nisttrade-pressNewsThe Broadside2 min read

NIST and CISA finalize token-fraud guidance for federal agencies

A mandate first written under Biden and preserved in Trump's 2025 cyber executive order produced a final interagency report that 250 public comments and a year of industry consultation shaped, rare continuity on identity-layer defense.


TL;DR

NIST and CISA released the final version of NIST IR 8587 on September 15, 2026, giving federal agencies and cloud service providers implementation guidance on protecting identity tokens and assertions from forgery, theft, and misuse. The publication expands on NIST SP 800-53 controls and incorporates nearly 250 public comments on token validation, secrets management, and detection. New in the final version: outcome-based cryptographic key guidance, high-level considerations for AI and post-quantum cryptography migration, and expanded options for token revocation and signal-sharing.

NIST and CISA finalize token-fraud guidance for federal agencies
Editorial illustration · drawn by The Broadside

NIST IR 8587 (full title Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers) is the product of a mandate that originated in a Biden-era capstone cyber executive order and was preserved when the Trump administration issued its own EO in 2025. The tasking survived both White Houses without revision, which is worth noting in a domain where program-level priorities routinely shift with administrations.

The report's scope is narrower than its title suggests. It focuses on the tokens and signed assertions that underpin single sign-on, federation, and API-based access in hybrid and multi-cloud environments, the identity plumbing that, when compromised, lets an adversary move laterally across agency systems. The authors cite one breach in which attackers used a single stolen commercial signing key to forge tokens and exfiltrate over 60,000 emails from an agency.

What the final version changed

The December 2025 public draft drew nearly 250 comments. The final report incorporates that feedback in several specific ways: cryptographic key protection guidance is now less prescriptive and more outcome-based; key usage, protection, and storage recommendations are expanded; and new high-level considerations address AI systems and migration to post-quantum cryptography standards, though NIST is clear these are not comprehensive. The publication also adds references to current and emerging standards and provides more options for token revocation and sharing signals between organizations.

CISA facilitated industry engagement through the Joint Cyber Defense Collaborative, including a technical exchange with over 50 experts in June 2025 and a webinar on the draft in January 2026. The agency also held individual meetings with major CSPs, Google, Microsoft, Okta, AWS, HashiCorp, IBM, Oracle, Wiz, and the OpenID Foundation, among others.

What it means Monday

For federal agencies, the publication is implementation guidance, not a binding operational directive. CISA hasn't indicated whether it will tie compliance to a BOD or fold these recommendations into a FedRAMP baseline. Until that happens, the document sits in the category of "strongly recommended" that contractors know well. The practical weight depends on whether agency CISOs and cloud service providers treat it as a reference or a checklist.

NIST Digital Identity Program Lead Ryan Galluzzo framed the audience broadly: "Anyone who is using tokens as part of their access management infrastructure can look to this for insights, whether they are in government or commercial industry." That's accurate as a statement of applicability, but the document's primary lever is the federal procurement and authorization ecosystem, agencies adopt it, CSPs follow to keep the business, and the practices ripple outward.


Published ·Deep Fathom