Skip to main content

3 posts tagged with "US"

Focus on United States regulations and standards.

View All Tags

NIST Updates IoT Product Guidance

· 4 min read
SBD Community
Maintainer

On 24 June 2026, NIST released the initial public draft of SP 800-213 Revision 1, IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements (NIST announcement, draft PDF). For connected device makers, the draft is useful because it treats IoT as a product and deployment-risk problem, not just a device-feature checklist.

CISA Updates Secure-by-Design Guidance

· 3 min read
SBD Community
Maintainer

On 12 May 2026, CISA highlighted an updated version of the joint Secure-by-Design guidance, co-sealed by additional international cybersecurity agencies. The update reinforces the core message behind the movement: technology providers should take ownership of customer security outcomes, be transparent about their security posture, and treat security as an executive-level product responsibility (CISA Secure-by-Design resource).

FDA Overhauls Medical Device Cybersecurity Guidance, Unifying Rules for 'Cyber Devices'

· 3 min read
SBD Community
Maintainer

On June 27, 2025, the US Food and Drug Administration (FDA) published a landmark update to its premarket cybersecurity guidance, superseding the version from September 2023. This new document provides critical clarity for medical device manufacturers by consolidating previous guidances and formally defining the legal obligations for "cyber devices" under Section 524B of the FD&C Act.