Standards & Compliance

What is RFC?

Also known as: Request for Comments

Definition

RFC (Request for Comments) is a document series published by the Internet Engineering Task Force (IETF) that defines internet protocols, standards, and conventions.

An RFC, or Request for Comments, is a formal document from the Internet Engineering Task Force (IETF) that describes specifications for internet protocols, procedures, and conventions. The series began in 1969 as part of the ARPANET project and has since grown to over 9,000 documents. Each RFC is assigned a unique number and, once published, is never modified; corrections or updates appear in subsequent RFCs.

RFCs progress through a maturity ladder. A document starts as an Internet-Draft, undergoes community review, and may be published as an RFC. The IETF classifies RFCs into several categories: Standards Track (Proposed Standard, Draft Standard, Internet Standard), Best Current Practice (BCP), Informational, Experimental, and Historic. An Internet Standard, the highest level, requires proven interoperability and broad deployment. For example, RFC 791 defines the Internet Protocol version 4 (IPv4), and RFC 793 defines TCP.

The RFC Editor, currently operated by the Association Management Solutions under contract with the IETF, manages the publication process. The editorial board ensures consistency and quality. RFCs are freely available online and serve as the definitive reference for internet engineers, network operators, and researchers. They form the core of internet governance by consensus, not by fiat.

Key facts

  • First RFC (RFC 1) was published in April 1969 by Steve Crocker.
  • RFCs are never revised; errata and updates are published as new RFCs.
  • Only a small fraction of RFCs reach Internet Standard status.
  • The RFC Editor maintains the official repository at rfc-editor.org.
  • RFC 2026 defines the standards process used by the IETF.

How it works in practice

When a network engineer configures BGP on a router, they consult RFC 4271, which defines the Border Gateway Protocol version 4. If they need to implement IPsec, they reference RFC 4301. Each RFC provides the exact packet formats, state machines, and operational requirements needed for interoperable implementations.

Related terms

IETF Internet-Draft STD BCP RFC Editor Standards Track

References

More in Standards & Compliance

BCP 14

BCP 14 defines the normative meaning of MUST, SHOULD, MAY, and related keywords used in RFCs to specify requirement levels in Internet standards.

BCP 38

BCP 38 (RFC 2827) is a Best Current Practice that defines ingress filtering to prevent packets with spoofed source IP addresses from leaving a network.

GDPR

The General Data Protection Regulation (GDPR) is an EU law that governs the processing of personal data and applies to any organization worldwide that handles data of EU residents.

HIPAA

HIPAA is a 1996 US federal law that sets national standards for protecting sensitive patient health information from disclosure without consent or knowledge.

IANA

IANA is the function that coordinates global IP address allocation, manages the DNS root zone, and assigns protocol numbers used in Internet standards, ensuring unique identifiers across the network.

ICANN

ICANN is a nonprofit organization that coordinates the Domain Name System (DNS) root zone, accredits registrars, and oversees the Internet Assigned Numbers Authority (IANA) functions for global unique identifiers.

IETF

The Internet Engineering Task Force (IETF) is an open international community of network designers, operators, vendors, and researchers that develops voluntary internet standards, primarily through working groups and the RFC document series.

ISO 27001

ISO 27001 is an international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).

ITU-T

ITU-T is the United Nations agency that sets global telecommunications standards, including X.509 certificates and G-series video codecs.

PCI DSS

PCI DSS is the mandatory security standard for any organization that stores, processes, or transmits credit card data, enforced by the payment card brands.

Who Is Online

In total there are 63 users online: 0 registered, 55 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Applebot Baiduspider Bingbot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 369