Capability 1
IoT device security
NIST IR 8259A — IoT Device Cybersecurity
IoT Device Cybersecurity Capability Core Baseline
Evaluate whether an IoT or connected cyber-physical device provides the foundational technical cybersecurity capabilities identified by NIST IR 8259A. The assessment addresses device identification, configuration, data protection, interface access, software updates, and cybersecurity state awareness.
This assessment is a cybersecurity readiness and decision-support tool. NIST IR 8259A provides a baseline of generally applicable IoT device cybersecurity capabilities and does not mandate implementation of every capability for every device or environment. Applicability and implementation should be evaluated based on the device, deployment architecture, operating environment, threat model, organizational risk, and applicable regulatory or contractual requirements. VoltVerify does not provide certification or guarantee compliance with NIST guidance.
Capability 2
Device Configuration
Capability 3
Data Protection
Capability 4
Logical Access to Interfaces
Capability 5
Software Update
Capability 6
Cybersecurity State Awareness
39 original readiness questions across six baseline capabilities. Scope any connected device, including EVSE, inverters, storage systems, gateways, meters, sensors, and controllers. No supplemental catalog capability is included in the initial score.
Device capabilities → manufacturer activities → supporting capabilities
Assess each perspective independently for the same product boundary. Evidence may be reused through the governed repository; answers and scores are never transferred automatically.
IoT Device Cybersecurity Capability Core Baseline
39 questions · 6 areas
NIST IR 8259 Rev. 1Foundational Cybersecurity Activities for IoT Product Manufacturers
27 questions · 9 areas
NIST IR 8259BIoT Non-Technical Supporting Capability Core Baseline
24 questions · 4 areas
Industrial/OT products → IEC 62443 review
Informational / requires qualified validation. Proposed topic comparisons to IEC 62443-4-1:2018 do not establish clause coverage, equivalence, a security level, or certification. IEC 62443-4-2 concerns technical component requirements and needs separate evaluation. IEC 62443-2-4 applies to service providers when that role is in scope. Validate the applicable edition, licensed requirements, product boundary, and organizational role with qualified industrial/OT specialists. Crosswalks never change assessment answers or scores.
Review proposed crosswalks