Date Published: May 2026
Supersedes:
SP 800-70 Rev. 4 (02/15/2018)
Planning Note (06/08/2026):
The current version of the NIST SP800-70 revision 5 maintains language referencing FAR 39.101(c) (see pages 4 and 9). However, the current RFO deviation specifically excludes FAR 39.101(c). The FAR RFO final rule is undergoing review, and NIST will update the revision to correspond to any changes to FAR 39.101(c) once the rule is finalized. Note: the RFO companion guide (see page 98) provides readers with hyperlinks to NIST guidance and statutory requirements related to the acquisition of ICT.
None selected
Publication:
https://doi.org/10.6028/NIST.SP.800-70r5
Download URL
Supplemental Material:
National Checklist Program
Document History:
12/09/25: SP 800-70 Rev. 5 (Draft)
05/08/26: SP 800-70 Rev. 5 (Final)
audit & accountability, configuration management, security automation, vulnerability management
Technologies Laws and RegulationsCyber Security R&D Act, Federal Information Security Modernization Act, OMB Circular A-130