U.S. flag   An unofficial archive of your favorite United States government website
Dot gov

Official websites do not use .rip
We are an unofficial archive, replace .rip by .gov in the URL to access the official website. Access our document index here.


Secure websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to our website. Please do not share sensitive information with us.

This is an archive
(replace .gov by .rip)

SP 800-213 (Draft)

IoT Device Cybersecurity Guidance for the Federal Government: Establishing IoT Device Cybersecurity Requirements

Date Published: December 2020
Comments Due: February 26, 2021 (public comment period is CLOSED)
Email Questions to: iotsecurity@nist.gov

Planning Note (2/8/2021): The comment period has been extended to February 26, 2021.


Michael Fagan (NIST), Jeffrey Marron (NIST), Kevin Brady (NIST), Barbara Cuthill (NIST), Katerina Megas (NIST), Rebecca Herold (The Privacy Professor Consultancy)


This draft includes background and recommendations to help federal agencies consider how an IoT device they plan to acquire can integrate into a federal information system. IoT devices and their support for security controls are presented in the context of organizational and system risk management. SP 800-213 provides guidance on considering system security from the device perspective. This allows for the identification of IoT device cybersecurity requirements—the abilities and actions a federal agency will expect from an IoT device and its manufacturer and/or third parties, respectively.

Draft SP 800-213 is being released concurrently with these related IoT draft publications:

  • Draft NISTIR 8259BIoT Non-Technical Supporting Capability Core Baseline
  • Draft NISTIR 8259CCreating a Profile Using the IoT Core Baseline and Non-Technical Baseline
  • Draft NISTIR 8259DProfile Using the IoT Core Baseline and Non-Technical Baseline for the Federal Government 
See this announcement for more details about all four documents.

NOTE: A call for patent claims is included on page iv of this draft.  For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.



Risk Management Framework; Cybersecurity Framework; cybersecurity baseline; Internet of Things (IoT); security requirements; securable computing devices
Control Families

None selected


SP 800-213 (Draft) (DOI)
Local Download

Supplemental Material:
None available

Related NIST Publications:
NISTIR 8259B (Draft)
NISTIR 8259C (Draft)
NISTIR 8259D (Draft)

Document History:
12/15/20: SP 800-213 (Draft)


Security and Privacy
acquisition; program management; risk management


cybersecurity framework; Internet of Things