Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8389 (Initial Public Draft)

Cybersecurity Considerations for Open Banking Technology and Emerging Standards

Date Published: January 3, 2022
Comments Due: March 3, 2022 (public comment period is CLOSED)
Email Questions to:


Jeffrey Voas (NIST), Phillip Laplante (Penn State University), Mohamad Kassab (Penn State University), Steve Lu (Stealth Software), Rafail Ostrovsky (UCLA), Nir Kshetri (UNC Greensboro)


“Open banking” (OB) refers to a new financial ecosystem that provides more choices to individuals and small and mid-size businesses concerning the movement of their money, as well as information between financial institutions. Open banking is already being used in several countries around the world, however, it is yet to be adopted in the United States. Anytime a system becomes more transparent, a potential for abuse occurs, and for open banking, that would be at the API level.

This report contains a definition and description of open banking, its activities, enablers, and cybersecurity, and privacy challenges. This report is not intended to be a promotion of OB within the U.S but rather a factual description of the technology and how various countries have implemented it. Any proposal of a specific API that would be compatible across heterogeneous systems was purposely avoided in this report.


NOTE:  A call for patent claims is included on page iv of this draft.  For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.



open banking; computer security; privacy; cybersecurity; APIs
Control Families

None selected


Download URL

Supplemental Material:
None available

Document History:
01/03/22: IR 8389 (Draft)


Security and Privacy

general security & privacy


small & medium business


financial services