Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Call for Comments on NIST’s IoT Device Cybersecurity Requirement Catalog | SP 800-213A

NIST is initiating a revision of Special Publication (SP) 800-213A, Internet of Things (IoT) Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, and has posted a Pre-Draft Call for Comments. This update

NIST is initiating a revision of Special Publication (SP) 800-213A, Internet of Things (IoT) Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, and has posted a Pre-Draft Call for Comments. This update aims to incorporate lessons learned, align with recent frameworks like CSF 2.0 and SP 800-53 Rev. 5.2.0, and address the evolving IoT threat landscape. This follows the draft update to SP 800-213 Rev. 1.

We are seeking public input and expert perspectives to ensure the revised catalog remains effective, relevant, and practical for managing IoT cybersecurity risks. Specifically, we welcome feedback on key topics, including expanding the scope to cover IoT products versus devices, emerging IoT use cases, tailored component deployments, and potential new source guidelines to incorporate.

Please submit your feedback to iotsecurity [at] nist.gov (iotsecurity[at]nist[dot]gov) with the subject line “Comments on SP 800-213A.” All public comments must be received by October 15, 2026. Visit our website to review the full list of review questions and submission guidelines.

Released August 31, 2026
Was this page helpful?