Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

      • 5G Cybersecurity
      • Applied Cryptography
      • Artificial Intelligence
      • Cybersecurity for the Space Domain
      • Data Classification
      • Data Security
      • DevSecOps
      • Digital Identities - mDL
      • Genomics Cybersecurity
      • Internet of Things (IoT)
      • Mobile Device Security
      • Supply Chain Assurance
      • Trusted Cloud
      • Zero Trust Architecture
      • Consumer Data Protection
      • Energy
      • Financial Services
      • Healthcare
      • Manufacturing
      • Public Safety/First Responder
      • Transportation
      • Water/Wastewater
      • Privacy
      • Resources for Applying NIST Frameworks
      • Defining Scope
      • Seeking Collaborators
      • Preparing Draft
      • Soliciting Comments
      • Reviewing Comments
      • Finalized
      • Archived
    • Mission & Vision
    • How We Work
    • Our Project Portfolio
    • About the Center
    • News
    • Events
    • Contact Us
    • Visit Us
    • Speakers Corner
    • Subscribe to Updates
    • Join a Community of Interest
    • Technical Contributions
    • Government Organizations
    • Academic Engagement
  • Home
  • All Projects

All Projects

Search or scroll below to browse projects.

  • 5G Cybersecurity

    Demonstrates how operators and users of 5G networks can mitigate 5G cybersecurity risks and meet industry sectors’ compliance requirements
    Preparing Draft
  • A Guide to Creating Community Profiles

    Reviewing Comments
  • Access Rights Management for the Financial Services Sector

    Controlling who can obtain access to information and resources with a cohesive and secure identity and access management system
    Archived
  • Addressing Visibility Challenges with TLS 1.3 within the Enterprise

    Addresses challenges to compliance, operations, and security with modern encrypted protocols, and TLS 1.3 in particular
    Finalized
  • Artificial Intelligence: Adversarial Machine Learning

    Informing future standards and best practices for assessing and managing the security of machine learning components
    Finalized
  • Asset Management for the Energy Sector

    Methods for managing, monitoring, and baselining IT and OT assets to reduce the risk of cybersecurity incidents
    Finalized
  • Automation of the NIST Cryptographic Module Validation Program (CMVP)

    Demonstrates the value and practicality of automation to improve the efficiency and timeliness of Cryptographic Module Validation Program (CMVP) operation and processes
    Reviewing Comments
  • Autonomous Vehicle Vision

    The NCCoE is working on cyber assurance for autonomous vehicles by developing a public dataset and a testbed with difficult-to-handle and adversarial road/traffic conditions with the goal of improving autonomous vehicles and accelerating their safe deploy
    Preparing Draft
  • Critical Cybersecurity Hygiene: Patching the Enterprise

    Examines how commercial and open source tools can be used to aid with the most challenging aspects of patching general IT systems
    Finalized
  • Cyber AI Profile

    Guidance based on the NIST Cybersecurity Framework to address the cybersecurity risks related to AI development and use.
    Reviewing Comments
  • Cybersecurity and Privacy of Genomic Data

    The Cybersecurity and Privacy of Genomic Data project offers guidelines and resources for enabling secure technology adoption.
    Reviewing Comments
  • Cybersecurity for Smart Inverters: Guidelines for Residential and Light Commercial Solar Energy Systems

    Practical cybersecurity guidelines for small-scale solar inverter implementations typically used in homes and small businesses.
    Finalized
  • Cybersecurity Framework Profile for Electric Vehicle Extreme Fast Charging Infrastructure

    Providing users with a national-level risk-based approach for managing cybersecurity activities for EV XFC systems.
    Finalized
  • Cybersecurity Framework Profile for Liquefied Natural Gas

    A unified approach to identify and prioritize opportunities for managing cybersecurity risks in the liquefied natural gas lifecycle.
    Finalized
  • Cybersecurity Framework Profile for PNT

    A risk management approach for assurance and resilience of positioning, navigation, and timing services.
    Soliciting Comments
  • Cybersecurity Framework Profile for Semiconductor Manufacturing

    A unified approach to identify and prioritize opportunities for managing cybersecurity risks in the semiconductor manufacturing industry.
    Reviewing Comments
  • Data Classification

    Defining technology-agnostic recommended practices for defining data classifications and data handling rulesets and communicating them to others
    Reviewing Comments
  • Data Confidentiality: Detect, Respond to, and Recover from Data Breaches

    Identifying methods to efficiently detect, respond, and recover from data confidentiality attacks
    Finalized
  • Data Confidentiality: Identifying and Protecting Assets Against Data Breaches

    Exploring methods to effectively identify and protect assets against data confidentiality attacks
    Finalized
  • Data Integrity: Detecting and Responding to Ransomware and Other Destructive Events

    Detailing methods and potential tool sets that can detect, mitigate, and contain data integrity events
    Finalized
  • Data Integrity: Identifying and Protecting Assets Against Ransomware and Other Destructive Events

    Exploring methods to effectively identify and protect assets against data integrity attacks
    Finalized
  • Data Integrity: Recovering from Ransomware and Other Destructive Events

    Demonstrates how to effectively recover from a data corruption event in various Information Technology (IT) enterprise environments
    Finalized
  • Digital Identities - mDL

    Digital Identity is becoming ubiquitous. To address that, we aim to define and facilitate reference architectures for digital identities that protects privacy, is implemented in a secure way, enables equity, is widely adoptable, and easy to use.
    Reviewing Comments
  • Dioptra

    Dioptra is a software test platform for assessing the trustworthy characteristics of AI models.
    Preparing Draft
  • Electronic Health Records on Mobile Devices

    Illustrates how healthcare providers securely document, maintain, and exchange electronic patient records among mobile devices
    Finalized
  • Hybrid Satellite Networks Cybersecurity

    Hybrid Satellite Networks or HSN provides flexible use of commercial satellites that can host non-commercial payloads.
    Finalized
  • Identity and Access Management (IdAM) for the Energy Sector

    A single, centralized IdAM solution to control and secure access to utility resources, including OT and IT systems, buildings, and equipment
    Finalized
  • Implementing a Zero Trust Architecture

    Demonstrating examples of zero trust architectures designed and deployed according to the concepts and tenets documented in NIST SP 800-207, Zero Trust Architecture
    Finalized
  • IoT Device Characterization

    Demonstrates how to use device characterization techniques to describe the communication requirements of IoT devices
    Finalized
  • IPv6 Transition

    Demonstrates the feasibility of securely migrating common enterprise network environments to IPv6-only deployments.
    Archived
  • IT Asset Management for the Financial Services Sector

    Making software changes and network breaches more easily identifiable
    Finalized
  • Migration to Post-Quantum Cryptography

    Brings awareness to the issues involved in migrating to post-quantum algorithms and develops practices to ease migration from current public-key algorithms to replacement algorithms that are resistant to quantum computer-based attacks
    Reviewing Comments
  • Mitigating Cybersecurity and Privacy Risks in Telehealth Smart Home Integration

    Identifies and mitigates cybersecurity and privacy risks based on patient use of smart home devices interfacing with patient information systems
    Finalized
  • Mobile Application Single Sign-On

    NIST SP 1800-13 describes how public safety organizations can implement single sign-on functions for public safety personnel, use identity federation to authenticate personnel across organization boundaries, and enable MFA with a high level of assurance.
    Finalized
  • Mobile Device Security: Bring Your Own Device

    Provides a clear and repeatable security and privacy-enhanced reference example solution architecture for organizations that allow personally owned mobile devices to access their organizational data
    Finalized
  • Mobile Device Security: Cloud and Hybrid Builds

    Provides clear and repeatable security and privacy-enhanced reference example solution architectures for organizations using either cloud or a hybrid combination of both enterprise and cloud based services for their mobile device deployment architectures
    Finalized
  • Mobile Device Security: Corporate-Owned Personally-Enabled

    Clear and repeatable reference mobile architecture in which strong data confidentiality is implemented using certified technologies.
    Finalized
  • Multifactor Authentication for E-Commerce

    Reducing the risk of false online identification and authentication fraud for e-commerce transactions using multifactor authentication tied to web analytics and contextual risk calculation
    Finalized
  • NCCoE Chatbot

    The NCCoE seeks to understand the benefits and vulnerabilities of generative AI systems and opportunities to implement technologies to mitigate these vulnerabilities. The project is beginning to leverage generative AI to support the work of the NCCoE.
    Reviewing Comments
  • Privacy-Enhancing Technologies (PETs) Testbed

    NIST’s Privacy-Enhancing Technologies Testbed is a resource for evaluating these capabilities, featuring real-world use cases, model solutions, and rigorous metrics for utility and privacy.
    Preparing Draft
  • Privileged Account Management for the Financial Services Sector

    Implementing stronger controls for privileged account security to enable organizations to enforce access policies
    Archived
  • Protecting Information and System Integrity in Industrial Control System Environments

    Demonstrated practice example solutions that manufacturers can use to protect their ICS from data integrity attacks and documented in NIST SP 1800-10, Protecting Information and System Integrity in Industrial Control System Environments
    Finalized
  • Ransomware CSF Community Profile

    Use this CSF 2.0 Community Profile to focus cybersecurity efforts on the outcomes that strengthen ransomware prevention, response, recovery, and resilience.
    Finalized
  • Responding to and Recovering from a Cyber Attack: Cybersecurity for the Manufacturing Sector

    An approach for cybersecurity incident response and recovery in a manufacturing environment
    Soliciting Comments
  • Secure Software Development, Security, and Operations (DevSecOps) Practices

    Demonstrating an applied risk-based approach and recommendations for secure DevOps and software supply chain practices
    Reviewing Comments
  • Securing Distributed Energy Resources

    An approach for securing data exchanges between and among distributed energy resource systems and electric power distribution facilities
    Finalized
  • Securing Home IoT Devices Using MUD

    Demonstrates using the Manufacturer Usage Description (MUD) standard to improve the security of home IoT devices
    Finalized
  • Securing Manufacturing Industrial Control Systems: Behavioral Anomaly Detection

    Demonstrated examples of behavioral anomaly detection and prevention mechanisms according to the concepts and tenets documented in NISTIR 8219 Securing Manufacturing Industrial Control Systems: Behavioral Anomaly Detection
    Finalized
  • Securing Picture Archiving and Communication System

    Finalized
  • Securing Property Management Systems

    Demonstrates how hospitality organizations can use a standards-based approach with commercially available technologies to meet their security needs for protecting property management systems
    Finalized
  • Securing Telehealth Remote Patient Monitoring Ecosystem

    Ensuring that the infrastructure supporting remote patient monitoring capabilities can maintain the confidentiality of patient data
    Finalized
  • Securing Water and Wastewater Utilities

    Presenting a traditional on-premises remote access reference architecture and two example solutions.
    Reviewing Comments
  • Securing Wireless Infusion Pumps

    Helping healthcare delivery organizations secure wireless infusion pumps (WIP) on an enterprise network
    Finalized
  • Security Segmentation in a Small Manufacturing Environment

    An approach that manufacturers can follow to implement security segmentation and mitigate cyber vulnerabilities in their manufacturing environments.
    Finalized
  • Situational Awareness for the Energy Sector

    Mechanisms to capture, transmit, analyze, and store real-time and near-real-time data from both IT and OT networks and systems
    Finalized
  • Software and AI Agent Identity and Authorization

    With the advancement of AI and software agents, systems have the capability for autonomous decision-making with limited human supervision to achieve complex goals. This increased scale and autonomy brings new opportunities as well as new risks.
    Reviewing Comments
  • Supply Chain Assurance

    Demonstrates how organizations can verify that the internal components of their purchased computing devices are genuine and have not been altered during the manufacturing and distribution processes
    Finalized
  • Supply Chain Traceability Principles: A Manufacturing Meta-Framework

    This project is implementing supply chain component traceability across industry blockchain enabled ecosystems of manufacturers and will inform supply chain visibility for critical infrastructures.
    Reviewing Comments
  • TLS Server Certificate Management

    Proposes a solution that efficiently and effectively provisions and manages TLS server certificates during normal operations and disaster recovery in a typical enterprise environment
    Finalized
  • Transit Cybersecurity Framework (CSF) Community Profile

    Creating a Community Profile involves understanding priorities and risks, making collaboration an important part of the process. To ensure its success, it's crucial to involve stakeholders in developing this Profile. We welcome...
    Reviewing Comments
  • Trusted Cloud: VMware Hybrid Cloud IaaS Environments

    An approach to determine the physical location of cloud computing servers to monitor and control workloads, anticipate and mitigate risks, and reduce the likelihood that unauthorized parties will obtain data
    Finalized
  • Trusted IoT Device Network-Layer Onboarding and Lifecycle Management

    Demonstrates approaches for securely onboarding IoT devices with network credentials
    Finalized

NCCoE
9700 Great Seneca Highway, Rockville, MD 20850

NIST is an agency of the U.S. Department of Commerce.

  • Facebook
  • X
  • LinkedIn
  • YouTube
  • Site Privacy
  • Accessibility
  • Privacy Program
  • Copyrights
  • Vulnerability Disclosure
  • No Fear Act Policy
  • FOIA
  • Environmental Policy
  • Scientific Integrity
  • Information Quality Standards
  • Commerce.gov
  • Science.gov
  • USA.gov
  • Vote.gov