NIST released the initial public draft of SP 800-213 Revision 1, titled IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, updating how agencies and other organizations define cybersecurity requirements for IoT products and incorporate them into system risk management. The revision replaces narrower references to "devices" with "products," adds clearer language and more relevant content, and stresses that integrating an IoT product into an information system can alter the system’s risk profile and require additional or different security controls.
The draft is part of a broader NIST effort to modernize practical IoT security guidance through its Cybersecurity for the Internet of Things Program. NIST said feedback from the Cybersecurity for IoT Workshop: Future Directions, captured in NIST IR 8618, will help shape updates to SP 800-213 and future guidance, including possible next steps for SP 800-213A and a longer-term framework aimed at helping risk managers and CISOs make contextual, operational IoT security decisions. The public comment period for the draft remains open through August 24, 2026.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
NIST published an update on its Cybersecurity for the Internet of Things Program describing the SP 800-213 Revision 1 draft, planned consideration of next steps for SP 800-213A, forthcoming IR 8618 proceedings, and development of a future framework for contextual IoT security decision-making. The update also invited stakeholder feedback through NIST's IoT security program outreach.
NIST participated in Unify 2026 through a June 17 panel titled "Security by Design Across Alliance Standards." The panel focused on embedding security principles across standards and on harmonized security frameworks to support interoperability and reduce certification complexity.
NIST published a notice stating that NIST IR 8618 summarizes presentations and feedback from the March 31 to April 1 workshop and that the output is intended to inform updates to SP 800-213 and future IoT cybersecurity guidelines. The notice also said NIST planned to release the initial public draft of SP 800-213 Revision 1 on June 24.
NIST's Cybersecurity for IoT Workshop: Future Directions continued through April 1, concluding discussions on stakeholder needs, accessibility of IoT security guidance, and future directions for NIST guidance. The proceedings were later slated for publication as NIST IR 8618.
NIST held the hybrid "Cybersecurity for IoT Workshop: Future Directions" to examine emerging and future IoT technology trends and their impact on IoT cybersecurity. The workshop gathered feedback intended to inform updates to SP 800-213 and future IoT cybersecurity guidelines.
NIST's Cybersecurity for IoT Program released the initial public draft of Special Publication 800-213r1, "IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements." The draft updates guidance for establishing cybersecurity requirements for IoT products and accounting for them in system risk management.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
nist.gov
Open sourcecsrc.nist.gov
Open sourcecsrc.nist.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.