Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST SP 800-38F Rev. 1 (Initial Preliminary Draft)

PRE-DRAFT Call for Comments: Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping

Date Published: May 5, 2026
Comments Due: July 10, 2026
Email Comments to: [email protected]

Author(s)

National Institute of Standards and Technology

Announcement

NIST plans to revise Special Publication (SP) 800-38F, Recommendation for Block Cipher Modes of Operation: Methods for Key Wrapping (2012), and is soliciting preliminary feedback.

The following are the two main goals for the revision:

  1. The specification of TKW should be removed because its underlying block cipher, TDEA, is no longer approved.
  2. The approval in Section 3.1 of unspecified combinations of an approved encryption mode with an approved authentication method should be revisited because such combinations may introduce unexpected security vulnerabilities compared to fully specified methods for authenticated encryption.  (See the NIST page on authentication for block cipher modes for more information, including links to some of the relevant security analysis.)

NIST requests feedback on all aspects of this publication, especially the following questions:

  • What ad hoc combinations—approved encryption mode and approved authentication method—are currently implemented, in practice?
  • Should NIST limit the approval to an explicit set of such combinations that occur within prominent protocols?

The public comment period is open through July 10, 2026. Send comments to [email protected] with “Pre-Draft Comments on SP 800-38F” in the subject line. Comments received in response to this request will be posted on this page after the due date. Submitters’ names and affiliations (when provided) will be included, while contact information will be removed. 

Control Families

None selected

Documentation

Publication:
No Download Available

Supplemental Material:
None available

Related NIST Publications:
SP 800-38F

Document History:
05/05/26: SP 800-38F Rev. 1 (Draft)

Topics

Security and Privacy

authentication, encryption, key management