Key takeaways
- NIST opened a pre-draft comment period for SP 800-213A Revision 1 on August 31, 2026; comments are due October 15, 2026.
- The current catalog helps organizations translate system security needs into IoT device cybersecurity and supplier-support capabilities.
- NIST is considering whether the revised document should address complete IoT products, including elements such as backends and mobile applications, rather than only devices.
- Federal suppliers, integrators and agencies can use the consultation to flag practical issues in multi-component, off-the-shelf and operational-technology-connected deployments.
NIST begins revision process for SP 800-213A
The National Institute of Standards and Technology has begun the revision process for Special Publication 800-213A, the IoT Device Cybersecurity Requirement Catalog used alongside its federal IoT cybersecurity guidance. NIST posted a pre-draft call for comments on August 31, 2026, and will accept submissions through October 15, 2026.
The distinction matters for procurement and engineering teams: NIST has not issued a revised catalog or announced a new mandatory purchasing requirement. It is gathering input before preparing an initial revision. Still, the questions NIST has posed offer an early view of where the guidance may change and what product evidence federal buyers could eventually seek from manufacturers and integrators.
What the current catalog does
The existing SP 800-213A was finalized in November 2021. It supplies a catalog of technical cybersecurity capabilities that an IoT device may need to support security controls, as well as non-technical supporting capabilities expected from manufacturers and other supporting entities. The catalog cross-references these capabilities to NIST SP 800-53 security controls.
In practice, the document is intended to help federal organizations turn a system-specific risk assessment into device-level cybersecurity requirements. That makes it relevant to connected physical-security and facility technologies, including cameras, access-control panels, environmental sensors, gateways, building systems and management appliances, when those products are being evaluated for federal environments. Requirements are selected according to the organization’s system context and risk decisions; the catalog is not a one-size-fits-all product certification checklist.
The scope may move from devices to products
A central question in the consultation is whether SP 800-213A should remain focused on an individual IoT device or broaden to encompass an IoT product. NIST’s companion draft, SP 800-213 Revision 1, already uses the broader product framing. That model recognizes that a deployable solution can include a device plus hardware or software components needed for its smart functions, such as cloud or remote backends, companion applications, sensor base stations and protocol hubs.
For equipment teams, that change could make the cybersecurity conversation more complete. A camera, controller or sensor may be secure only in combination with its management platform, firmware-delivery path, identity service, mobile application or hosted service. If the catalog expands, vendors and integrators may need to provide clearer boundaries for those components, explain who operates each element and show how the combined product supports the customer’s security controls.
Custom assemblies and operational environments are in view
NIST is also asking how the catalog should address tailored deployments in which an organization combines commercial components into a subsystem resembling an IoT product. Its example is an assembly built from off-the-shelf elements such as a Raspberry Pi and sensors. This question is pertinent where integrators assemble monitoring, access, telemetry or control solutions from controllers, edge-compute devices, radios, power equipment and application software.
The wider SP 800-213 revision work has highlighted the convergence of IoT with operational technology. Building automation, physical access control and environmental monitoring can have long service lives, availability constraints and safety or resiliency considerations that differ from conventional IT. For integrators, a useful response to NIST would identify where a generalized device catalog is difficult to apply to installed systems, including component ownership, patch responsibility, network segmentation, remote management and replacement planning.
Alignment with newer NIST guidance is planned
NIST says the SP 800-213A update will incorporate lessons learned, reflect the evolving IoT threat landscape and align with current guidance including the Cybersecurity Framework 2.0 and SP 800-53 Revision 5.2.0. The agency is additionally seeking recommendations for other standards, practices and source documents that could inform the revised catalog.
NIST specifically asks reviewers how the document can better help practitioners select appropriate capabilities for different operational environments. That is an opportunity to comment on evidence that is useful during real acquisition and installation work: documented asset identity, supported authentication methods, secure configuration options, vulnerability handling, software-update practices, product lifecycle information, logging interfaces and dependencies on remote services. NIST has not proposed a final set of new capabilities, so organizations should avoid treating these potential topics as finalized requirements.
Recommended actions before the October deadline
Manufacturers selling into public-sector channels should compare their current product documentation with the 2021 catalog and identify gaps that arise when the device depends on software, cloud services or other product components. They should also document which cybersecurity functions are native to the equipment, which are supplied by an external platform and which must be configured by the deploying organization.
Federal contractors, distributors and system integrators can use the review period to collect practical feedback from project teams. Useful topics include the treatment of mixed-vendor systems, allocation of responsibilities among manufacturer, installer and customer, and the feasibility of assessing cybersecurity features in long-lived or difficult-to-service deployments. Comments submitted to NIST will become part of the public record, so contributors should not include confidential business information or personal data.
Sources
- PRE-DRAFT Call for Comments: IoT Device Cybersecurity Requirement Catalog, NIST SP 800-213A Rev. 1 — NIST Computer Security Resource Center
- Call for Comments on NIST’s IoT Device Cybersecurity Requirement Catalog | SP 800-213A — National Institute of Standards and Technology
- IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog, NIST SP 800-213A — NIST Computer Security Resource Center
- IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, NIST SP 800-213 Rev. 1 Initial Public Draft — NIST Computer Security Resource Center
