NIST has released a new draft update to its Internet of Things cybersecurity guidance for federal agencies, giving security and risk teams a clearer way to evaluate connected products before they enter an organization’s environment.
The draft, NIST SP 800-213 Rev. 1, focuses on how federal agencies should establish cybersecurity requirements for IoT products. In plain English, that means agencies need to think about connected products before they are purchased, deployed, and connected to systems that carry operational or sensitive data.
The story matters beyond the federal government because NIST guidance often shapes how security teams, vendors, contractors, and enterprise buyers think about cybersecurity expectations. The draft also reflects a larger shift in security governance. Connected products are no longer being treated as small device purchases. They are part of the organization’s risk picture.
For CISOs, compliance teams, privacy leaders, procurement teams, and risk owners, the message is practical. A connected camera, badge reader, sensor, building system, medical device, or piece of operational equipment can create new risks. Those risks need to be assessed, assigned, controlled, documented, and reviewed over time.

Background
On June 24, 2026, NIST released the initial public draft of SP 800-213 Rev. 1, titled IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements. The draft is open for public comment through August 24, 2026.
The publication updates NIST’s earlier IoT cybersecurity guidance for federal agencies. The original guidance focused heavily on IoT devices. The new draft uses the broader term “IoT products,” which is important because connected technology is rarely just one physical device anymore.
An IoT product may include hardware, software, firmware, cloud services, remote support, mobile apps, update mechanisms, and vendor-managed components. A smart camera may depend on a cloud platform. A building system may rely on a remote management portal. A sensor may transmit data to a third-party service. A medical or industrial product may include embedded software that the customer cannot fully inspect or manage.
NIST is telling agencies to consider how these products fit into the systems they join. Once an IoT product becomes part of an information system, it can affect the system’s risk assessment. If the risk changes, agencies may need to select new controls or adjust existing ones.
What NIST Means by IoT Products
IoT stands for Internet of Things. It refers to physical products that connect to networks, exchange data, or interact with digital systems. In an enterprise setting, this can include security cameras, smart locks, badge readers, sensors, printers, connected appliances, building automation systems, clinical equipment, industrial systems, and other connected products.
For many organizations, these products do not always enter through the same process as traditional IT systems. A business unit may buy them. Facilities may manage them. Operations may install them. A vendor may maintain them. IT or security may only become involved after the product is already connected.
That creates a governance problem. The organization may not have a complete view of what the product does, what data it collects, where that data goes, how updates are handled, or who is responsible for security decisions after deployment.
NIST’s draft addresses that gap by treating IoT products as part of the system risk picture. The question is not only whether the product has security features. The better question is how the product changes the risk of the environment it joins.
A connected product can introduce new access paths, new vendor dependencies, new patching needs, new logging requirements, new privacy issues, and new operational dependencies. Those issues need to be understood before approval and managed after deployment.
Is This More Than Device Security?
For years, IoT cybersecurity was often discussed as a device issue. Security teams looked at whether a device had default passwords, whether firmware could be updated, whether encryption was supported, or whether access could be restricted.
That is why the shift from “device” to “product” is meaningful. NIST is recognizing that the security of connected technology depends on the full product environment, not just the physical device.
What Remains Unclear
The NIST document is still a draft. The final version may change after the public comment period. Organizations should not treat every detail as a finished requirement.
It is also not yet clear how quickly the guidance will influence procurement language outside federal agencies. Some organizations may adopt parts of it quickly. Others may wait for final guidance or for customer pressure to build.
Another open question is how organizations will operationalize the guidance. Many already have asset inventories, vendor reviews, risk registers, control libraries, and procurement workflows. The challenge is connecting those processes so IoT products do not fall between departments.
GRC Takeaway
Organizations should use NIST’s draft as a prompt to review how connected products enter their environment.
The strongest starting point is the intake process. Before a connected product is purchased or deployed, teams should know what it connects to, what data it handles, who supports it, how updates work, what vendor dependencies exist, and what controls are required.
The next step is ownership. Every connected product should have a clear business owner, a technical owner, and a risk owner. Without ownership, IoT security becomes reactive.
The third step is evidence. Vendor responses, security documentation, risk assessments, control mappings, approvals, exceptions, and remediation plans should be kept in a way that supports audits and internal reporting.
Finally, organizations should treat IoT risk as ongoing. A connected product can change after deployment. Vendors may update services. Support windows may expire. Vulnerabilities may be disclosed. Business use may expand. A product that was acceptable at approval may need a new review later.
FAQs
Is NIST SP 800-213 Rev. 1 a new regulation?
No. It is draft NIST guidance for federal agencies. It is not a final regulation. Still, NIST guidance often influences procurement standards, vendor expectations, and enterprise cybersecurity practices.
Why does the draft focus on IoT products instead of IoT devices?
A connected product is often more than a physical device. It may include software, cloud services, vendor support, mobile apps, and update mechanisms. That broader view gives organizations a more realistic way to assess risk.
What kinds of products does this apply to?
It can apply to connected cameras, badge readers, sensors, smart building systems, connected medical equipment, industrial systems, and other products that connect to networks or exchange data.


