Date Published: August 31, 2026
Comments Due: October 15, 2026
Email Comments to:
[email protected]
Following the publication of draft revision IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, NIST SP 800-213 Rev. 1, NIST has initiated the process of revising the companion document IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, NIST SP 800-213A, to incorporate lessons learned, align with relevant NIST guidance (e.g., Cybersecurity Framework (CSF) 2.0, NIST SP 800-53 Rev. 5.2.0)—as well as IoT cybersecurity standards and practices, and address changes in the IoT threat landscape.
We welcome any valuable perspectives on potential revisions to the current SP 800-213A to maximize the document’s effectiveness, relevance, and usability in helping the community understand and manage cybersecurity risk. To help guide this input, NIST has included specific questions below, though reviewers are encouraged to address any, all, or additional topics in their comments.
The public comment period is open through October 15, 2026. Submit comments via email to [email protected] with the subject line “Comments on SP 800-213A.”
Specifically, NIST asks for input on the following questions to help us plan and produce an initial revision of NIST SP 800-213A:
Submitted comments, including attachments and other supporting materials, will become part of the public record and are subject to public disclosure. Personally identifiable information and confidential business information should not be included (e.g., account numbers, Social Security numbers, names of other individuals). Comments that contain profanity, vulgarity, threats, or other inappropriate language will not be posted or considered.
None selected
Publication:
See SP 800-213A (pdf)
Supplemental Material:
None available
Document History:
08/31/26: SP 800-213A Rev. 1 (Draft)
acquisition, program management, risk management
Technologies Applications Laws and Regulations