- Provides the CSF structure that the new publication uses.
"organized as Functions, Categories, and Subcategories"
Practical NIST SP 800-61 Rev. 3 Changes Guide guidance with source-linked decisions, owner checklists, evidence records, and implementation steps.
Turn guidance into a standalone operating path with clear scope, accountable owners, evidence requirements, review cadence, and decision outputs.
Structured answer sets in this page tree.
Cited legal and guidance references.
NIST SP 800-61 Rev. 3 is not just a refreshed incident-handling guide. The revision supersedes SP 800-61r2, rewrites the publication around cybersecurity risk management, and presents the content as a CSF 2.0 Community Profile for incident response and cyber risk management.
The biggest change is the scope. Rev. 3 moves away from a static how-to guide for detecting, analyzing, prioritizing, and handling incidents, and instead focuses on recommendations and considerations for incorporating incident response throughout cybersecurity risk management.
The publication also reorganizes the material as a CSF 2.0 Community Profile, using CSF Functions, Categories, and Subcategories to organize the guidance and map incident response activities across Govern, Identify, Protect, Detect, Respond, and Recover.
Rev. 2 readers will notice that Rev. 3 is less about a single incident lifecycle and more about managing incident response as part of broader cyber risk management. NIST explicitly says the details of how to perform incident response change often and vary across technologies, environments, and organizations, so those details are no longer captured in one static publication.
Instead, the document points readers toward the CSF 2.0 ecosystem, including the CSF website, the Incident Response project page, and the Cybersecurity and Privacy Reference Tool (CPRT) for mappings and additional implementation resources.
The revision is a complete rewrite intended to improve clarity and usability while removing outdated material and material covered in more depth elsewhere. It also shifts the focus from a narrow incident-handling model to continuous cybersecurity risk management across all six CSF Functions.
For practical use, that means teams should look for the revised lifecycle model, the roles and responsibilities section, the policy and procedures guidance, and the two-part CSF Community Profile tables that separate preparation from incident response.
Use the cited sources to turn the guidance into scoped decisions, owners, evidence requests, and review checkpoints.
Create source-linked tasks, evidence requests, and review checkpoints for this NIST SP 800-61 Rev. 3 scope.
Check source coverage, ownership, evidence gaps, and next steps before publishing or operationalizing the work.
"organized as Functions, Categories, and Subcategories"
"April 2025"
"This publication seeks to assist organizations with incorporating cybersecurity incident response recommendations and considerations throughout their cybersecurity risk management activities"