What you need to know
Procurement should evaluate how a connected product will be configured, updated, supported, monitored, reset, and retired—not only whether it performs its primary function.
Potentially affected
Organizations selecting cameras, controllers, readers, intercoms, gateways, sensors, appliances, management cards, or other connected physical-security products.
DSE recommendation
Add cybersecurity and lifecycle questions to requirements, require evidence for vendor answers, and evaluate deployment and exit costs before approval.
Procurement creates a long-lived security dependency
NIST IR 8259 Rev. 1 describes foundational cybersecurity activities that IoT product manufacturers should consider before products are sold. It focuses on making products more securable and giving customers cybersecurity information they need. Buyers can use that perspective to ask whether a network-connected security product can be governed throughout its useful life.
NIST does not certify products through this publication, and this checklist does not establish that any device is secure, compatible, or suitable for a particular facility. It is a structured way to collect evidence before a purchase creates an operational dependency.
Define the environment and required outcome
Describe the product’s intended role, network location, users, data, integrations, availability requirement, expected service life, and management model. Identify whether it will communicate with cloud services, mobile applications, identity providers, video or access platforms, or vendor support systems. Requirements should distinguish mandatory capabilities from preferences and name the team responsible after installation.
Ask for lifecycle evidence
- Identification: How are the model, hardware revision, software version, and device identity inventoried?
- Configuration and access: Which settings, roles, accounts, authentication methods, certificates, and administrative interfaces are available?
- Updates: How are security updates delivered, authenticated, documented, installed, and recovered if deployment fails?
- Support: What support period, end-of-support notice, security advisory, and vulnerability-reporting process is documented?
- Visibility: Which security, administrative, health, and time-synchronized logs or alerts can authorized operators obtain?
- Data: What information is stored, transmitted, exported, backed up, or sent to a vendor service, and how can it be deleted?
- Retirement: What supported process removes credentials, customer data, licenses, cloud associations, and management records?
Request current manuals, policy pages, release notes, advisory examples, and supported integration documentation. A questionnaire response without a product document, demonstration, or contractual commitment may be difficult to rely on years later.
Evaluate the operating cost, not only acquisition
Consider the tools and labor needed for inventory, secure configuration, certificate and account management, firmware deployment, configuration backup, log collection, monitoring, and replacement. Determine whether required functions depend on a subscription or external service and what happens when that service changes or ends. Confirm how responsibilities are divided among DSE, the customer, the manufacturer, another integrator, and any cloud provider.
Validate before standardizing
Use a representative evaluation to test documented workflows in the intended architecture. Confirm onboarding, authentication, least-privilege roles, logging, time, update and rollback behavior, backup or export, integrations, and reset or decommissioning. Record exact hardware and software versions because results from one combination should not be generalized to another.
Finally, maintain a decision record: requirements, evidence, exceptions, approvers, support assumptions, and an exit plan. Good procurement does not promise that risk disappears. It gives future operators the information and supported controls needed to manage risk deliberately.
Review the official source
NIST IR 8259 Rev. 1 — Foundational Cybersecurity Activities for IoT Product Manufacturers · Published April 20, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE