Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Search CSRC

Use this form to search content on CSRC pages.

For a phrase search, use " "


Limit results to content tagged with of the following topics:
Showing 26 through 50 of 1437 matching records.
Projects

Post-Quantum Cryptography

https://csrc.nist.gov/projects/post-quantum-cryptography

Short URL: https://www.nist.gov/pqcrypto For a plain-language introduction to post-quantum cryptography, see What Is Post-Quantum Cryptography? PQC Standards | Migration to PQC | Ongoing PQC Standardization Process NIST’s Post-Quantum Cryptography (PQC) project leads the national and global effort to secure electronic information against the future threat of quantum computers—machines that may be years or decades away but could eventually break many of today’s widely used cryptographic systems. Through a multi-year international competition involving industry, academia, and...

Projects

Ransomware Protection and Response

https://csrc.nist.gov/projects/ransomware-protection-and-response

Thanks for helping shape our ransomware guidance! We've published our final version of NIST IR 8374 Revision 1, Ransomware Risk Management: A Cybersecurity Framework Profile. It reflects changes made to the Cybersecurity Framework (CSF) from CSF 1.1 to CSF 2.0 which identifies security objectives that support managing, detecting, responding to, and recovering from ransomware events. NIST is still actively seeking feedback on resources that can help communities prepare for and recover from ransomware attacks. Please reach out to us at [email protected] NIST has also previously published...

Updates

Practical Guidelines for Preventing and Mitigating Ransomware | CSF 2.0 Community Profile

June 11, 2026
https://csrc.nist.gov/news/2026/ransomware-risk-management-ir-8374r1

NIST IR 8374r1, "Ransomware Risk Management: A Cybersecurity Framework (CSF) 2.0 Community Profile," is now available.

Publications IR 8374 Rev. 1 (Final)

Ransomware Risk Management: A Cybersecurity Framework 2.0 Community Profile

June 11, 2026
https://csrc.nist.gov/pubs/ir/8374/r1/final

Abstract: Ransomware is a type of malicious attack where attackers encrypt an organization’s data and demand payment to restore access. Attackers may also steal an organization’s information and demand an additional payment in return for not disclosing the information to authorities, competitors,...

Project Pages

SP 800-171A

https://csrc.nist.gov/projects/protecting-controlled-unclassified-information/sp-800-171a-1

Assessing Security Requirements for Controlled Unclassified Information Purpose Assessment procedures and a methodology that can be employed to conduct assessments of the CUI security requirements in NIST SP 800-171. Scope A system security plan describes how the SP 800-171 security requirements are met. The plan describes the system boundary; the environment in which the system operates; how the requirements are implemented; and the relationships with or connections to other systems. The scope of the assessments conducted using the procedures described in SP 800-171A are guided and...

Projects

Protecting Controlled Unclassified Information

https://csrc.nist.gov/projects/protecting-controlled-unclassified-information

Protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations is critical to federal agencies. The suite of guidance (NIST Special Publication (SP) 800-171, SP 800-171A, SP 800-172, and SP 800-172A) focuses on protecting the confidentiality of CUI and recommends specific security requirements to achieve that objective. Recent Updates May 13, 2026: NIST issues SP 800-172r3, Enhanced Security Requirements for Protecting Controlled Unclassified Information, and SP 800-172Ar3, Assessing Enhanced Security Requirements for Controlled Unclassified...

Project Pages

Assured Autonomy and Explainable AI Papers

https://csrc.nist.gov/projects/automated-combinatorial-testing-for-software/autonomous-systems-assurance/assured-autonomy-papers

Our conference and journal papers on assured autonomy and explainable AI. We try to include links to the full papers, but for those not yet linked, please contact us for a copy: [email protected]. Papers 2025 Lanus, E., Lee, B., Chandrasekaran, J., Freeman, L. J., Raunak, M. S., Kacker, R. N., & Kuhn, D. R. (2025, March). Data frequency coverage impact on ai performance. In 2025 IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW) (pp. 258-267). IEEE. Wei, Q., Sikder, F., Feng, H., Lei, Y., Kacker, R., & Kuhn, R. (2025). SmartExecutor:...

Project Pages

Workshops and Timeline

https://csrc.nist.gov/projects/post-quantum-cryptography/workshops-and-timeline

Workshops Date September 24-26, 2025 Sixth PQC Standardization Conference (In-Person / Virtual) Venue: NIST Gaithersburg, Maryland, USA Call for Papers April 10-12, 2024 Fifth PQC Standardization Conference (In-Person) Hilton Washington DC/Rockville Hotel Rockville, MD Call for Papers November 29- December 1, 2022 Fourth PQC Standardization Conference Virtual Call for Papers June 7-9, 2021 Third...

Project Pages

Common Platform Enumeration (CPE)

https://csrc.nist.gov/projects/security-content-automation-protocol/specifications/cpe

Common Platform Enumeration (CPE) is a standardized method of describing and identifying classes of applications, operating systems, and hardware devices present among an enterprise's computing assets. CPE names product classes rather than specific installed instances, which lets security tools make consistent, automated decisions for asset management, vulnerability management, and configuration management. This page is the entry point for the CPE specification. It gives a high-level overview of the CPE versions and the work now under way on the next major revision. Each version has its own...

Project Pages

Common Platform Enumeration 3.0 (CPE 3.0)

https://csrc.nist.gov/projects/security-content-automation-protocol/specifications/cpe-3-0

CPE 3.0 is the next major revision of Common Platform Enumeration (CPE), now in early development at NIST. This page tracks the effort and how to take part. For the current published version, see Common Platform Enumeration (CPE). About the CPE 3.0 effort CPE 2.3 has been in wide use for more than a decade. Implementation experience over that period, together with current security automation needs, has surfaced a set of issues worth addressing in a future version. The CPE 3.0 effort will evaluate how platforms and products are identified for current security automation use cases, including...

Updates

Hardware-Enabled Security: Draft Report Available for Comment

May 29, 2026
https://csrc.nist.gov/news/2026/draft-nist-ir-hardware-enabled-security

NIST Interagency Report (NIST IR) 8320E ipd (initial public draft), Hardware-Enabled Security: Confidential Computing of Data in Cloud Workloads, is open for public comment through July 13, 2026.

Publications IR 8320E (Initial Public Draft)

Hardware-Enabled Security: Confidential Computing of Data in Cloud Workloads

May 29, 2026
https://csrc.nist.gov/pubs/ir/8320/e/ipd

Abstract: Confidential computing addresses data security and privacy concerns for organizations that move sensitive workloads to the cloud. It is a critical advancement that enables the encryption of data both while it is being processed in memory and in active use. As cloud adoption continues to grow, confid...

Projects

Human-Centered Cybersecurity

https://csrc.nist.gov/projects/human-centered-cybersecurity

The National Institute of Standards and Technology (NIST) Human-Centered Cybersecurity program, which is part of the Human-Centered Technologies Group (formerly named Visualization and Usability Group), seeks to "champion the human in cybersecurity" by conducting interdisciplinary research to better understand and improve people’s interactions with cybersecurity systems, products, processes, and services. Be sure to connect with NIST and the Human-Centered Cybersecurity program on social media and subscribe to GovDelivery to stay apprised of our latest research....

Updates

Just Published | NIST’s FY 2025 Cybersecurity & Privacy Program Annual Report

May 21, 2026
https://csrc.nist.gov/news/2026/fy-2025-cybersecurity-annual-report

NIST has published Special Publication (SP) 800-238, FY 2025 NIST Cybersecurity and Privacy Program Annual Report.

Updates

Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector | NIST SP 1800-41 is Available for Public Comment

May 21, 2026
https://csrc.nist.gov/news/2026/nist-sp-1800-41-released-for-public-comment

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft of NIST Special Publication 1800-41, Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector. Public comments are due by July 8th. This report provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience.

Publications SP 800-238 (Final)

Fiscal Year 2025 Cybersecurity and Privacy Annual Report

May 21, 2026
https://csrc.nist.gov/pubs/sp/800/238/final

Abstract: Throughout Fiscal Year 2025 (FY 2025) — from October 1, 2024, through September 30, 2025 — the NIST Information Technology Laboratory (ITL) Cybersecurity and Privacy Program successfully responded to numerous challenges and opportunities in security and privacy. This Annual Report highli...

Publications SP 1800-41 (Initial Public Draft)

Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector

May 21, 2026
https://csrc.nist.gov/pubs/sp/1800/41/ipd

Abstract: Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing numb...

Updates

IR 8500A ipd, Blockchain-Based Secure Software Assets Management (BloSS@M), Available for Public Comment

May 19, 2026
https://csrc.nist.gov/news/2026/nist-ir-8500a-ipd-available-for-public-comment

NIST Internal Report (IR) 8500A ipd (initial public draft), Blockchain-Based Secure Software Assets Management (BloSS@M), outlines a modernized conceptual approach for transforming how software assets are acquired, tracked, and secured across an interagency ecosystem.

Publications IR 8500A (Initial Public Draft)

Blockchain-Based Secure Software Assets Management (BloSS@M)

May 19, 2026
https://csrc.nist.gov/pubs/ir/8500/a/ipd

Abstract: The report proposes a conceptual aggregation model for software acquisitions. The proposed approach relies on the immutability and auditability of blockchain technology. The model also enables automated, dynamic queries to the National Vulnerability Database (NVD) to continuously identify newly disc...

Project Pages

Human-Centered Cybersecurity (General)

https://csrc.nist.gov/projects/human-centered-cybersecurity/research-areas/human-centered-cybersecurity-general

Our team often writes articles or provides presentations that discuss and provide information about human-centered cybersecurity to various audiences, for example, cybersecurity practitioners or fellow researchers. We are co-hosting the Human-Centered Cybersecurity Series for the Redefining Cybersecurity Podcast (see General Human-Centered Cybersecurity -> Podcasts below). Currently, we are conducting a multi-phased research project to understand the interactions between human-centered cybersecurity researchers and practitioners. We hope the results will lead to the creation of mutually...

Project Pages

Membership

https://csrc.nist.gov/projects/ispab/members

FY 2026 ISPAB BOARD MEMBERS Steven Lipner, Chairperson Executive Director SAFECode Term Expires 5/30/2026 Edna Conway CEO & Founder EMC Advisors Term Expires 1/19/2030 Anne Dames Distinguished Engineer International Business Machines (IBM) Term Expires 11/24/2028 Michael Duffy Associate Director for Capacity Building CISA Cybersecurity Division, Department of Homeland Security Term Expires 3/13/2028 Jessica Fitzgerald-McKay Co-Lead, Center for Cyber Security Standards (CCSS) National Security Agency Term Expires 3/3/2027 Alex Gantman Vice President, Security Engineering: Head of...

<< first   < previous   1     2     3     4     5     6     7     8     9     10     11     12     13     14     15     16     17     18     19     20     21     22     23     24     25  next >  last >>