Author(s)
Patrick O'Reilly, Kristina Rigopoulos
Abstract
Throughout Fiscal Year 2025 (FY 2025) - from October 1, 2024, through September 30, 2025 - the NIST Information Technology Laboratory (ITL) Cybersecurity and Privacy Program successfully responded to numerous challenges and opportunities in security and privacy. This Annual Report highlights the ITL Cybersecurity and Privacy Program's FY 2025 research activities, including the ongoing participation and development of international standards, research, and practical applications in several key priority, including improved software and supply chain cybersecurity, work on IoT cybersecurity guidelines, National Cybersecurity Center of Excellence (NCCoE) projects, a new comment site for NIST's Risk Management Framework, the release of a Phish scale, and progress in the Identity and Access Management program.
Citation
Special Publication (NIST SP) - 800-238
Keywords
annual report, 2025 annual report, cybersecurity, cybersecurity program, cybersecurity and privacy program, Federal Information Security Modernization Act, FISMA, information security, Information Technology Laboratory, ITL, privacy, program accomplishments, program highlights, project accomplishments, project highlights.
Citation
O'Reilly, P. and Rigopoulos, K. (2026), Fiscal Year 2025 Annual Report for NIST Cybersecurity and Privacy Program, Special Publication (NIST SP), National Institute of Standards and Technology, Gaithersburg, MD, [online], https://doi.org/10.6028/NIST.SP.800-238, https://tsapps.nist.gov/publication/get_pdf.cfm?pub_id=961901 (Accessed May 22, 2026)
Additional citation formats
Issues
If you have any questions about this publication or are having problems accessing it, please contact [email protected].