Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Drafts Open for Comment

Feeds:      RSS/Atom      JSON

Many of NIST's cybersecurity and privacy publications are posted as drafts for public comment. Comment periods are still open for the following publications. Select the publication title to access downloads, related content, and instructions for submitting comments. Your thoughtful reviews and comments are greatly appreciated and help us to improve our standards and guidance.

Also see a complete list of public drafts that includes those whose comment periods have closed.

NIST has released initial working drafts of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM...

NIST has released initial working drafts of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM...

NIST has released initial working drafts of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM...

NIST Internal Report (IR) 8613 ipd (initial public draft), Multi-Cloud Architecture Challenges, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or significantly amplified by multi-cloud architectures. This analysis by the NIST Multi-Cloud Security...

Per the Sept. 29, 2026, Executive Order on Inaugurating the Era of Super Intelligence, NIST is working to update its communications to incorporate the term “super intelligence” as directed. This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing,...

Following the publication of draft revision IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, NIST SP 800-213 Rev. 1, NIST has initiated the process of revising the companion document IoT Device Cybersecurity Guidance for the...

Revision 1 updates the referenced specification to IEEE Std. 1619-2025 and clarifies NIST’s requirements for the approved use of XTS-AES, including its scope of use, data-unit and key-scope limits, key requirements, and the ordering convention for ciphertext stealing. Rather than reproducing the...

This initial public draft details how the availability of inexpensive, off-the-shelf hardware and software tools allows attackers to mimic legitimate carrier equipment to intercept and disrupt cellular communications. The paper evaluates how 5G devices respond to six simulated false base station...

Federal agencies that deploy an Open Radio Access Network (O-RAN) as part of their infrastructure must include that deployment in their risk management programs. This draft Cybersecurity Framework (CSF) 2.0 profile describes how components that conform to the security specifications produced by the...

This report provides guidelines for improving the security of Operational Technology (OT) systems while addressing their unique performance, reliability, and safety requirements.  OT encompasses a broad range of programmable systems or devices that interact with the physical environment (or manage...