Date Published: May 6, 2026
Comments Due: July 6, 2026
Email Comments to:
[email protected]
This profile helps organizations manage risks to systems, networks, and assets that use PNT services, such as Global Positioning Systems (GPS), public NIST and United States Naval Observatory (USNO) Network Time Protocol (NTP) servers, commercial services, and internal systems.
Originally developed based on NIST Cybersecurity Framework version 1.1, this profile has been updated to align with the NIST CSF 2.0 and includes updated references to standards, guidelines, and practices to provide practical guidelines to help an organization achieve the desired outcome for each Subcategory in the profile.
Organizations can apply the Profile to govern cybersecurity risk management, identify systems dependent on PNT, identify appropriate PNT sources, protect PNT user equipment from adversaries, detect anomalies and manipulation of PNT services, and respond to and recover from PNT service disruptions.
We encourage you to review the revised publication draft and submit comments until July 6, 2026, using the instructions provided on the project page. NIST is seeking targeted feedback to ensure the profile is practical and aligned to real-world use.
Specific questions are included in the draft document. In particular, we are interested in:
None selected
Publication:
https://doi.org/10.6028/NIST.IR.8323r2.ipd
Download URL
Supplemental Material:
Project homepage
Document History:
03/12/25: IR 8323 Rev. 2 (Draft)
05/06/26: IR 8323 Rev. 2 (Draft)
general security & privacy, risk management
Applications Laws and Regulations