# NIST and CISA Finalize Cloud Token Guidance

NIST and CISA finalized NIST Interagency Report 8587 with technical recommendations for protecting identity tokens used in cloud sign-ins, APIs, and service-to-service access. The report is guidance, not a universal legal mandate. Federal agencies and cloud customers can use it to assess provider controls and clarify shared security responsibilities in cloud procurements.

- Procurement teams can use the report’s focus areas—token lifecycle, key management, monitoring, and revocation—to inform provider assessments and discussions of cloud security responsibilities.
- Cloud providers and contractors may find it useful to review how their services address these token protections and explain relevant controls to government customers.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Cloud Services
**Published:** September 30, 2026

### Government Entities
- National Institute of Standards and Technology (NIST)
- Cybersecurity and Infrastructure Security Agency (CISA)

### Sources
- [NIST Finalises Guidance to Protect Cloud Identity Tokens](https://streamlinefeed.co.ke/news/nist-finalises-guidance-protect-cloud-identity-tokens) - streamlinefeed.co.ke