NIST finalises guidance on protecting digital identity and access tokens

NIST and CISA have finalised guidance to help organisations protect identity and access tokens from forgery, theft and misuse across cloud and other digital systems.

NIST finalises guidance on protecting digital identity and access tokens

The US National Institute of Standards and Technology (NIST) and the Cybersecurity and Infrastructure Security Agency (CISA) have finalised guidance on protecting tokens and related identity assertions used to access online services. The publication, NIST Internal Report 8587, was released on 15 September 2026.

The report, titled Protecting Tokens and Assertions from Forgery, Theft, and Misuse, provides implementation guidance for organisations that use tokens as part of their access management infrastructure. It is primarily aimed at federal agencies and the cloud service providers (CSPs) they use, but NIST says the recommendations can also assist other organisations that rely on identity tokens.

Tokens are pieces of information used to identify users and determine what resources they are authorised to access. They are widely used in cloud services and can support functions such as authentication and single sign-on, allowing users to access multiple applications without repeatedly authenticating.

Because tokens can provide access to sensitive resources, their compromise can allow attackers to bypass normal access controls. The report cites an incident in which attackers used forged tokens derived from a stolen commercial signing key to access government email systems, resulting in the theft of more than 60,000 emails from one agency.

The guidance sets out responsibilities for both service providers and organisations using their services. It covers how providers can secure token-related services and how customers can configure and manage those services to reduce the risk of token forgery, theft and misuse.

The final publication was revised following public feedback on a draft released in December 2025. Among the changes, the guidance takes a less prescriptive and more outcome-based approach to cryptographic key protection, while adding further considerations on key usage, protection and storage.

The final version also introduces high-level considerations related to artificial intelligence and the transition to post-quantum cryptography. It adds references to current and emerging standards and provides organisations with additional approaches for functions such as token revocation and sharing signals about tokens.

NIST said the guidance builds on recent updates to its security and privacy controls and responds to requirements under Executive Order 14306. The publication is intended to help organisations strengthen token management as identity-based access becomes an increasingly important part of cloud and digital infrastructure.

Go to Top