purpose-built AI infrastructure used in model training, inference, and applications. By contrasting AI data... |
|
NIST Internal Report (IR) 8613 ipd (initial public draft), Multi-Cloud Architecture Challenges, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis by the NIST Multi-Cloud Security... |
|
This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes. The document’s purpose is to: Provide structured AI prompts as tools for practitioners to begin... |
|
Following the publication of draft revision IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, NIST SP 800-213 Rev. 1, NIST has initiated the process of revising the companion document IoT Device Cybersecurity Guidance for the... |
|
Revision 1 updates the referenced specification to IEEE Std. 1619-2025 and clarifies NIST’s requirements for the approved use of XTS-AES, including its scope of use, data-unit and key-scope limits, key requirements, and the ordering convention for ciphertext stealing. Rather than reproducing the... |