Back to signals
NIST draft for commentGuidance and regulationPublished August 31, 2026

SP 800-213A Rev. 1, PRE-DRAFT Call for Comments: IoT Device Cybersecurity Requirement CatalogInitial Preliminary Draft

Following the publication of draft revision IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, NIST SP 800-213 Rev. 1, NIST has initiated the process of revising the companion document IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, NIST SP 800-213A, to incorporate lessons learned, align with relevant NIST guidance (e.g., Cybersecurity Framework (CSF) 2.0, NIST SP 800-53 Rev. 5.2.0)-as well as IoT cybersecurity standards and practices, and address changes in the IoT threat landscape. We welcome any valuable perspectives on potential revisions to the current SP 800-213A to maximize the document's effectiveness, relevance, and usability in helping the community understand and manage cybersecurity risk. To help guide this input, NIST has included specific questions below, though reviewers are encouraged to address any, all, or additional topics in their comments. The public comment period is open through October 15, 2026. Submit comments via email to iotsecurity@nist.gov with the subject line “Comments on SP 800-213A.” Specifically, NIST asks for…

Open the source record
Tags
NIST, draft open for comment, SP 800-213A REV. 1
Related exam domains
CISSP 1: Security and Risk Management; CISM 1: Information Security Governance; CISM 2: Information Security Risk Management
Source record id
https://csrc.nist.gov/pubs/sp/800/213/a/r1/iprd
First seen by InfoSec Signals
9/23/2026

Exam domain labels come from a keyword heuristic and are study hints, not an official mapping. The summary is the publisher's own text, shortened; the linked record is authoritative.