﻿{
  "title": "NIST Draft Publications Open for Comment",
  "subtitle": "Many of NIST's cybersecurity and privacy publications are posted as drafts for public comment. Comment periods are still open for the following publications. Visit the links for downloads, related content, and instructions for submitting comments. Your thoughtful reviews and comments are greatly appreciated and help us to improve our standards and guidance.",
  "updated": "2026-10-09T05:00:41.8496424-04:00",
  "id": "https://csrc.nist.gov/csrc/media/feeds/pubs/drafts-open-for-comment.xml",
  "link": "https://csrc.nist.gov/publications/drafts-open-for-comment",
  "entries": [
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/73/pt1/6/iwd",
      "title": "SP 800-73-6, Interfaces for Personal Identity Verification: Part 1 – PIV Card Application Namespace, Data Model and RepresentationInitial Working Draft",
      "summary": "<p>NIST has released <a href=\"https://pages.nist.gov/piv-standards\">initial working drafts</a> of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism with PIV.<o></o></p>\n<p>The <a href=\"https://pages.nist.gov/piv-standards\">current draft set</a> comprises:<o></o></p>\n<ul>\n<li>SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation<o></o></li>\n<li>SP 800-73 Part 2: PIV Card Application Card Command Interface<o></o></li>\n<li>SP 800-78: Cryptographic Algorithms and Key Sizes for PIV<o></o></li>\n</ul>\n<p>A supporting PQC Overview accompanies the drafts to present a working gap analysis of the specification changes needed across the PIV algorithm profile, command interface, and data model, and outline the general approach under consideration. This approach centers on a dual-stack model that preserves existing classical PIV keys and data objects; adds new key references, certificate containers, and data objects for PQC credentials; and supports backward compatibility and incremental deployment during the transition.<o></o></p>\n<p>These are preliminary working materials, not formal public drafts. By collaborating with implementers and users to develop these guidelines and specifications, NIST hopes to accelerate the standardization and implementation of PQC in PIV credentials.<o></o></p>\n<p>NIST welcomes feedback throughout the development process. Interested parties can follow the work and participate by:<o></o></p>\n<ul>\n<li><strong>Joining the public mailing list</strong> &mdash; Subscribe at <a href=\"mailto:piv-standards+subscribe@list.nist.gov\">piv-standards+subscribe@list.nist.gov</a>,&nbsp;and take part in discussions at <a href=\"mailto:piv-standards@list.nist.gov\">piv-standards@list.nist.gov</a>&nbsp;(<a href=\"https://groups.google.com/a/list.nist.gov/g/piv-standards\">archive</a>).<o></o></li>\n<li><a href=\"https://github.com/usnistgov/piv-standards\"><strong>Engaging on GitHub</strong></a> &mdash; Review the drafts, file issues, or open pull requests at the project repository.<o></o></li>\n</ul>",
      "published": "2026-06-12T00:00:00",
      "updated": "2026-06-12T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/73/pt1/6/iwd",
      "content": "No Due Date: Comment Period Remains Open"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/73/pt2/6/iwd",
      "title": "SP 800-73-6, Interfaces for Personal Identity Verification: Part 2 – PIV Card Application Card Command InterfaceInitial Working Draft",
      "summary": "<p>NIST has released <a href=\"https://pages.nist.gov/piv-standards\">initial working drafts</a> of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism with PIV.<o></o></p>\n<p>The <a href=\"https://pages.nist.gov/piv-standards\">current draft set</a> comprises:<o></o></p>\n<ul>\n<li>SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation<o></o></li>\n<li>SP 800-73 Part 2: PIV Card Application Card Command Interface<o></o></li>\n<li>SP 800-78: Cryptographic Algorithms and Key Sizes for PIV<o></o></li>\n</ul>\n<p>A supporting PQC Overview accompanies the drafts to present a working gap analysis of the specification changes needed across the PIV algorithm profile, command interface, and data model, and outline the general approach under consideration. This approach centers on a dual-stack model that preserves existing classical PIV keys and data objects; adds new key references, certificate containers, and data objects for PQC credentials; and supports backward compatibility and incremental deployment during the transition.<o></o></p>\n<p>These are preliminary working materials, not formal public drafts. By collaborating with implementers and users to develop these guidelines and specifications, NIST hopes to accelerate the standardization and implementation of PQC in PIV credentials.<o></o></p>\n<p>NIST welcomes feedback throughout the development process. Interested parties can follow the work and participate by:<o></o></p>\n<ul>\n<li><strong>Joining the public mailing list</strong> &mdash; Subscribe at <a href=\"mailto:piv-standards+subscribe@list.nist.gov\">piv-standards+subscribe@list.nist.gov</a>,&nbsp;and take part in discussions at <a href=\"mailto:piv-standards@list.nist.gov\">piv-standards@list.nist.gov</a>&nbsp;(<a href=\"https://groups.google.com/a/list.nist.gov/g/piv-standards\">archive</a>).<o></o></li>\n<li><a href=\"https://github.com/usnistgov/piv-standards\"><strong>Engaging on GitHub</strong></a> &mdash; Review the drafts, file issues, or open pull requests at the project repository.<o></o></li>\n</ul>",
      "published": "2026-06-12T00:00:00",
      "updated": "2026-06-12T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/73/pt2/6/iwd",
      "content": "No Due Date: Comment Period Remains Open"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/78/6/iwd",
      "title": "SP 800-78-6, Cryptographic Algorithms and Key Sizes for Personal Identity VerificationInitial Working Draft",
      "summary": "<p>NIST has released <a href=\"https://pages.nist.gov/piv-standards\">initial working drafts</a> of proposed updates to the Personal Identity Verification (PIV) standards to support the use of post-quantum cryptography (PQC). The drafts identify the changes expected to be needed to use the ML-DSA digital signature algorithm and the ML-KEM key-encapsulation mechanism with PIV.<o></o></p>\n<p>The <a href=\"https://pages.nist.gov/piv-standards\">current draft set</a> comprises:<o></o></p>\n<ul>\n<li>SP 800-73 Part 1: PIV Card Application Namespace, Data Model, and Representation<o></o></li>\n<li>SP 800-73 Part 2: PIV Card Application Card Command Interface<o></o></li>\n<li>SP 800-78: Cryptographic Algorithms and Key Sizes for PIV<o></o></li>\n</ul>\n<p>A supporting PQC Overview accompanies the drafts to present a working gap analysis of the specification changes needed across the PIV algorithm profile, command interface, and data model, and outline the general approach under consideration. This approach centers on a dual-stack model that preserves existing classical PIV keys and data objects; adds new key references, certificate containers, and data objects for PQC credentials; and supports backward compatibility and incremental deployment during the transition.<o></o></p>\n<p>These are preliminary working materials, not formal public drafts. By collaborating with implementers and users to develop these guidelines and specifications, NIST hopes to accelerate the standardization and implementation of PQC in PIV credentials.<o></o></p>\n<p>NIST welcomes feedback throughout the development process. Interested parties can follow the work and participate by:<o></o></p>\n<ul>\n<li><strong>Joining the public mailing list</strong> &mdash; Subscribe at <a href=\"mailto:piv-standards+subscribe@list.nist.gov\">piv-standards+subscribe@list.nist.gov</a>,&nbsp;and take part in discussions at <a href=\"mailto:piv-standards@list.nist.gov\">piv-standards@list.nist.gov</a>&nbsp;(<a href=\"https://groups.google.com/a/list.nist.gov/g/piv-standards\">archive</a>).<o></o></li>\n<li><a href=\"https://github.com/usnistgov/piv-standards\"><strong>Engaging on GitHub</strong></a> &mdash; Review the drafts, file issues, or open pull requests at the project repository.<o></o></li>\n</ul>",
      "published": "2026-06-12T00:00:00",
      "updated": "2026-06-12T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/78/6/iwd",
      "content": "No Due Date: Comment Period Remains Open"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/1353/ipd",
      "title": "SP 1353, NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intelligence (AI) for CSF Analysis and ReportingInitial Public Draft",
      "summary": "<blockquote>\n<p>Per the Sept. 29, 2026, <a href=\"https://www.whitehouse.gov/presidential-actions/2026/09/inaugurating-the-era-of-super-intelligence/\">Executive Order on Inaugurating the Era of Super Intelligence</a>,&nbsp;NIST is working to update its communications to incorporate the term &ldquo;super intelligence&rdquo; as directed.</p>\n</blockquote>\n<p>This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization&rsquo;s progress toward achieving CSF 2.0 outcomes.&nbsp;<o></o></p>\n<p>The document&rsquo;s purpose is to:<o></o></p>\n<ul>\n<li><b>Provide structured AI prompts</b> <b>as tools</b> for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes</li>\n<li><b>Identify current state of practice</b> for AI prompt engineering in CSF implementation and analysis</li>\n</ul>\n<p>While the focus was not to write about AI best practices or to provide cybersecurity guidelines thereof, there are places where specific precautions are denoted with the /!\\ notation.&nbsp; <o></o></p>\n<p>This guide includes three notional use cases, examples of prompts for structuring natural language inputs to produce&nbsp;specified CSF 2.0 outputs from a generative AI model, simulated organizational files for a fictitious company, tips for getting started, and more. <o></o></p>\n<ul>\n<li><b>USE CASE 1</b> illustrates the use of an AI-assisted review to evaluate organization cybersecurity policy, strategy, and <b>risk governance in alignment with the CSF 2.0 outcomes.</b></li>\n<li><b>USE CASE 2&nbsp;</b>illustrates how to <b>produce a draft Organization Current State Profile &ndash;&nbsp;</b>mapping artifacts and personnel interview notes to CSF 2.0 outcomes, documenting any assumptions, and recording observed gaps in the interviews and evidence.</li>\n<li><b>USE CASE 3&nbsp;</b>illustrates how to draw upon internal and industry references to <b>create a draft CSF target state profile </b>describing desired outcomes to meet mission objectives, stakeholder expectations, address the risk landscape, and fulfill requirements.</li>\n</ul>\n<p>Use case examples illustrate a&nbsp;possible approach and are not prescriptive assessment or assurance methodologies.&nbsp;</p>\n<p><o></o><em>Note: The README file in the Supplemental Materials List contains the ZIP file checksums.&nbsp;</em></p>\n<p><b>Submit Your Comments: <o></o></b></p>\n<p>The comment period is open through October 15, 2026, at 11:59 PM. Email comments to: <a href=\"mailto:csf@nist.gov\">csf@nist.gov</a>.&nbsp;<o></o></p>\n<p>Note: NIST is only seeking comments on the quick-start guide and supplied AI prompts. NIST is not seeking comment on the fictional organizational documents. Those are for illustrative purposes only. <o></o></p>\n<p>This publication is the most recent within a portfolio of CSF 2.0&nbsp;quick-start&nbsp;guides released by the CSF 2.0 project team since February 26, 2024. These resources&nbsp;offer tailored pathways for different audiences to engage with the CSF 2.0, making the Framework easier to implement. View all&nbsp;<a href=\"https://www.nist.gov/cyberframework/navigating-nists-csf-20-quick-start-guides\">CSF 2.0 quick-start guides</a>.<b></b></p>\n<p><o>&nbsp;</o></p>",
      "published": "2026-08-19T00:00:00",
      "updated": "2026-08-19T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/1353/ipd",
      "content": "Comments Due 10/15/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/213/a/r1/iprd",
      "title": "SP 800-213A Rev. 1, PRE-DRAFT Call for Comments: IoT Device Cybersecurity Requirement CatalogInitial Preliminary Draft",
      "summary": "<p>Following the publication of draft revision&nbsp;<i>IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, </i>NIST <a data-csrc-link=\"true\" data-node-guid=\"4931def3-45b2-4e86-a17f-6945ba0662fb\" href=\"/pubs/sp/800/213/r1/ipd\">SP 800-213 Rev. 1</a>, NIST has initiated the process of revising the companion document <strong><i>IoT Device Cybersecurity Guidance for the Federal Government: IoT Device Cybersecurity Requirement Catalog</i>, &nbsp;NIST <a data-csrc-link=\"true\" data-node-guid=\"3cb0c4fe-7843-4d69-985a-d9beca88d5ea\" href=\"/pubs/sp/800/213/a/final\">SP 800-213A</a></strong>, to incorporate lessons learned, align with relevant NIST guidance (e.g., <a data-csrc-link=\"true\" data-node-guid=\"99708dc3-cd81-4c6e-962f-5f3319de95bd\" href=\"/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final\">Cybersecurity Framework (CSF) 2.0</a>, <a href=\"https://csrc.nist.gov/projects/cprt/catalog#/cprt/framework/version/SP_800_53_5_2_0/home\">NIST SP 800-53 Rev. 5.2.0</a>)&mdash;as well as IoT cybersecurity standards and practices, and address changes in the IoT threat landscape.<o></o></p>\n<p>We welcome any valuable perspectives on potential revisions to the current SP 800-213A to maximize the document&rsquo;s effectiveness, relevance, and usability in helping the community understand and manage cybersecurity risk. To help guide this input, NIST has included specific questions below, though reviewers are encouraged to address any, all, or additional topics in their comments.</p>\n<p>The public comment period is open through October 15, 2026. Submit comments via email to <a href=\"mailto:iotsecurity@nist.gov\">iotsecurity@nist.gov</a> with the subject line &ldquo;Comments on SP 800-213A.&rdquo;<o></o></p>\n<p>Specifically, NIST asks for input on the following questions to help us plan and produce an initial revision of NIST SP 800-213A:<o></o></p>\n<ol>\n<li><b>Addressing IoT Products</b>. Given that draft NIST SP 800-213 Rev. 1 discusses IoT products while NIST SP 800-213A was written for IoT devices, how should we align NIST SP 800-213A with NIST SP 800-213 Rev. 1 in relation to IoT products? For example, the scope of SP 800-213A could be expanded to IoT products, or the scope of SP 800-213A could remain IoT devices with additional guidelines used for IoT product components other than the IoT device (e.g., mobile applications, backends). We welcome suggestions of other paths forward as well.<o></o></li>\n<li><b>Novel and Unique IoT Adoption and Use Cases</b>. How is your organization using IoT and are there novel IoT use cases we should consider in the update?<o></o></li>\n<li><b>Addressing Unique and Tailored IoT Deployments.</b> How can the NIST SP 800-213A guidelines appropriately handle situations in which an organization combines multiple off-the-shelf components (e.g., Raspberry Pi, sensors) to create an IoT sub-system akin to an IoT product? <o></o></li>\n<li><b>Foundational Guidelines to Base our Work Upon</b>. The content in NIST SP 800-213A was sourced primarily from NIST SP 800-53 Rev. 5, as well as the NIST Cybersecurity Framework (CSF). What other sources should we look to?<o></o></li>\n<li><b>Document Usability</b>. How can descriptions and discussions for each capability in NIST SP 800-213A best help practitioners identify appropriate IoT product cybersecurity capabilities in different operational environments?</li>\n</ol>\n<p>Submitted comments, including attachments and other supporting materials, will become part of the public record and are subject to public disclosure. Personally identifiable information and confidential business information should not be included (e.g., account numbers, Social Security numbers, names of other individuals). Comments that contain profanity, vulgarity, threats, or other inappropriate language will not be posted or considered.</p>\n<p></p>\n<p></p>",
      "published": "2026-08-31T00:00:00",
      "updated": "2026-08-31T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/213/a/r1/iprd",
      "content": "Comments Due 10/15/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/38/e/r1/ipd",
      "title": "SP 800-38E Rev. 1, Recommendation for Block Cipher Modes of Operation: XTS-AES Mode for Confidentiality on Storage DevicesInitial Public Draft",
      "summary": "<p>Revision 1 updates the referenced specification to <b>IEEE Std. 1619-2025</b> and clarifies NIST&rsquo;s requirements for the approved use of XTS-AES, including its scope of use, data-unit and key-scope limits, key requirements, and the ordering convention for ciphertext stealing.<o></o></p>\n<p>Rather than reproducing the XTS-AES specification, this recommendation incorporates&nbsp;<b>IEEE Std. 1619-2025</b> by reference. To facilitate review of the draft SP, <a href=\"https://app.box.com/s/l7v69bw75kit5exqr13vgzhlwf0hg0kh\">IEEE Std. 1619-2025 is publicly available</a> during the public comment period.<o></o></p>\n<p>The public comment period is open through <b>October 16, 2026</b>.<i><o>&nbsp;</o></i></p>\n<p><span style=\"font-size: 10pt;\"><i>NOTE: A call for patent claims is included in this draft. For additional information, see the </i><a href=\"https://www.nist.gov/itl/publications-0/itl-patent-policy-inclusion-patents-itl-publications\">Information Technology Laboratory (ITL)&nbsp;Patent Policy <i>&ndash;</i> Inclusion of Patents in ITL Publications</a><i>.</i></span><span style=\"font-size: 10pt;\"><i></i></span><span style=\"font-size: 10pt;\"><i></i></span><span style=\"font-size: 10pt;\"><i></i></span></p>\n<p></p>",
      "published": "2026-09-03T00:00:00",
      "updated": "2026-09-03T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/38/e/r1/ipd",
      "content": "Comments Due 10/16/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/cswp/36/g/false-base-station-applying-5g-cybersecurity-and-p/ipd",
      "title": "CSWP 36G, False Base Station: Applying 5G Cybersecurity and Privacy CapabilitiesInitial Public Draft",
      "summary": "<p>This initial public draft details how the availability of inexpensive, off-the-shelf hardware and software tools allows attackers to mimic legitimate carrier equipment to intercept and disrupt cellular communications. The paper evaluates how 5G devices respond to six simulated false base station scenarios and examines protections available to mitigate risks.<o></o></p>\n<h4><b>Background<o></o></b></h4>\n<p>This white paper is part of the NCCoE&rsquo;s work to accelerate the adoption of 5G security features by demonstrating their implementation on NCCoE&rsquo;s operational 5G security testbed and providing actionable implementation guidelines to help network operators and other stakeholders enhance the cybersecurity and privacy of 5G systems and supporting infrastructures.<o></o></p>\n<p>A false (aka Rogue or Fake) Base Station (FBS) impersonates a real carrier radio access network. It transmits and receives radio signals that mimic a legitimate 5G cell and tricks unsuspecting User Equipment (UE) to connect to it. This can result in cybersecurity risks, including service degradation, privacy breaches, and location tracking for the user.&nbsp; Although 5G standards include greater security features than previous generations to protect subscribers, they are still susceptible to Denial-of-Service (DoS) attacks.<o></o></p>\n<h4><b>About the White Paper<o></o></b></h4>\n<p>This white paper evaluates six FBS scenarios (simulated in the NCCoE&rsquo;s 5G Security lab) to assess how the tested 5G devices respond to FBS attacks and identify areas for improvement in standards and available device-configurable protections.<o></o></p>\n<p>By demonstrating security features on our operational 5G Testbed, we aim to deliver real-world implementation insights to advance 5G security and inform the next generation of wireless security technologies and standards.<o></o><o>&nbsp;</o></p>\n<p>NIST is particularly interested in your feedback on the following questions:<o></o></p>\n<ol>\n<li>How do you envision using this paper? What changes would you like to see to improve that use?</li>\n<li>What additional information would you like this paper to provide?</li>\n<li>What other 5G cybersecurity and privacy capabilities are you most interested in learning more about?</li>\n</ol>\n<ul></ul>\n<h4><b>Submit Your Feedback!<o></o></b></h4>\n<p>This white paper is available for public comment through&nbsp;<b>October 30, 2026</b>. Visit the <a href=\"https://www.nccoe.nist.gov/5g-cybersecurity#project-promo\">NCCoE project page</a> to learn more and download the white paper today!<o></o></p>",
      "published": "2026-09-30T00:00:00",
      "updated": "2026-09-30T00:00:00",
      "link": "https://csrc.nist.gov/pubs/cswp/36/g/false-base-station-applying-5g-cybersecurity-and-p/ipd",
      "content": "Comments Due 10/30/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/ir/8623/ipd",
      "title": "IR 8623, Cybersecurity Framework 2.0 Community Profile for Federal Agency Open Radio Access Network (O-RAN) DeploymentInitial Public Draft",
      "summary": "<p>Federal agencies that deploy an Open Radio Access Network (O-RAN) as part of their infrastructure must include that deployment in their risk management programs. This draft Cybersecurity Framework (CSF) 2.0 profile describes how components that conform to the security specifications produced by the O-RAN ALLIANCE support various CSF 2.0 outcomes. It also includes references to O-RAN ALLIANCE-produced documents and other relevant guidelines that may help federal agency cybersecurity managers. <o></o></p>",
      "published": "2026-09-17T00:00:00",
      "updated": "2026-09-17T00:00:00",
      "link": "https://csrc.nist.gov/pubs/ir/8623/ipd",
      "content": "Comments Due 11/02/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/82/r4/ipd",
      "title": "SP 800-82 Rev. 4, Guide to Operational Technology (OT) SecurityInitial Public Draft",
      "summary": "<p>This report provides guidelines for improving the security of Operational Technology (OT) systems while addressing their unique performance, reliability, and safety requirements.&nbsp;<o></o></p>\n<p>OT encompasses a broad range of programmable systems or devices that interact with the physical environment (or manage devices that interact with the physical environment). These systems/devices detect or cause a direct change through the monitoring and/or control of devices, processes, and events. Examples include industrial control systems (ICS), building automation systems, transportation systems, physical access control systems, physical environment monitoring systems, and physical environment measurement systems. <o></o></p>\n<p>This fourth revision of SP 800-82 provides an overview of OT and typical system topologies, identifies common threats to organizational mission and business functions supported by OT, describes typical vulnerabilities in OT, and provides recommended security safeguards and countermeasures to manage the associated risks.&nbsp; <o></o></p>\n<p>Updates in this revision include:<o></o></p>\n<ul>\n<li>Expanded introduction to operational technology (OT) sectors to include Building Automation and Control Systems (BACS), Water and Wastewater Systems (WWS), food and agriculture, freight rail, maritime vessels, and Industrial Internet of Things (IIoT) and cloud convergence<o></o></li>\n<li>Restructured around the NIST Cybersecurity Framework (CSF) 2.0, including a reorganization of the previous risk management section to focus on the CSF Govern Function<o></o></li>\n<li>Expanded discussion of how OT risk management aligns with broader enterprise risk management, as described in NIST IR 8286r1<o></o></li>\n<li>Discussion of the adoption of the NIST Risk Management Framework (RMF) in Appendix F<o></o></li>\n<li>Expanded guidelines for implementing OT security controls, including asset management and network monitoring and detection<o></o></li>\n<li>Security architecture guidelines focused on protecting system management functions and applying zero trust principles<o></o></li>\n</ul>\n<p><b>The comment period on this initial public draft is open through November 30, 2026. </b>We encourage you to use this <a href=\"/files/pubs/sp/800/82/r4/ipd/docs/sp800-82r4-ipd-comment-template.xlsx\">comment template</a> when preparing your comments.&nbsp;<o></o></p>\n<p><span style=\"font-size: 10pt;\"><i>NOTE: A call for patent claims is included in this draft. For additional information, see the </i><a href=\"https://www.nist.gov/itl/publications-0/itl-patent-policy-inclusion-patents-itl-publications\">Information Technology Laboratory (ITL)&nbsp;Patent Policy <i>&ndash;</i> Inclusion of Patents in ITL Publications</a></span><i><span style=\"font-size: 10pt;\">.</span> <o></o></i></p>",
      "published": "2026-09-21T00:00:00",
      "updated": "2026-09-21T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/82/r4/ipd",
      "content": "Comments Due 11/30/2026"
    },
    {
      "id": "https://csrc.nist.gov/pubs/sp/800/185/r1/ipd",
      "title": "SP 800-185 Rev. 1, SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash, and ParallelHashInitial Public Draft",
      "summary": "<p>Revision 1 introduces streaming interfaces for extendable-output function (XOF) computations, which allow applications to process input and request output incrementally without knowing the total input or output length in advance.<o></o></p>\n<p>From the Note to Reviewers (p. v):</p>\n<ol>\n<li>The Keccak-derived functions in this recommendation have been updated to describe a<br>streaming mode of access that provides full XOF functionality. This involves calls to three<br>functions: INIT, ABSORB, and SQUEEZE.</li>\n<li>Illustrative pseudocode is provided for the streaming interface, but the correct behavior of<br>all streaming modes is defined in terms of the corresponding single-call interface to the<br>functions.</li>\n<li>The single-call interfaces for these functions are equivalent to the functions defined in the<br>previous version of this document.</li>\n<li>cSHAKE, KMAC, and ParallelHash use the ABSORB function to incrementally input<br>data into the function so that ABSORB(𝑋1) followed by ABSORB(𝑋2) has the same effect<br>as ABSORB(𝑋1 ∥ 𝑋2).</li>\n<li>TupleHash uses the absorb function somewhat differently in that each ABSORB call<br>processes one complete tuple element. NIST invites comment on whether this different use<br>of ABSORB might be confusing.</li>\n</ol>\n<p>The public comment period is open through <strong>December 7, 2026</strong>.</p>\n<p><span style=\"font-size: 10pt;\"><i>NOTE: A call for patent claims is included in this draft. For additional information, see the </i><a href=\"https://www.nist.gov/itl/publications-0/itl-patent-policy-inclusion-patents-itl-publications\"><i>Information Technology Laboratory (ITL)&nbsp;Patent Policy &ndash; Inclusion of Patents in ITL Publications</i></a><i>.</i></span></p>",
      "published": "2026-10-08T00:00:00",
      "updated": "2026-10-08T00:00:00",
      "link": "https://csrc.nist.gov/pubs/sp/800/185/r1/ipd",
      "content": "Comments Due 12/07/2026"
    }
  ]
}