Use this form to search content on CSRC pages.
Short URL: https://www.nist.gov/pqcrypto For a plain-language introduction to post-quantum cryptography, see What Is Post-Quantum Cryptography? PQC Standards | Migration to PQC | Ongoing PQC Standardization Process NIST’s Post-Quantum Cryptography (PQC) project leads the national and global effort to secure electronic information against the future threat of quantum computers—machines that may be years or decades away but could eventually break many of today’s widely used cryptographic systems. Through a multi-year international competition involving industry, academia, and...
Thanks for helping shape our ransomware guidance! We've published our final version of NIST IR 8374 Revision 1, Ransomware Risk Management: A Cybersecurity Framework Profile. It reflects changes made to the Cybersecurity Framework (CSF) from CSF 1.1 to CSF 2.0 which identifies security objectives that support managing, detecting, responding to, and recovering from ransomware events. NIST is still actively seeking feedback on resources that can help communities prepare for and recover from ransomware attacks. Please reach out to us at [email protected] NIST has also previously published...
NIST IR 8374r1, "Ransomware Risk Management: A Cybersecurity Framework (CSF) 2.0 Community Profile," is now available.
Abstract: Ransomware is a type of malicious attack where attackers encrypt an organization’s data and demand payment to restore access. Attackers may also steal an organization’s information and demand an additional payment in return for not disclosing the information to authorities, competitors,...
Assessing Security Requirements for Controlled Unclassified Information Purpose Assessment procedures and a methodology that can be employed to conduct assessments of the CUI security requirements in NIST SP 800-171. Scope A system security plan describes how the SP 800-171 security requirements are met. The plan describes the system boundary; the environment in which the system operates; how the requirements are implemented; and the relationships with or connections to other systems. The scope of the assessments conducted using the procedures described in SP 800-171A are guided and...
Protecting Controlled Unclassified Information (CUI) in nonfederal systems and organizations is critical to federal agencies. The suite of guidance (NIST Special Publication (SP) 800-171, SP 800-171A, SP 800-172, and SP 800-172A) focuses on protecting the confidentiality of CUI and recommends specific security requirements to achieve that objective. Recent Updates May 13, 2026: NIST issues SP 800-172r3, Enhanced Security Requirements for Protecting Controlled Unclassified Information, and SP 800-172Ar3, Assessing Enhanced Security Requirements for Controlled Unclassified...
Our conference and journal papers on assured autonomy and explainable AI. We try to include links to the full papers, but for those not yet linked, please contact us for a copy: [email protected]. Papers 2025 Lanus, E., Lee, B., Chandrasekaran, J., Freeman, L. J., Raunak, M. S., Kacker, R. N., & Kuhn, D. R. (2025, March). Data frequency coverage impact on ai performance. In 2025 IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW) (pp. 258-267). IEEE. Wei, Q., Sikder, F., Feng, H., Lei, Y., Kacker, R., & Kuhn, R. (2025). SmartExecutor:...
Workshops Date September 24-26, 2025 Sixth PQC Standardization Conference (In-Person / Virtual) Venue: NIST Gaithersburg, Maryland, USA Call for Papers April 10-12, 2024 Fifth PQC Standardization Conference (In-Person) Hilton Washington DC/Rockville Hotel Rockville, MD Call for Papers November 29- December 1, 2022 Fourth PQC Standardization Conference Virtual Call for Papers June 7-9, 2021 Third...
Common Platform Enumeration (CPE) is a standardized method of describing and identifying classes of applications, operating systems, and hardware devices present among an enterprise's computing assets. CPE names product classes rather than specific installed instances, which lets security tools make consistent, automated decisions for asset management, vulnerability management, and configuration management. This page is the entry point for the CPE specification. It gives a high-level overview of the CPE versions and the work now under way on the next major revision. Each version has its own...
CPE 3.0 is the next major revision of Common Platform Enumeration (CPE), now in early development at NIST. This page tracks the effort and how to take part. For the current published version, see Common Platform Enumeration (CPE). About the CPE 3.0 effort CPE 2.3 has been in wide use for more than a decade. Implementation experience over that period, together with current security automation needs, has surfaced a set of issues worth addressing in a future version. The CPE 3.0 effort will evaluate how platforms and products are identified for current security automation use cases, including...
NIST Interagency Report (NIST IR) 8320E ipd (initial public draft), Hardware-Enabled Security: Confidential Computing of Data in Cloud Workloads, is open for public comment through July 13, 2026.
Abstract: Confidential computing addresses data security and privacy concerns for organizations that move sensitive workloads to the cloud. It is a critical advancement that enables the encryption of data both while it is being processed in memory and in active use. As cloud adoption continues to grow, confid...
The National Institute of Standards and Technology (NIST) Human-Centered Cybersecurity program, which is part of the Human-Centered Technologies Group (formerly named Visualization and Usability Group), seeks to "champion the human in cybersecurity" by conducting interdisciplinary research to better understand and improve people’s interactions with cybersecurity systems, products, processes, and services. Be sure to connect with NIST and the Human-Centered Cybersecurity program on social media and subscribe to GovDelivery to stay apprised of our latest research....
NIST has published Special Publication (SP) 800-238, FY 2025 NIST Cybersecurity and Privacy Program Annual Report.
The NIST National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft of NIST Special Publication 1800-41, Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector. Public comments are due by July 8th. This report provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience.
Abstract: Throughout Fiscal Year 2025 (FY 2025) — from October 1, 2024, through September 30, 2025 — the NIST Information Technology Laboratory (ITL) Cybersecurity and Privacy Program successfully responded to numerous challenges and opportunities in security and privacy. This Annual Report highli...
Abstract: Industrial Control Systems (ICS) that operate manufacturing environments play a critical role in the supply chain. Manufacturing organizations rely on control systems to monitor and control physical processes that produce goods for public consumption. These same systems are facing an increasing numb...
Type: Presentation
Type: Presentation
NIST Internal Report (IR) 8500A ipd (initial public draft), Blockchain-Based Secure Software Assets Management (BloSS@M), outlines a modernized conceptual approach for transforming how software assets are acquired, tracked, and secured across an interagency ecosystem.
Abstract: The report proposes a conceptual aggregation model for software acquisitions. The proposed approach relies on the immutability and auditability of blockchain technology. The model also enables automated, dynamic queries to the National Vulnerability Database (NVD) to continuously identify newly disc...
Our team often writes articles or provides presentations that discuss and provide information about human-centered cybersecurity to various audiences, for example, cybersecurity practitioners or fellow researchers. We are co-hosting the Human-Centered Cybersecurity Series for the Redefining Cybersecurity Podcast (see General Human-Centered Cybersecurity -> Podcasts below). Currently, we are conducting a multi-phased research project to understand the interactions between human-centered cybersecurity researchers and practitioners. We hope the results will lead to the creation of mutually...
FY 2026 ISPAB BOARD MEMBERS Steven Lipner, Chairperson Executive Director SAFECode Term Expires 5/30/2026 Edna Conway CEO & Founder EMC Advisors Term Expires 1/19/2030 Anne Dames Distinguished Engineer International Business Machines (IBM) Term Expires 11/24/2028 Michael Duffy Associate Director for Capacity Building CISA Cybersecurity Division, Department of Homeland Security Term Expires 3/13/2028 Jessica Fitzgerald-McKay Co-Lead, Center for Cyber Security Standards (CCSS) National Security Agency Term Expires 3/3/2027 Alex Gantman Vice President, Security Engineering: Head of...
Combinatorial approach Case studies