IoT device security

NIST IR 8259A — IoT Device Cybersecurity

IoT Device Cybersecurity Capability Core Baseline

Evaluate whether an IoT or connected cyber-physical device provides the foundational technical cybersecurity capabilities identified by NIST IR 8259A. The assessment addresses device identification, configuration, data protection, interface access, software updates, and cybersecurity state awareness.

This assessment is a cybersecurity readiness and decision-support tool. NIST IR 8259A provides a baseline of generally applicable IoT device cybersecurity capabilities and does not mandate implementation of every capability for every device or environment. Applicability and implementation should be evaluated based on the device, deployment architecture, operating environment, threat model, organizational risk, and applicable regulatory or contractual requirements. VoltVerify does not provide certification or guarantee compliance with NIST guidance.

Capability 1

Device Identification

Capability 2

Device Configuration

Capability 3

Data Protection

Capability 4

Logical Access to Interfaces

Capability 5

Software Update

Capability 6

Cybersecurity State Awareness

39 original readiness questions across six baseline capabilities. Scope any connected device, including EVSE, inverters, storage systems, gateways, meters, sensors, and controllers. No supplemental catalog capability is included in the initial score.

Device capabilities → manufacturer activities → supporting capabilities

Assess each perspective independently for the same product boundary. Evidence may be reused through the governed repository; answers and scores are never transferred automatically.

Industrial/OT products → IEC 62443 review

Informational / requires qualified validation. Proposed topic comparisons to IEC 62443-4-1:2018 do not establish clause coverage, equivalence, a security level, or certification. IEC 62443-4-2 concerns technical component requirements and needs separate evaluation. IEC 62443-2-4 applies to service providers when that role is in scope. Validate the applicable edition, licensed requirements, product boundary, and organizational role with qualified industrial/OT specialists. Crosswalks never change assessment answers or scores.

Review proposed crosswalks