NIST SP 800-61 Rev. 3Free Resource

NIST SP 800-61 Rev. 3 Incident response and recovery implementation hub

Use NIST SP 800-61 Rev. 3 to connect preparation and lessons learned with active detection, response, recovery, and incident communications across all six CSF 2.0 Functions. It is intended for most organizations, regardless of sector or size, and for everyone responsible for preparing for, detecting, responding to, or recovering from cybersecurity incidents.

By Sorena AIApril 2025 NIST finalNo signup required
Quick scan
IR
Implementation guide
How Rev. 3 reframes as cybersecurity risk management.
Playbook template
A scenario-ready structure for triage, mitigation, communication, and recovery.
Severity and SLA model
How to convert NIST risk evaluation factors into prioritization and response timing.

Use one incident model across handlers, asset owners, leadership, technology teams, legal and privacy teams, public affairs, human resources, physical security, providers, and recovery personnel. Define authority, deputies, supplier boundaries, secure communication paths, evidence safeguards, and recovery criteria before an incident.

Key dates
Apr 2025
Published
CSF 2.0
Profile
RS plus RC
Integrated
Evidence
Preserved
What NIST SP 800-61 Rev. 3 helps you do
Run incident response across CSF 2.0
Use Govern, Identify, and Protect to prevent or prepare for incidents and reduce impact. Use Detect, Respond, and Recover to discover, manage, contain, eradicate, and recover from incidents. Feed evaluations and lessons into improvements.
Prioritize and manage incidents by risk
Define risk factors such as asset criticality, functional impact, data impact, stage of observed activity, threat-actor characteristics, and recoverability. Use them to validate reports, estimate severity and urgency, categorize incidents such as ransomware or account takeover, prioritize response, escalate resources or involve higher management, and decide when recovery starts. NIST does not prescribe universal severity bands or response times.
Preserve trustworthy response records
Record investigation actions, collect incident data and metadata, preserve integrity and provenance, restrict access, and follow the organization's retention and evidence-preservation procedures.
Analyze
Communicate
Recover
Publication details
Editorial metadata for this artifact
Author
Sorena AI
Published
Mar 4, 2026
Updated
Jul 24, 2026

NIST published Rev. 3 in April 2025 and superseded the August 2012 Rev. 2. The new edition is a CSF 2.0 : a published baseline of outcomes for a shared incident-response use case that an organization can use as input to its own Target Profile. It is not a universal notification clock, severity scale, certification, or step-by-step playbook. Nongovernmental organizations may use it voluntarily; binding federal authority and applicable laws, regulations, policies, and contracts still control their own duties.

Recommended reading path

Build an incident-response operating model

Rev. 3 organizes outcomes as cybersecurity risk management rather than a single linear checklist. Follow this path from publication status and lifecycle design to playbooks, evidence, communications, recovery, and external obligations.

1

Start here: status, scope, and lifecycle

Understand the April 2025 final publication, its replacement of Rev. 2, the voluntary-versus-incorporated distinction, and how all six CSF 2.0 Functions support incident response.

2

Prepare and operate

Turn the profile into scenario playbooks, organization-defined risk criteria, escalation authority, third-party coordination, and recovery decisions.

3

Evidence and continuous improvement

Preserve investigation records and incident data with integrity and provenance, complete recovery documentation, and route lessons through Identify Improvement.

4

Compare and apply

Keep NIST guidance distinct from operational playbooks, continuity and incident-management standards, and binding notification regimes.

Next step

Map Rev. 3 outcomes to owners and evidence

Turn the selected Rev. 3 outcomes into assigned work, evidence requests, decision records, and review points.

What this unlocks
  • Scope the work by service, asset, team, provider, or incident scenario.
  • Assign each outcome, decision, evidence request, and review point to an owner.
  • Keep policies, procedures, incident records, and recovery evidence linked to the relevant outcome.
  • Review gaps after exercises and incidents and track the resulting improvements.