Standards & Compliance

What is BCP 14?

Also known as: RFC 2119

Definition

BCP 14 defines the normative meaning of MUST, SHOULD, MAY, and related keywords used in RFCs to specify requirement levels in Internet standards.

BCP 14, also known as RFC 2119, is the Best Current Practice document that standardizes the interpretation of key words used to indicate requirement levels in Internet Standards Track documents. It was published in March 1997 by S. Bradner. The document defines six terms: MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, SHOULD NOT, RECOMMENDED, MAY, and OPTIONAL. Each term carries a precise, legally-tinged meaning that authors and implementers must follow when reading or writing an RFC.

How it works: When an RFC says a behavior is REQUIRED (MUST), the specification demands that all compliant implementations implement that behavior. SHOULD indicates a strong recommendation that may be ignored only after careful consideration. MAY grants permission; an implementation is free to include or omit the feature. The document also clarifies that these terms are not used arbitrarily. They appear in uppercase to distinguish them from ordinary English usage. RFC 2119 does not define any new protocol or technology. It provides a shared vocabulary for writing unambiguous requirements, which is essential for interoperability.

Where it sits in the wider stack: BCP 14 is part of the RFC Editor's Best Current Practice series, which means it represents the consensus of the IETF community on how to write standards. It is referenced by thousands of subsequent RFCs. In 2017, RFC 8174 updated BCP 14 to clarify that the key words must be in uppercase for their normative meaning to apply. Without BCP 14, RFC authors would lack a consistent way to express obligation, recommendation, or permission, leading to confusion during implementation and testing.

Key facts

  • Published as RFC 2119 in March 1997 by Scott Bradner.
  • Defines six key words: MUST, MUST NOT, SHOULD, SHOULD NOT, MAY, and OPTIONAL.
  • Updated by RFC 8174 in 2017 to require uppercase usage for normative meaning.
  • Classified as Best Current Practice 14 (BCP 14) by the IETF.
  • Referenced by thousands of RFCs to specify compliance levels.

How it works in practice

An RFC specifying a new HTTP header might write: "Implementations MUST include the Date header in all responses." This means any implementation claiming conformance with that RFC must include the Date header. If the RFC instead said "Implementations SHOULD include the Date header," a developer could omit it only after determining that the omission is acceptable for their specific use case.

Related terms

RFC 8174 MUST SHOULD MAY Best Current Practice Standards Track IETF

References

More in Standards & Compliance

BCP 38

BCP 38 (RFC 2827) is a Best Current Practice that defines ingress filtering to prevent packets with spoofed source IP addresses from leaving a network.

GDPR

The General Data Protection Regulation (GDPR) is an EU law that governs the processing of personal data and applies to any organization worldwide that handles data of EU residents.

HIPAA

HIPAA is a 1996 US federal law that sets national standards for protecting sensitive patient health information from disclosure without consent or knowledge.

IANA

IANA is the function that coordinates global IP address allocation, manages the DNS root zone, and assigns protocol numbers used in Internet standards, ensuring unique identifiers across the network.

ICANN

ICANN is a nonprofit organization that coordinates the Domain Name System (DNS) root zone, accredits registrars, and oversees the Internet Assigned Numbers Authority (IANA) functions for global unique identifiers.

IETF

The Internet Engineering Task Force (IETF) is an open international community of network designers, operators, vendors, and researchers that develops voluntary internet standards, primarily through working groups and the RFC document series.

ISO 27001

ISO 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

ITU-T

ITU-T is the United Nations agency that sets global telecommunications standards, including X.509 certificates and G-series video codecs.

PCI DSS

PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits credit card data, enforced by the payment card brands.

Regional Internet Registry

A Regional Internet Registry (RIR) is an organization that manages the allocation and registration of Internet number resources (IP addresses and Autonomous System Numbers) within a specific geographic region.

Who Is Online

In total there are 53 users online: 0 registered, 47 guests and 6 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: Applebot Baiduspider Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 369