Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8613 (Initial Public Draft)

Multi-Cloud Architecture Challenges: Security and Compliance Implications

Date Published: August 21, 2026
Comments Due: October 5, 2026
Email Comments to: [email protected]

Author(s)

Michaela Iorga (NIST), Nedim Goren (NIST)

Announcement

NIST Internal Report (IR) 8613 ipd (initial public draft), Multi-Cloud Architecture Challenges, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis by the NIST Multi-Cloud Security Public Working Group (MCSPWG) addresses security and Authorization to Operate (ATO) challenges and highlights areas where additional community research could meaningfully reduce risk.

The MCSPWG identified 23 consolidated challenge areas that represent novel friction points and architectural misalignments that emerge when orchestrating control across autonomous cloud silos. The most significant structural challenge areas are:

  • Security-significant differences in cloud-native services across providers
  • Organizational logistics and staffing complexity across heterogeneous environments
  • Difficulty in implementing centralized security capabilities across provider boundaries

These structural gaps are most acute in five areas: (1) identity and access management, (2) telemetry and logging, (3) configuration and change management, (4) data protection, and (5) compliance and authorization.

Submit Your Comments:

NIST invites input from federal agencies, industry partners, researchers, and the broader cybersecurity community. The public comment period is open through October 5, 2026.

How to Participate:

Email your completed template to [email protected] with the subject line "NIST.IR.8613 Comments."

    Abstract

    Keywords

    Analysis; authorization; authorization challenges; Authorization to Operate (ATO); cloud service customer (CSC); cloud service provider (CSP); multi-cloud; multi-cloud architecture; security challenges; system security plan
    Control Families

    None selected

    Documentation

    Publication:
    https://doi.org/10.6028/NIST.IR.8613.ipd
    Download URL

    Supplemental Material:
    Comment Template (xlsx)

    Document History:
    08/21/26: IR 8613 (Draft)

    Topics

    Security and Privacy

    access authorization, planning

    Technologies

    cloud & virtualization