Wonders

The Rabbit Hole · Citation guides

How to Cite a White Paper or Industry Report

Cite a white paper, think-tank paper or industry report in APA 7, MLA 9, Chicago, Harvard, IEEE and Vancouver, including the report number and the issuing organisation.

Sep 22, 2026
How to Cite a White Paper or Industry Report

TL;DR

Every style treats a white paper as a report: the issuing organisation is the author when no individual is named, the report or series number goes with the title, and the URL or DOI points at the issuer's own copy rather than a news summary. APA and Harvard have dedicated report forms; IEEE has a published white-paper example; Chicago treats reports as books; MLA's only free report guidance is flagged as eighth-edition content.

"White paper" is a publishing label, not a citation category. A vendor white paper, a think-tank working paper and a standards body's framework document are all cited through the same report machinery: an organisation or a named team as author, a title, a number that identifies the document within a series, the issuing body, and a link to the issuer's own copy.

The worked example is real and was verified on 22 September 2026 against the issuing body's publication record and against Crossref: NIST CSWP 29, The NIST Cybersecurity Framework (CSF) 2.0, authored by the National Institute of Standards and Technology, published 26 February 2024, DOI 10.6028/NIST.CSWP.29. CSWP is NIST's cybersecurity white paper series; its landing page is at csrc.nist.gov/pubs/cswp/29/the-nist-cybersecurity-framework-csf-20/final.

What to Collect

Quick Reference by Major Style

APA (7th Edition)

APA's Common Reference Examples handout publishes two report forms. Both examples below are APA's own, verbatim.

Report by a Group Author:

World Health Organization. (2025). Global report on neglected tropical diseases. https://iris.who.int/server/api/core/bitstreams/9c4655d8-3671-4503-ae51-4a80bb44d5e0/content

Report by Individual Authors:

Winthrop, R., Ziegler, L., Handa, R., & Fakoya, F. (2019). How playful learning can help leapfrog progress in education. Center for Universal Education at Brookings. https://www.brookings.edu/wp-content/uploads/2019/04/how_playful_learning_can_help_leapfrog_progress_in_education.pdf

The University of Queensland Library's APA 7th guide publishes an Industry/corporate report template with a slot for the report number, verbatim:

Author(s) - last name, initial(s) or company name - use & for multiple authors. (Year). Title of report - italicised (Report number - if available). Publisher - include if different to author. Web address - if available

Applied to the verified example, where the author and the publisher are the same body, so the publisher is not repeated:

National Institute of Standards and Technology. (2024). The NIST cybersecurity framework (CSF) 2.0 (NIST CSWP 29). https://doi.org/10.6028/NIST.CSWP.29

In-text: (National Institute of Standards and Technology, 2024)

Long organisation names are usually abbreviated after the first citation. That is a general author rule rather than a report rule, so check how your style handles it before you shorten anything.

MLA (9th Edition)

The MLA Style Center's post "How do I cite a company's report?" carries MLA's own banner: "This post relates to content in the eighth edition of the MLA Handbook." Check the ninth edition before relying on it. Its rule is that a report is cited by following the MLA format template, and that the company or organisation is usually the publisher unless another entity published it. Three of its examples, verbatim:

Reading at Risk: A Survey of Literary Reading in America. National Endowment for the Arts, June 2004.

Hart Research Associates. It Takes More Than a Major: Employer Priorities for College Learning and Student Success. Association of American Colleges and Universities, 2013, www.aacu.org/publications-research/periodicals/it-takes-more-major-employer-priorities-college-learning-and.

Powell, Catherine, and Ann Mei Chang. Women in Tech as a Driver for Growth in Emerging Economies. Council on Foreign Relations Press, July 2016, www.cfr.org/technology-and-science/women-tech-driver-growth-emerging-economies/p38097.

Following the first pattern, since NIST both wrote and published the paper:

The NIST Cybersecurity Framework (CSF) 2.0. National Institute of Standards and Technology, Feb. 2024. NIST CSWP 29, doi.org/10.6028/NIST.CSWP.29.

In-text: (NIST Cybersecurity Framework)

Chicago (18th Edition)

The free Citation Quick Guide has no report entry — its thirteen entries run from book to personal communication, and a report is not among them. Murdoch University's Chicago author-date guide does publish a reports page, and its stated rule is short: "Reports are generally treated as Books." So the report takes the book shape, with the issuing body in the author slot and the number kept with the title:

National Institute of Standards and Technology. 2024. The NIST Cybersecurity Framework (CSF) 2.0. NIST CSWP 29. Gaithersburg, MD: National Institute of Standards and Technology. https://doi.org/10.6028/NIST.CSWP.29.

In-text: (National Institute of Standards and Technology 2024)

Because Murdoch's page gives a rule rather than a worked report example, treat the entry above as the book form applied, and check your department's guide if it has a report entry of its own.

Harvard (Cite Them Right)

Cite Them Right is subscription-only; the templates below are the University of Sheffield Library's, from the guide that states it is based on Cite Them Right. Sheffield's two online report templates, verbatim:

Author Surname, INITIAL(S) or Corporate Author (Year of publication) Title of report. Paper number (if applicable). Available at: URL (Accessed: date).

Author Surname, INITIAL(S) or Corporate Author (Year of publication) Title of report. Paper number (if applicable). doi:

Sheffield's own example of a think-tank paper with a number, verbatim:

Snowdon, C. (2017) Cheap as chips: Is a healthy diet affordable? IEA Discussion Paper No. 82. Available at: https://iea.org.uk/wp-content/uploads/2017/03/Cheap-as-Chips-PDF.pdf (Accessed: 30 March 2017).

Note the difference between Sheffield's two templates: the URL form ends with "Available at: URL (Accessed: date)", and the DOI form ends at the DOI with neither. Sheffield publishes no explanation for the difference, but the practical effect is that a report with a DOI needs no accessed date. Applied to the verified example:

National Institute of Standards and Technology (2024) The NIST cybersecurity framework (CSF) 2.0. NIST CSWP 29. doi: https://doi.org/10.6028/NIST.CSWP.29.

In-text: (National Institute of Standards and Technology, 2024)

IEEE

The IEEE Reference Guide has a Reports section, and its Report Online examples include a white paper. Both of the following are IEEE's own, verbatim:

J. K. Author, "Title of report," Company, City, State, Country, Rep. no., (optional: vol./issue), Date. Accessed: Date. [Online]. Available: site/path/file

F. Zhao, "Smartphone solutions white paper," Shenzhen, China, Huawei, White Paper, 2012. [Online]. Available: http://www.huawei.com/ilink/en/download/HW_193034

Applied to the verified example:

National Institute of Standards and Technology, "The NIST cybersecurity framework (CSF) 2.0," NIST, Gaithersburg, MD, USA, NIST CSWP 29, Feb. 2024. [Online]. Available: https://doi.org/10.6028/NIST.CSWP.29

In-text: [1]

Vancouver / AMA

The University of Queensland Library's Vancouver (AMA) guide publishes a report template, verbatim:

Author AA, Author BB. Title of report or document. Name of Organisation. Report number. (if available) Series number. (if available) Month DD, YYYY. (date published if available) Updated Month DD, YYYY. (date updated if available) Accessed Month DD, YYYY. URL

Applied to the verified example:

National Institute of Standards and Technology. The NIST cybersecurity framework (CSF) 2.0. National Institute of Standards and Technology. NIST CSWP 29. February 26, 2024. Accessed September 22, 2026. https://doi.org/10.6028/NIST.CSWP.29

UQ's guidance on when to use this form is useful: use it for documents that are formal in nature and summarise information on an issue, event or problem, and use the web-page form otherwise.

Missing Elements

No individual author. Use the organisation. APA calls this a group author; Harvard guides call it a corporate author. Where the organisation is also the publisher, do not repeat the name.

No report number. Many corporate white papers have none. Leave the slot out rather than inventing a number, and make the title and date do the identifying work.

No date on the PDF. Check the issuer's landing page, which usually carries a publication date even when the file does not. If there is genuinely no date, use the undated convention for your style and give the date you accessed it.

A revised version. Say which version you read. NIST, for instance, publishes planning notes and revisions against a paper's landing page after publication; a reader needs to know whether you used the original or an update.

Only a paywalled or gated copy. Cite the document, and note in your text that it sits behind registration. Do not cite a mirror of unclear provenance as though it were the issuer's copy.

Common Mistakes

Sources for These Formats

Full style rules: APA, MLA, Chicago, Harvard, IEEE, Vancouver.

Reports and white papers are often outside the journal indexes. Wonders searches OpenAlex and Semantic Scholar and has no index of its own, so a paper that is not deposited anywhere will not turn up — go to the issuing body's own publications page for those.

Frequently asked questions

Is a white paper a report?

For citation purposes, yes. None of the five styles here has a separate white-paper category; all of them route it through the report form. The IEEE Reference Guide is the one that shows the label explicitly, with a published example that ends "Huawei, White Paper, 2012".

Who is the author when no person is named?

The issuing organisation. APA's own handout calls this a "Report by a Group Author" and gives the World Health Organization as the author of its 2025 report. Harvard and Vancouver guides do the same. Do not leave the author slot empty and start with the title unless nothing at all is named.

Do I need the report number?

Include it whenever the document has one — NIST CSWP 29, IEA Discussion Paper No. 82, a series number on a working paper. It is often the only thing that distinguishes one paper from the next in a long-running series, and the APA, Harvard, IEEE and Vancouver templates all have a slot for it.

Should I link the issuer's PDF or a news article about it?

The issuer's own page or PDF. A press write-up is a different source with a different author, and if you are citing the report's findings you need the report. If you also rely on the coverage, cite both.

How do I cite a consultancy report I had to pay for or that is behind a client login?

Cite it the way you cite any report, and say in your text that access is restricted. If the document is genuinely internal and unpublished, it is not a published source: describe it in the text and, where your style allows, treat it as personal communication rather than giving it a reference-list entry.

More useful guides

All citation guides

Finding these guides useful?

Try these techniques in Wonders — an AI workspace for literature review. 14 days free. Students get 50% off.

Start free →