Security and privacy

NIST IR 8259 IoT cybersecurity baseline

A voluntary baseline of six foundational cybersecurity activities for connected devices, used widely in procurement and product planning.

CodeNIST 8259
RegionUnited States framework
TypeVoluntary framework
Issued byNational Institute of Standards and Technology
Last verified2026-10-10
Quick answerCertification · last verified 2026-10-10

A voluntary baseline of six foundational cybersecurity activities for connected devices, used widely in procurement and product planning. Status: Voluntary framework. Issued or recognised by National Institute of Standards and Technology.

CodeNIST 8259
RegionUnited States framework
TypeVoluntary framework
Issued byNational Institute of Standards and Technology
GroupSecurity and privacy
Last verified2026-10-10
How to cite this pageIoT Atlas. "NIST IR 8259 IoT cybersecurity baseline". https://hi-spark.net/certification/nist-8259.html Last verified 2026-10-10.

What it means

NIST IR 8259 describes what a manufacturer should do before a device reaches the market, and 8259A lists the corresponding device capabilities. It is often used together with the IoT device cybersecurity guidance for federal acquisition.

Applies to

  • Manufacturers planning device security features
  • Procurement requirements that reference NIST guidance
  • Products seeking a documented baseline for enterprise buyers

What it does not cover

  • A certification or a mark
  • Privacy law compliance
  • Sector-specific regulation such as medical devices

Verification checklist

  • Identify the device and its security assumptions
  • Define the customer-facing security capabilities
  • Document the update and vulnerability handling model
  • Map the device against the six activities and 8259A capabilities