# NIST and CISA Finalize Cloud Token Security Guidelines

NIST and the Cybersecurity and Infrastructure Security Agency (CISA) have finalized and released NIST Interagency Report 8587, providing comprehensive, outcome-based guidelines to protect digital identity and access tokens critical to federal cloud services and online authentication. These guidelines address risks such as token theft and forgery by recommending best practices in token issuance, verification, cryptographic key management, and lifecycle controls. While voluntary, these updated standards are expected to influence federal procurement requirements for cloud service providers and identity management solutions, emphasizing enhanced security measures aligned with zero trust architectures and emerging technologies like AI and post-quantum cryptography.

- Federal agencies and contractors should evaluate their identity and access management solutions against NIST IR 8587 to align with evolving federal cybersecurity expectations.
- Cloud service providers aiming to support federal contracts may need to demonstrate compliance with these guidelines to remain competitive in government procurements.
- Procurement professionals should anticipate increased emphasis on token security features in upcoming solicitations and contract requirements.
- Organizations can leverage these guidelines to strengthen cybersecurity postures and reduce risks associated with token misuse in federal cloud environments.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 15, 2026

### Government Entities
- National Institute of Standards and Technology (NIST)
- Cybersecurity and Infrastructure Security Agency (CISA)
- National Cybersecurity Center of Excellence (NCCoE)

### Key Quotes
> This publication provides implementation considerations for protecting tokens appropriately. Anyone who is using tokens as part of their access management infrastructure can look to this for insights, whether they are in government or commercial industry.
> — Ryan Galluzzo, Digital Identity Program Lead, NIST

> These guidelines give agencies and cloud providers a clear, practical path to harden token issuance, verification, and management so a stolen or forged credential can’t become a foothold across the federal enterprise.
> — Chris Butera, Acting Executive Assistant Director for Cybersecurity, CISA

### Sources
- [NIST and CISA Release Guidelines on Protecting Digital Access Tokens - SSBCrack News](https://news.ssbcrack.com/nist-and-cisa-release-guidelines-on-protecting-digital-access-tokens) - news.ssbcrack.com
- [CISA and NIST Releases Technical Checklist for Safeguarding the Identity Tokens From Theft and Misuse](https://cybersecuritynews.com/cisa-nist-identity-token-security/amp) - CyberSecurityNews
- [CISA, NIST Finalize Cloud Identity Token Security Guidelines – MeriTalk](https://www.meritalk.com/articles/cisa-nist-finalize-cloud-identity-token-security-guidelines) - meritalk.com