Use NIST SP 800-61 Rev. 3 to connect preparation and lessons learned with active detection, response, recovery, and incident communications across all six CSF 2.0 Functions. It is intended for most organizations, regardless of sector or size, and for everyone responsible for preparing for, detecting, responding to, or recovering from cybersecurity incidents.
Use one incident model across handlers, asset owners, leadership, technology teams, legal and privacy teams, public affairs, human resources, physical security, providers, and recovery personnel. Define authority, deputies, supplier boundaries, secure communication paths, evidence safeguards, and recovery criteria before an incident.
NIST published Rev. 3 in April 2025 and superseded the August 2012 Rev. 2. The new edition is a CSF 2.0 : a published baseline of outcomes for a shared incident-response use case that an organization can use as input to its own Target Profile. It is not a universal notification clock, severity scale, certification, or step-by-step playbook. Nongovernmental organizations may use it voluntarily; binding federal authority and applicable laws, regulations, policies, and contracts still control their own duties.
Rev. 3 organizes outcomes as cybersecurity risk management rather than a single linear checklist. Follow this path from publication status and lifecycle design to playbooks, evidence, communications, recovery, and external obligations.
Understand the April 2025 final publication, its replacement of Rev. 2, the voluntary-versus-incorporated distinction, and how all six CSF 2.0 Functions support incident response.
Turn the profile into scenario playbooks, organization-defined risk criteria, escalation authority, third-party coordination, and recovery decisions.
Preserve investigation records and incident data with integrity and provenance, complete recovery documentation, and route lessons through Identify Improvement.
Keep NIST guidance distinct from operational playbooks, continuity and incident-management standards, and binding notification regimes.
Turn the selected Rev. 3 outcomes into assigned work, evidence requests, decision records, and review points.