Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-213A Rev. 1 (Initial Preliminary Draft)

PRE-DRAFT Call for Comments: IoT Device Cybersecurity Requirement Catalog

Date Published: August 31, 2026
Comments Due: October 15, 2026
Email Comments to: [email protected]

Announcement

Following the publication of draft revision IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, NIST SP 800-213 Rev. 1, NIST has initiated the process of revising the companion document IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog,  NIST SP 800-213A, to incorporate lessons learned, align with relevant NIST guidance (e.g., Cybersecurity Framework (CSF) 2.0, NIST SP 800-53 Rev. 5.2.0)—as well as IoT cybersecurity standards and practices, and address changes in the IoT threat landscape.

We welcome any valuable perspectives on potential revisions to the current SP 800-213A to maximize the document’s effectiveness, relevance, and usability in helping the community understand and manage cybersecurity risk. To help guide this input, NIST has included specific questions below, though reviewers are encouraged to address any, all, or additional topics in their comments.

The public comment period is open through October 15, 2026. Submit comments via email to [email protected] with the subject line “Comments on SP 800-213A.”

Specifically, NIST asks for input on the following questions to help us plan and produce an initial revision of NIST SP 800-213A:

  1. Addressing IoT Products. Given that draft NIST SP 800-213 Rev. 1 discusses IoT products while NIST SP 800-213A was written for IoT devices, how should we align NIST SP 800-213A with NIST SP 800-213 Rev. 1 in relation to IoT products? For example, the scope of SP 800-213A could be expanded to IoT products, or the scope of SP 800-213A could remain IoT devices with additional guidelines used for IoT product components other than the IoT device (e.g., mobile applications, backends). We welcome suggestions of other paths forward as well.
  2. Novel and Unique IoT Adoption and Use Cases. How is your organization using IoT and are there novel IoT use cases we should consider in the update?
  3. Addressing Unique and Tailored IoT Deployments. How can the NIST SP 800-213A guidelines appropriately handle situations in which an organization combines multiple off-the-shelf components (e.g., Raspberry Pi, sensors) to create an IoT sub-system akin to an IoT product?
  4. Foundational Guidelines to Base our Work Upon. The content in NIST SP 800-213A was sourced primarily from NIST SP 800-53 Rev. 5, as well as the NIST Cybersecurity Framework (CSF). What other sources should we look to?
  5. Document Usability. How can descriptions and discussions for each capability in NIST SP 800-213A best help practitioners identify appropriate IoT product cybersecurity capabilities in different operational environments?

Submitted comments, including attachments and other supporting materials, will become part of the public record and are subject to public disclosure. Personally identifiable information and confidential business information should not be included (e.g., account numbers, Social Security numbers, names of other individuals). Comments that contain profanity, vulgarity, threats, or other inappropriate language will not be posted or considered.

Control Families

None selected

Documentation

Publication:
See SP 800-213A (pdf)

Supplemental Material:
None available

Document History:
08/31/26: SP 800-213A Rev. 1 (Draft)