Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

News & Updates

Stay informed as the Information Technology Laboratory’s Cybersecurity and Privacy Program releases publications, schedules virtual and in-person events, and announces other important developments.

Subscribe to our email updates.

Visit these additional NIST sites to learn more about:

  • NVD: National Vulnerability Database news and status updates
  • NICE: National Initiative for Cybersecurity Education news and events
  • NCCoE: National Cybersecurity Center of Excellence news and events
  • NIST-wide cybersecurity and privacy news and events
 
Showing 47 matching records.
August 27, 2026

NIST has released Internal Report (IR) 8611, m-NGAC: Transcending Traditional Database Security Models.

August 25, 2026

The final version of NIST Special Publication (SP) 1347, NIST Cybersecurity Framework (CSF) 2.0: Informative References Quick-Start Guideis now available

August 21, 2026

NIST IR 8613 ipd, Multi-Cloud Architecture Challenges, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis addresses security and ATO challenges and highlights areas where additional community research could meaningfully reduce risk.

August 19, 2026

NIST has released the initial public draft of Special Publication (SP) 1353, Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and Reporting. The public comment period is open through October 15, 2026.

August 6, 2026

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft Cybersecurity White Paper (CSWP) 36F, Initial Non-Access Stratum (NAS) Message Security, which describes a 5G security feature that protects sensitive information in the Initial Non-Access Stratum (NAS) Message and explains how organizations can verify these protections in deployed 5G networks.

August 5, 2026

NIST's NCCoE announces the release of the final NIST Interagency Report (IR) 8576, Transit Cybersecurity Framework (CSF) Community Profile.

July 27, 2026

NIST invites public comments on the initial public draft (ipd) of Special Publication (SP) 800-239, AI Data Center Security Analysis: A High-Performance Computing (HPC) Driven Approach. The public comment period is open through September 25, 2026.

July 22, 2026

The initial public draft (ipd) of NIST Special Publication (SP) 800-209r1, Security Guidelines for Storage Infrastructure, is now available for public comment through September 8, 2026.

July 8, 2026

This Quick-Start Guide based on the widely adopted content in NIST SP 800-161r1 proposes an implementation-ready approach to conducting the minimum amount of reasonable research and investigative rigor on potential suppliers.

June 30, 2026

NIST has released Special Publication (SP) 800-18r2 (Revision 2), Developing Security, Privacy, and Cybersecurity Supply Chain Risk Management Plans for Systems. This revision broadens the scope of system planning to encompass three interconnected plan types that are collectively referred to as "system plans". Essential system plan elements are correlated with the steps and tasks of the NIST Risk Management Framework (RMF) to provide a streamlined approach to system plan development. 

June 25, 2026

The NCCoE is seeking feedback on the draft Project Description Asset Management as a Foundation for OT Cybersecurity , outlining the proposed scope, challenges, and technical approach for the project.

June 24, 2026

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the final version of NIST Special Publication 1800-45, "Cybersecurity for the Water and Wastewater Sector: Build Architecture", demonstrating how to securely enable remote access to operational technology for critical infrastructure.  

June 24, 2026

The NIST Cybersecurity for IoT Program has released the initial public draft of Special Publication (SP) 800-213r1 (Revision 1), "IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements." The public comment period ends August 24, 2026.

June 22, 2026

NIST requests comments on the initial public draft (ipd) of Special Publication (SP) 800-219r2 (Revision 2), Automated Secure Configuration Guidance From the macOS Security Compliance Project (mSCP).

June 17, 2026

NIST publishes NIST Internal Report (IR) 8618, Summary Report for “Cybersecurity for IoT Workshop: Future Directions”.

June 17, 2026

The NIST National Cybersecurity Center of Excellence (NCCoE) has published NIST Special Publication (SP) 1339, Operational Technology Backup Quick Start Guide

June 12, 2026

NIST has released initial working drafts of proposed updates to the PIV standards, including an overview of expected changes to support post-quantum cryptography in PIV credentials.

June 11, 2026

NIST IR 8374r1, "Ransomware Risk Management: A Cybersecurity Framework (CSF) 2.0 Community Profile," is now available.

June 8, 2026

NIST announces the release of Special Publication (SP) 800-126r4 (Revision 4), Technical Specification for the Security Content Automation Protocol (SCAP): SCAP Version 1.4, and SP 800-126Ar4, SCAP 1.4 Component Specification Version Updates: An Annex to NIST SP 800-126r4.

June 1, 2026

NIST is revising Special Publication 800-38D, Recommendation for Block Cipher Modes of Operation: Galois/Counter Mode (GCM) and GMAC. The public comment period is open through July 31, 2026.

May 29, 2026

NIST Interagency Report (NIST IR) 8320E ipd (initial public draft), Hardware-Enabled Security: Confidential Computing of Data in Cloud Workloads, is open for public comment through July 13, 2026.

May 21, 2026

NIST has published Special Publication (SP) 800-238, FY 2025 NIST Cybersecurity and Privacy Program Annual Report.

May 21, 2026

The NIST National Cybersecurity Center of Excellence (NCCoE) has released the initial public draft of NIST Special Publication 1800-41, Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector. Public comments are due by July 8th. This report provides guidelines on response and recovery activities in an industrial control system (ICS) environment and recommendations to improve operational resilience.

May 19, 2026

NIST Internal Report (IR) 8500A ipd (initial public draft), Blockchain-Based Secure Software Assets Management (BloSS@M), outlines a modernized conceptual approach for transforming how software assets are acquired, tracked, and secured across an interagency ecosystem.

May 18, 2026

The initial public draft of NIST Special Publication (SP) 800-228A is available for public comment. The comment period is oopen through July 2, 2026.

May 14, 2026

NIST Internal Report (IR) 8610 announces nine candidates advancing to the third round of the Additional Digital Signatures for the Post-Quantum Cryptography (PQC) Standardization Process.

May 13, 2026

As part of ongoing efforts to strengthen protections for securing controlled unclassified information (CUI) in nonfederal systems, NIST has released SP 800-172r3, Enhanced Security Requirements for Protecting Controlled Unclassified Information, and SP 800-172Ar3, Assessing Enhanced Security Requirements for Controlled Unclassified Information

May 8, 2026

The final version of NIST Special Publication (SP) 800-70r5 (Revision 5), National Checklist Program for IT Products – Guidelines for Checklist Users and Developers, is now available.

May 7, 2026

NIST's Crypto Publication Review Board invites comments on Special Publication (SP) 800-52 Revision 2, "Guidelines for the Selection, Configuration, and Use of TLS Implementations." The comment period is open through July 10, 2026.

May 6, 2026

The NIST NCCoE has released the draft NIST Internal Report (IR) 8323 Revision 2, "Foundational PNT Profile: Applying the Cybersecurity Framework for the Responsible Use of Positioning, Navigation, and Timing (PNT)." The public comment period is open through July 6, 2026.

May 5, 2026

This announcement is a pre-draft call for comments to solicit preliminary feedback on SP 800-38F. The public comment period is open through July 10, 2026.

May 4, 2026

NIST Special Publication 800-234 (final) is now available.

April 20, 2026

NIST's Cybersecurity for IoT Program is releasing Revision 1 of NIST IR 8259, "Foundational Cybersecurity Activities for IoT Product Manufacturers."

April 17, 2026

The initial public draft (ipd) of NIST Special Publication (SP) 800-133r3 (Revision 3), "Recommendation for Cryptographic Key Generation," is open for public comment through June 16, 2026.

April 15, 2026

NIST has published Cybersecurity White Paper (CSWP) 52, "Firmware-Based Monitoring for Bus-Based Computer Systems," introducing a low-cost, innovative approach to enhancing hardware security visibility.

April 14, 2026

NIST has released a new public draft of Small Business Cybersecurity: Non-Employer Firms. The public comment period is open through May 14, 2026.

April 13, 2026

NIST releases the initial public draft of SP 800-230, Additional SLH-DSA Parameter Sets for Limited Signature Use Cases. The comment period closes on June 12, 2026.

March 23, 2026

The final release of NIST Special Publication 1308, "NIST CSF 2.0: Cybersecurity, Enterprise Risk Management, and Workforce Management QSG," is now available. Also, NIST requests public comments on SP 1347, "CSF 2.0 Informative References Quick-Start Guide." The public comment period ends 

March 19, 2026

NIST Publishes SP 800-81r3: Secure Domain Name System (DNS) Deployment Guide final version

March 19, 2026

"Applying 5G Cybersecurity and Privacy Capabilities" white paper series helps consumers and operators of 5G networks securely adopt this technology as the development, deployment, and usage of 5G simultaneously evolves.

March 18, 2026

The NCCoE has released an initial public draft of NIST Special Publication (SP) 1800-42A, "Digital Identities - Mobile Driver’s License (mDL): Accelerating Development and Adoption of Digital Identity for Financial Institutions." The public comment period is open through May 8, 2026.

February 12, 2026

This guide demonstrates how organizations can discover, identify and label unstructured data using data classification practices. The public comment period is open through March 30, 2026.

January 29, 2026

NIST has published the final version of Interagency Report (IR) 8446, which compares Germany’s BSI AIS 20/31 and NIST’s SP 800-90 series.

January 22, 2026

The NIST National Cybersecurity Center of Excellence (NCCoE) has released a draft of NIST Interagency Report (IR) 8576, Transit Cybersecurity Framework (CSF) Community Profile, which is available for public comment through February 23, 2026.

January 22, 2026

NIST has initiated the process of revising NIST SP 800-82, Guide to Operational Technology (OT) Security, to incorporate lessons learned, align with relevant NIST guidance and OT cybersecurity standards and practices, and address changes in the OT threat landscape.

January 20, 2026

NIST has published Internal Report (IR) 8214C, NIST First Call for Multi-Party Threshold Schemes.

January 6, 2026

After receiving public comments in response to its July 2025 proposal, NIST has decided to update SP 800-56Ar3 and revise SP 800-56Cr2.

* "Relevance" merely indicates the search engine's score for a document. It is based on the search parameters and information in the document's detailed record.