Title 15 › Chapter 7— NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY › § 278g–3b
The Director of the Institute must write and publish rules within 90 days after December 4, 2020, on how federal agencies should use and manage Internet of Things (IoT) devices that the agency owns or controls and that connect to agency information systems. The rules must include basic cybersecurity requirements and match NIST work in effect on December 4, 2020 about IoT vulnerabilities and how to handle them. They must cover things like secure development, identity management, patching, and configuration management, and should take into account private‑sector and agency best practices. Within 180 days after those rules are published, the OMB Director must review and update agency information security policies (not including national security systems) so they follow the new IoT rules. OMB must consult CISA and align with other federal information security law (44 U.S.C. chapter 35, subchapter II). The Institute must recheck and update the rules at least every 5 years, and OMB must revise its policies within 180 days after any Institute changes. The Federal Acquisition Regulation must be updated as needed to apply the rules.
Full Legal Text
Commerce and Trade, Source: USLM XML via OLRC
Legislative History
Reference
Citation
15 U.S.C. § 278g–3b
Title 15, Commerce and Trade
Last Updated
Apr 3, 2026
Release point: 119-73not60