nisttrade-pressNewsThe Broadside1 min read

NIST opens SP 800-213A comment as scope question surfaces

Third IoT guidance revision in two years, and NIST still hasn't settled whether the catalog controls devices or products.


TL;DR

NIST opened a pre-draft comment period on SP 800-213A, the federal IoT device cybersecurity requirement catalog, with comments due October 15. The agency's explicitly asking whether the revised catalog should expand its scope from IoT devices to IoT products, bringing it in line with SP 800-213 Rev. 1, which made the same shift in June. For contractors and integrators supplying IoT products to federal agencies, this is the window to shape how the catalog defines compliance requirements. The alternative's inheriting definitions written without them.

NIST opened a pre-draft call for comments on SP 800-213A on August 31, inviting stakeholders to weigh in before the agency begins revising the IoT cybersecurity requirement catalog. Comments are due October 15. The call explicitly puts the scope question on the table: should the catalog cover IoT products, which can include multiple devices, backends, and mobile companions, or stay trained on devices alone?

This is the third significant move in NIST's IoT guidance refresh, and it's following a pattern. In June, NIST published the initial public draft of SP 800-213 Rev. 1, which shifted the core federal IoT guidance from devices to products. Now the companion catalog's up for the same question. NIST is presenting two paths: "the scope of SP 800-213A could be expanded to IoT products, or the scope could remain IoT devices with additional guidelines used for IoT product components." The agency's also soliciting input on novel IoT use cases and on which foundational guidelines should inform the revision.

For contractors and integrators, the distinction matters. A product-level scope means the catalog's capability requirements apply to the full system the agency buys: the sensor, the gateway, the mobile app, the cloud backend, and the integration layer. A device-level scope keeps those pieces in separate compliance buckets. The October 15 deadline is the only opportunity to influence which direction NIST takes before drafting begins.


Published ·Deep Fathom

NIST opens SP 800-213A comment as scope question surfaces — The Broadside