NIST SP 800-61 Rev. 3 Incident response and recovery implementation hub
Use NIST SP 800-61 Rev. 3 to connect preparation and lessons learned with active detection, response, recovery, and incident communications across all six CSF 2.0 Functions. It is intended for most organizations, regardless of sector or size, and for everyone responsible for preparing for, detecting, responding to, or recovering from cybersecurity incidents.
Use one incident model across handlers, asset owners, leadership, technology teams, legal and privacy teams, public affairs, human resources, physical security, providers, and recovery personnel. Define authority, deputies, supplier boundaries, secure communication paths, evidence safeguards, and recovery criteria before an incident.
NIST published Rev. 3 in April 2025 and superseded the August 2012 Rev. 2. The new edition is a CSF 2.0 : a published baseline of outcomes for a shared incident-response use case that an organization can use as input to its own Target Profile. It is not a universal notification clock, severity scale, certification, or step-by-step playbook. Nongovernmental organizations may use it voluntarily; binding federal authority and applicable laws, regulations, policies, and contracts still control their own duties.
Build an incident-response operating model
Rev. 3 organizes outcomes as cybersecurity risk management rather than a single linear checklist. Follow this path from publication status and lifecycle design to playbooks, evidence, communications, recovery, and external obligations.
Start here: status, scope, and lifecycle
Understand the April 2025 final publication, its replacement of Rev. 2, the voluntary-versus-incorporated distinction, and how all six CSF 2.0 Functions support incident response.
Prepare and operate
Turn the profile into scenario playbooks, organization-defined risk criteria, escalation authority, third-party coordination, and recovery decisions.
Evidence and continuous improvement
Preserve investigation records and incident data with integrity and provenance, complete recovery documentation, and route lessons through Identify Improvement.
Compare and apply
Keep NIST guidance distinct from operational playbooks, continuity and incident-management standards, and binding notification regimes.
Map Rev. 3 outcomes to owners and evidence
Turn the selected Rev. 3 outcomes into assigned work, evidence requests, decision records, and review points.
- Scope the work by service, asset, team, provider, or incident scenario.
- Assign each outcome, decision, evidence request, and review point to an owner.
- Keep policies, procedures, incident records, and recovery evidence linked to the relevant outcome.
- Review gaps after exercises and incidents and track the resulting improvements.