[go: up one dir, main page]

You have JavaScript disabled. This site requires JavaScript to be enabled for complete site functionality.

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST IR 8259 Rev. 1 (2nd Public Draft)

Foundational Cybersecurity Activities for IoT Product Manufacturers

Date Published: September 30, 2025
Comments Due: December 10, 2025 (public comment period is CLOSED)
Email Questions to: [email protected]

Planning Note (11/13/2025):

The public comment period has been extended through December 10, 2025.


Author(s)

Michael Fagan (NIST), Katerina Megas (NIST), Barbara Cuthill (NIST), Jeffrey Marron (NIST), Brad Hoehn (HII)

Announcement

This document describes recommended activities related to cybersecurity for manufacturers, spanning pre-market and post-market, to help them develop products that meet their customers’ needs and expectations for cybersecurity. This second public draft builds on changes made in the first draft and responds to feedback primarily in:

  • Splitting and adding activities to better focus attention on each separate critical activities
  • Expanding emphasis on risk assessment and threat modeling as key parts of the development process
  • Expanding the connection to other references and make connection of this document to other work more explicit

We encourage sending emailed comments to [email protected] and look forward to hearing from you.

Abstract

Keywords

cybersecurity risk; Internet of Things (IoT); manufacturing; risk management; risk mitigation; securable computing devices; software development
Control Families

None selected

Documentation

Publication:
https://doi.org/10.6028/NIST.IR.8259r1.2pd
Download URL

Supplemental Material:
Cybersecurity Insights blog post

Document History:
05/13/25: IR 8259 Rev. 1 (Draft)
09/30/25: IR 8259 Rev. 1 (Draft)

Topics

Security and Privacy

risk management

Applications

Internet of Things

Laws and Regulations

Internet of Things Cybersecurity Improvement Act

Sectors

manufacturing