Federal and enterprise security leaders have until September 30, 2026, to shape NIST’s next set of cybersecurity guidance before it takes form. This is an early input stage, not a compliance deadline.
On August 17, 2026, NIST published a blog post and concept paper laying out a “human-centered cybersecurity” approach and asking for public feedback on where it should go next. Authors Julie Haney and Jody Jacobs are collecting comments by email at human-cybersec@nist.gov through the September deadline.
The paper names usability failures as a root cause of control abandonment. Clunky MFA, alert fatigue, and tools that do not fit real workflows push staff to bypass the very controls agencies deploy, including Zero Trust and AI-era security tooling.
NIST calls this a concept paper meant to inform future “practical guidelines and resources” that would complement, not replace, existing NIST publications. No framework, standard, or mandate has been finalized. The paper is a signal of direction and an opportunity for influence, not a compliance rule.
NIST frames people as “not just… vulnerabilities to be contained; they’re also defenders, reporters, and problem-solvers to be empowered.” The agency is also opening an HCC Community of Interest and mailing list for involvement past the comment window.
This initiative is separate from NIST’s February 2026 NCCoE paper on AI agent identity.



Leave a Reply