Artifact GuideGLOBALNIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 Rev. 3 Changes Guide

Rev. 3 changes the publication's scope, lifecycle model, organization, roles, and implementation approach. Use this guide to identify what must be remapped rather than renaming an old Rev. 2 plan.

Published in April 2025, Rev. 3 supersedes the August 2012 Rev. 2 and organizes incident-response recommendations as a CSF 2.0 Community Profile.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

NIST SP 800-61 Rev. 3 supersedes Rev. 2 and changes how the guidance is used. Rev. 2 was a detailed incident-handling guide built around preparation; detection and analysis; containment, eradication, and recovery; and post-incident activity. Rev. 3 is a that treats incident response as part of cybersecurity risk management, maps the lifecycle to all six CSF 2.0 Functions, and moves changing procedural detail to online resources.

Section 1

What changed in NIST SP 800-61 Rev. 3

Rev. 3 shifts the scope from detailed guidance on detecting, analyzing, prioritizing, and handling incidents to recommendations for incorporating incident response throughout cybersecurity risk management. NIST explains that technical procedures change too often and vary too much by technology, environment, and organization to maintain them in one static publication.

The new lifecycle uses all six CSF 2.0 Functions. Govern, Identify, and Protect support preparation and impact reduction. Detect, Respond, and Recover cover discovery, management, prioritization, containment, eradication, recovery, reporting, notification, and other incident communications. Identify Improvement (ID.IM) receives lessons from every Function so useful changes need not wait for recovery to end.

  • Rev. 3 supersedes SP 800-61r2 (August 2012).
  • The document is titled "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A ".
  • The new structure separates Preparation and Lessons Learned in Table 2 from Incident Response in Table 3.
Section 2

How Rev. 3 changes the way teams should read the guide

Rev. 3 still provides an incident-response lifecycle, but it does not require every organization to adopt that model. NIST says organizations should use the lifecycle framework or model that suits them best and consider incident response throughout cybersecurity risk management.

Use Rev. 3 for outcomes, priorities, recommendations, roles, and mappings. Use organization-specific procedures and NIST's online Incident Response project, CSF resources, and Cybersecurity and Privacy Reference Tool for implementation detail. A Rev. 2 procedure may still be useful, but its scope, roles, dependencies, and references need review against Rev. 3. NIST sets no separate migration deadline; another law, policy, contract, procurement term, or federal authority may set an implementation date for a particular organization.

  • Use the publication as a profile and mapping aid, not as a step-by-step incident playbook.
  • Map existing policy, plans, procedures, roles, suppliers, monitoring, analysis, mitigation, reporting, and recovery work to the Rev. 3 outcomes.
  • Use the linked NIST resources for implementation details instead of treating this document as the final procedural authority.
Section 3

Migration checklist for Rev. 2 users

Appendix C describes Rev. 3 as a full rewrite that improves clarity and usability, removes outdated material and material covered elsewhere, expands lifecycle, role, policy, process, and procedure content, and adds the Community Profile. Treat migration as a mapping and gap-analysis exercise.

Keep useful Rev. 2 procedures where they still fit the organization, but do not claim that they are the Rev. 3 model. Update references, map responsibilities and outcomes, confirm external dependencies, and identify missing preparation, active-response, recovery, communication, and improvement work.

  • Map the former four phases to the CSF Functions and document any organization-specific lifecycle retained.
  • Map Preparation to Govern, all Identify Categories, and Protect; Detection and Analysis to Detect and ID.IM; Containment, Eradication, and Recovery to Respond, Recover, and ID.IM; and Post-Incident Activity to ID.IM.
  • Review roles for leadership, incident handlers, technology teams, legal, public affairs, human resources, physical security, asset owners, and third parties.
  • Compare existing work with Table 2, Preparation and Lessons Learned, and Table 3, Incident Response.
  • Replace stale implementation references with current NIST online resources or organization-approved technical procedures.
  • Test the revised authority, contact, escalation, evidence, communication, and recovery paths before relying on them.
  • Reassess the mapping after material service, technology, supplier, threat, legal, contractual, or organizational changes and after exercises or incidents reveal a gap.
Primary sources

References and citations

doi.org
Referenced sections
  • Provides the CSF outcome structure used to map current and target incident-response work.
doi.org
Referenced sections
  • Appendix C lists the full rewrite, changed scope, CSF-based lifecycle, expanded roles and policy content, and Community Profile organization.
Related guides

Explore more topics

Event vs. Incident in NIST SP 800-61 Rev. 3
An event is observable activity. Declare an incident when analysis shows the occurrence meets documented cybersecurity incident criteria.
How should teams handle communications under NIST SP 800-61 Rev. 3 incident response?
Plan incident coordination, formal notifications, public communication, and voluntary information sharing under NIST SP 800-61 Rev. 3.
How should teams handle lessons learned under NIST SP 800-61 Rev. 3 incident response?
Capture incident-response lessons as they emerge, prioritize them through CSF 2.0 Improvement, and verify changes to plans, controls, training, and recovery.
How should teams handle post-incident evidence under NIST SP 800-61 Rev. 3 incident response?
Preserve incident records, collected data, metadata, integrity, provenance, access controls, and retention decisions under NIST SP 800-61 Rev. 3.
How should teams handle reporting clocks under NIST SP 800-61 Rev. 3 incident response?
NIST SP 800-61 Rev. 3 sets no universal reporting deadline. Build a clock register from each applicable law, regulation, policy, and contract.
How should teams handle severity under NIST SP 800-61 Rev. 3 incident response?
NIST SP 800-61 Rev. 3 sets no universal severity scale. Use documented risk factors to estimate severity and urgency, prioritize response, and reassess.
NIST SP 800-61 Rev. 3 CSF 2.0 Incident Profile Guide
Map NIST SP 800-61 Rev. 3 across CSF 2.0 preparation, Detect-Respond-Recover operations, and continuous improvement without treating the profile as a law or playbook.
NIST SP 800-61 Rev. 3 FAQ: practical implementation questions
Answers on incident declaration, severity, roles, communications, notification clocks, evidence, recovery, and continuous improvement under NIST SP 800-61 Rev. 3.
NIST SP 800-61 Rev. 3 Incident Communications and Escalation
Separate incident coordination, notification, public communication, information sharing, escalation, and elevation, with owners and decision records.
NIST SP 800-61 Rev. 3 Incident Response Playbook Template
Build a scenario-specific incident playbook with declaration criteria, authority, third-party coordination, response evidence, legal overlays, and recovery exit criteria.
NIST SP 800-61 Rev. 3 Incident Severity and Response Targets
Build organization-defined incident severity bands and response targets from NIST risk factors without claiming that NIST prescribes levels or deadlines.
NIST SP 800-61 Rev. 3 Post-Incident Evidence Log Workflow
Preserve incident records and data, document recovery, produce the after-action report, and verify corrective actions under NIST SP 800-61 Rev. 3.
NIST SP 800-61 Rev. 3 vs CISA playbooks: practical side-by-side comparison
Choose NIST SP 800-61 Rev. 3 for an organization-wide incident-response risk model and CISA's playbooks for detailed FCEB incident and vulnerability procedures.
NIST SP 800-61 Rev. 3 vs ISO 22301 business continuity: practical side-by-side comparison
Use NIST SP 800-61 Rev. 3 for cybersecurity incident response and ISO 22301:2019 with Amendment 1:2024 for the business continuity management system.
NIST SP 800-61 Rev. 3 vs ISO/IEC 27035: practical side-by-side comparison
Compare NIST SP 800-61 Rev. 3's CSF 2.0 outcome profile with the ISO/IEC 27035 incident-management process, planning, and ICT response guidance.
NIST SP 800-61 Rev. 3 vs NIS2 incident reporting: practical side-by-side comparison
Use NIST SP 800-61 Rev. 3 to run incident response and the applicable NIS2 national law to assess significant-incident reporting and legal deadlines.
NIST SP 800-61 Rev. 3: escalation decision workflow for incident communications
Run incident coordination, required notifications, public updates, and voluntary information sharing as separate, documented decision streams.
Using NIST SP 800-61 Rev. 3 for Incident Response
Use NIST SP 800-61 Rev. 3 to assign incident-response outcomes, owners, records, communications, and improvements while tracking binding duties separately.
What should recovery include in a NIST SP 800-61 Rev. 3 incident response process?
Select, authorize, prioritize, and verify recovery actions; check restoration assets and restored systems; confirm service restoration; and document recovery closure.
Which CSIRT roles should teams define under NIST SP 800-61 Rev. 3?
Define incident-response leadership, handlers, technical specialists, legal, communications, HR, facilities, asset owners, and providers under NIST SP 800-61 Rev. 3.