Skip to main content
USTelecom — The Broadband Association
Sample profile — content is illustrative. Verify every name, date, and status against official sources before use.
Back to Agency Atlas
NISTModerate activityReview recommended · 2026-07-10

National Institute of Standards and Technology

Non-regulatory standards anchor: C-SCRM practices (SP 800-161r1), the SSDF attestation baseline (SP 800-218), post-quantum cryptography standards and transition timeline, and CSF 2.0. The full NIST inventory and gap list lives in the companion NIST Tracking Report (July 10, 2026); this entry links to it rather than duplicating it.

One-minute briefing

Agency snapshot

NIST is the non-regulatory standards anchor whose outputs flow into CMMC, FAR, and agency requirements. Current headline items: SP 800-218r1 (SSDF v1.2) is in draft under EO 14306; IR 8547 sets the post-quantum transition timeline and is on a finalization watch; FIPS 140-2 validations sunset September 21, 2026; Section 5949-adjacent provenance expectations are emerging; and COSAiS plus the Cyber AI Profile form the AI-security standards track. The full inventory and gap list is in the companion NIST Tracking Report (July 10, 2026). Confirm publication status at csrc.nist.gov.

6
Active initiatives
2
Upcoming deadlines
3
Priority topics
Most important thing right now

Plan for the September 21, 2026 FIPS 140-2 sunset, track SP 800-218r1 (SSDF v1.2) for attestation changes, and continue post-quantum inventory against the IR 8547 timeline.

Mandate & jurisdiction

What this agency does

NIST standards are the technical baseline that federal contract and program requirements point to — changes here propagate into member obligations.

C-SCRM guidance

SP 800-161r1 shapes supply-chain risk-management expectations referenced by agencies.

SSDF attestation baseline

SP 800-218 (SSDF) underpins the federal secure-software attestation regime.

Cryptographic standards

Publishes PQC standards and the IR 8547 transition timeline; runs the module validation program (FIPS 140-2 sunset).

AI security

COSAiS and the Cyber AI Profile form the emerging AI-security standards track.

Jurisdiction

  • Cybersecurity and C-SCRM standards development
  • Secure software development framework (SSDF)
  • Cryptographic standards (FIPS) and PQC transition
  • AI-security standards (COSAiS / Cyber AI Profile)
Who should care

Security architecture, compliance, and product teams.

Operational

Crypto migration, module re-validation (FIPS 140-3), and SSDF tooling.

Compliance

Alignment to 800-161r1 / 800-218 referenced in contracts and attestations.

Procurement

Vendor security requirements tied to NIST frameworks and provenance expectations.

Initiatives & deadlines

What they are working on now

UpcomingProposedC-SCRM & SSDF

SP 800-218r1 — SSDF v1.2 draft (EO 14306)

NIST has a draft of SP 800-218r1 (Secure Software Development Framework v1.2) under Executive Order 14306. It refreshes the SSDF that underpins the federal secure-software attestation baseline.

UpcomingPendingPost-quantum cryptography 2024-08-13

IR 8547 — post-quantum cryptography transition

IR 8547 lays out the transition to post-quantum cryptography standards (following the August 2024 release of FIPS 203/204/205). It is on a finalization watch and sets expectations for phasing out quantum-vulnerable algorithms.

UpcomingEffectivePost-quantum cryptography 2026-09-21

FIPS 140-2 validation sunset

FIPS 140-2 cryptographic module validations sunset September 21, 2026; modules move to FIPS 140-3. Products relying on 140-2 validations will need re-validation.

MonitorEffectiveC-SCRM & SSDF 2024-02-26

SP 800-161r1 C-SCRM + Section 5949 provenance expectations

SP 800-161r1 remains the C-SCRM anchor; NIST is developing Section 5949-adjacent provenance expectations (semiconductor origin/traceability) that align with the FAR Council prohibition. CSF 2.0 (2024) added a "Govern" function and supply-chain emphasis.

MonitorProposedAI security

COSAiS & the Cyber AI Profile (AI-security track)

COSAiS and the Cyber AI Profile form NIST’s emerging AI-security standards track, extending cybersecurity practices to AI systems used across critical infrastructure.

Upcoming dates

  • 2026-09-21FIPS 140-2 validation sunset
Key decision-makers

Leadership to know

We focus on the roles whose decisions reach members, and why each one matters — not biographical trivia. Names are intentionally withheld until verified against an official source.

Arvind Raman
Under Secretary of Commerce for Standards and Technology and NIST Director

Why it mattersOversees standards development referenced across federal programs; confirmed May 2026, sworn in June 2026.

Review recommended
Working Group analysis

What we are watching

Confidence: DevelopingActive situation; details are still shifting.

What changed

  • SP 800-218r1 (SSDF v1.2) issued in draft under EO 14306.
  • IR 8547 PQC transition guidance on a finalization watch.
  • FIPS 140-2 sunset set for September 21, 2026.

What we are watching

  • Final SSDF v1.2 attestation changes.
  • Section 5949-adjacent provenance expectations.
  • COSAiS / Cyber AI Profile drafts.

Member exposure

  • Crypto migration and FIPS 140-3 re-validation effort.
  • Secure-software attestation obligations tied to the SSDF.
  • Emerging AI-security and component-provenance expectations.

Recommended preparation

  • Inventory FIPS 140-2 modules and plan 140-3 re-validation before September 21, 2026.
  • Track SP 800-218r1 for attestation impacts.
  • Continue PQC inventory against the IR 8547 timeline.

Open questions

  • How prescriptive will the Cyber AI Profile and Section 5949 provenance expectations become?
Primary references

Sources & verification

Agency-level sources

This profile is a sample interface. Leadership names, dates, regulatory status, and figures must be confirmed against current official sources before any member distribution.