Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Foundational Cybersecurity Activities for IoT Device Manufacturers



Michael J. Fagan, Katerina N. Megas, Karen Scarfone, Matthew Smith


Internet of Things (IoT) devices often lack device cybersecurity capabilities their customers-- organizations and individuals--can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by improving how securable the IoT devices they make are by providing necessary cybersecurity functionality and by providing customers with the cybersecurity-related information they need. This publication describes recommended activities related to cybersecurity that manufacturers should consider performing before their IoT devices are sold to customers. These foundational cybersecurity activities can help manufacturers lessen the cybersecurity-related efforts needed by customers, which in turn can reduce the prevalence and severity of IoT device compromises and the attacks performed using compromised devices.
NIST Interagency/Internal Report (NISTIR) - 8259
Report Number


cybersecurity risk, Internet of Things (IoT), manufacturing, risk management, risk mitigation, securable computing devices, software development


Fagan, M. , Megas, K. , Scarfone, K. and Smith, M. (2020), Foundational Cybersecurity Activities for IoT Device Manufacturers, NIST Interagency/Internal Report (NISTIR), National Institute of Standards and Technology, Gaithersburg, MD, [online], (Accessed July 25, 2024)


If you have any questions about this publication or are having problems accessing it, please contact

Created May 29, 2020