# CISA and NIST Issue Cloud Identity Token Guidance

CISA and NIST have released final voluntary guidance aimed at federal agencies and cloud service providers to strengthen protections against cloud identity token theft and misuse. This guidance focuses on implementing token expiration limits, key rotation, and secure key storage practices, and extends to emerging AI agent use cases. These measures address vulnerabilities revealed by recent token compromise incidents and seek to enhance overall cloud security posture.

- Federal agencies and contractors should evaluate their cloud identity management practices against the new guidance to reduce risks of token theft.
- Cloud service providers can leverage this guidance to improve security offerings and demonstrate compliance with federal best practices.
- Procurement professionals should consider incorporating these voluntary security recommendations into contract requirements and vendor evaluations.
- Organizations involved in AI deployments should pay particular attention to token security controls as outlined in the guidance to mitigate emerging threats.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity
**Published:** September 17, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)
- National Institute of Standards and Technology (NIST)

### Sources
- [CISA, NIST issue new guidance to stop cloud identity token theft | news | MSSP Alert](https://www.msspalert.com/news/cisa-and-nist-issue-guidance-on-protecting-cloud-identity-tokens) - MSSP Alert