Source context: this article examines information published by the source on September 03, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What was published
NIST has released a draft revision of Special Publication (SP) 800-38E, titled “Recommendation for Block Cipher Modes of Operation: XTS-AES Mode for Confidentiality on Storage Devices.” This document provides the approved framework for using the XTS-AES mode of operation to ensure data confidentiality specifically on storage devices.
Status and scope
The publication is currently a draft available for public comment through October 16, 2026. It does not reproduce the full technical specification but instead incorporates IEEE Std. 1619-2025 by reference. The scope of this guidance is limited to the confidentiality of data at rest on storage media using XTS-AES.
What the guidance covers
The revision updates the referenced specification to IEEE Std. 1619-2025 and provides clarifications on several critical technical parameters:
* Scope of Use: Defined boundaries for where XTS-AES is approved for deployment.
* Limits: Specific requirements regarding data-unit and key-scope limits.
* Key Requirements: Technical mandates for the keys used within this mode.
* Ciphertext Stealing: Clarifications on the ordering conventions used for ciphertext stealing to ensure consistent implementation.
How organizations can use it
Infrastructure owners and vulnerability management teams can use this draft to evaluate whether their current storage encryption implementations align with updated federal recommendations. Because XTS-AES is a foundational component of many hardware-encrypted drives (SEDs) and software-defined storage layers, this guidance allows defenders to identify potential gaps in how keys are scoped or how ciphertext stealing is handled.
Our analysis suggests that organizations should use the draft as a benchmark for technical audits. Rather than relying on vendor claims of “AES-256 encryption,” teams can specifically query whether the implementation adheres to the IEEE Std. 1619-2025 conventions referenced in the draft.
Decisions and next steps
Security leaders should determine if their current storage hardware or software vendors are aligning with IEEE Std. 1619-2025.
Recommended Validation Path:
1. Inventory Identification: Identify all assets utilizing XTS-AES for data-at-rest encryption.
2. Vendor Inquiry: Request technical documentation from vendors confirming adherence to the specific key-scope and ciphertext stealing conventions outlined in IEEE Std. 1619-2025.
3. Configuration Review: For software-defined storage, verify that the implementation of XTS-AES matches the updated ordering conventions for ciphertext stealing.
Limits and open questions
As this is a draft publication, it is not yet a final requirement. There is a residual risk that final revisions following the public comment period may alter these specifications. Furthermore, because NIST incorporates IEEE Std. 1619-2025 by reference, a full understanding of the requirements requires access to the IEEE standard itself; the SP 800-38Er1 document alone is not a complete technical manual for implementation.
Source and editorial note
XTS-AES Mode on Storage Devices: SP 800-38Er1 Available for Public Comment September 03, 2026 · Source date: September 03, 2026 · Retrieved September 03, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗