Artifact GuideGLOBALNIST SP 800-61 Rev. 3

NIST SP 800-61 Rev. 3 Rev. 3 Changes Guide

Practical NIST SP 800-61 Rev. 3 Changes Guide guidance with source-linked decisions, owner checklists, evidence records, and implementation steps.

Turn guidance into a standalone operating path with clear scope, accountable owners, evidence requirements, review cadence, and decision outputs.

Author
Sorena AI
Published
May 9, 2026
Updated
May 9, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated May 9, 2026
Overview

NIST SP 800-61 Rev. 3 is not just a refreshed incident-handling guide. The revision supersedes SP 800-61r2, rewrites the publication around cybersecurity risk management, and presents the content as a CSF 2.0 Community Profile for incident response and cyber risk management.

Section 1

What changed in NIST SP 800-61 Rev. 3

The biggest change is the scope. Rev. 3 moves away from a static how-to guide for detecting, analyzing, prioritizing, and handling incidents, and instead focuses on recommendations and considerations for incorporating incident response throughout cybersecurity risk management.

The publication also reorganizes the material as a CSF 2.0 Community Profile, using CSF Functions, Categories, and Subcategories to organize the guidance and map incident response activities across Govern, Identify, Protect, Detect, Respond, and Recover.

  • Rev. 3 supersedes SP 800-61r2 (August 2012).
  • The document is titled "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile".
  • The new structure emphasizes continuous risk management, not a one-time incident-handling workflow.
Section 2

How Rev. 3 changes the way teams should read the guide

Rev. 2 readers will notice that Rev. 3 is less about a single incident lifecycle and more about managing incident response as part of broader cyber risk management. NIST explicitly says the details of how to perform incident response change often and vary across technologies, environments, and organizations, so those details are no longer captured in one static publication.

Instead, the document points readers toward the CSF 2.0 ecosystem, including the CSF website, the Incident Response project page, and the Cybersecurity and Privacy Reference Tool (CPRT) for mappings and additional implementation resources.

  • Use the publication as a profile and mapping aid, not as a step-by-step incident playbook.
  • Expect the guidance to connect incident response with governance, supply chain risk, continuous monitoring, analysis, mitigation, reporting, and recovery.
  • Use the linked NIST resources for implementation details instead of treating this document as the final procedural authority.
Section 3

What visitors should take away from the Rev. 3 change log

The revision is a complete rewrite intended to improve clarity and usability while removing outdated material and material covered in more depth elsewhere. It also shifts the focus from a narrow incident-handling model to continuous cybersecurity risk management across all six CSF Functions.

For practical use, that means teams should look for the revised lifecycle model, the roles and responsibilities section, the policy and procedures guidance, and the two-part CSF Community Profile tables that separate preparation from incident response.

  • Look for the new CSF-based incident response lifecycle model, including the mapping from the previous four-phase model to CSF Functions.
  • Use the roles-and-responsibilities guidance to account for internal teams, third parties, leadership, legal, public affairs, and asset owners.
  • Use the CSF Community Profile tables to separate preparation and lessons learned from active response and recovery activities.
Primary sources

References and citations

doi.org
Referenced sections
  • Provides the CSF structure that the new publication uses.
"organized as Functions, Categories, and Subcategories"
csrc.nist.gov
Referenced sections
  • States that the publication was developed as a CSF 2.0 Community Profile and includes sections on incident response as part of cybersecurity risk management and on community profile recommendations.
"This publication seeks to assist organizations with incorporating cybersecurity incident response recommendations and considerations throughout their cybersecurity risk management activities"
Related guides

Explore more topics

How should teams handle communications under NIST SP 800-61 Rev. 3 incident response?
How should teams handle communications under NIST SP 800-61 Rev. 3 incident response? Clear, source-linked guidance with practical evidence checks, owner decisions, and implementation steps.
How should teams handle event vs. incident under NIST SP 800-61 Rev. 3 incident response?
How should teams handle event vs. incident under NIST SP 800-61 Rev. 3 incident response? Clear, source-linked guidance with practical evidence checks, owner decisions, and implementation steps.
How should teams handle lessons learned under NIST SP 800-61 Rev. 3 incident response?
How should teams handle lessons learned under NIST SP 800-61 Rev. 3 incident response? Clear, source-linked guidance with practical evidence checks, owner decisions, and implementation steps.
How should teams handle post-incident evidence under NIST SP 800-61 Rev. 3 incident response?
How should teams handle post-incident evidence under NIST SP 800-61 Rev. 3 incident response? Clear, source-linked guidance with practical evidence checks, owner decisions, and implementation steps.
How should teams handle reporting clocks under NIST SP 800-61 Rev. 3 incident response?
How should teams handle reporting clocks under NIST SP 800-61 Rev. 3 incident response? Clear, source-linked guidance with practical evidence checks, owner decisions, and implementation steps.
How should teams handle severity under NIST SP 800-61 Rev. 3 incident response?
How should teams handle severity under NIST SP 800-61 Rev. 3 incident response? Clear, source-linked guidance with practical evidence checks, owner decisions, and implementation steps.
NIST SP 800-61 Rev. 3 compliance playbook
Practical NIST SP 800-61 Rev. 3 compliance playbook guidance with source-linked decisions, owner checklists, evidence records, and implementation steps.
NIST SP 800-61 Rev. 3 CSF 2.0 Incident Profile Guide
Practical NIST SP 800-61 Rev. 3 CSF 2.0 Incident Profile Guide guidance with source-linked decisions, owner checklists, evidence records, and implementation steps.
NIST SP 800-61 Rev. 3 FAQ: practical implementation questions
Standalone NIST SP 800-61 Rev. 3 FAQ questions with source-linked answers, implementation checklists, and evidence guidance.
NIST SP 800-61 Rev. 3 incident communications: stakeholder matrix and notification templates
Practical NIST SP 800-61 Rev. 3 Communications and Escalation Guide guidance with source-linked decisions, owner checklists, evidence records, and implementation steps.
NIST SP 800-61 Rev. 3 Incident Response Playbook Template
Practical NIST SP 800-61 Rev. 3 Incident Response Playbook Template guidance with source-linked decisions, owner checklists, evidence records, and implementation steps.
NIST SP 800-61 Rev. 3 Post-Incident Evidence Log Workflow
A practical NIST SP 800-61 Rev. 3 Post-Incident Evidence Log Workflow with steps, owners, evidence fields, decisions, and source-linked review triggers.
NIST SP 800-61 Rev. 3 Severity Classification and SLA Model
Practical NIST SP 800-61 Rev. 3 Severity Classification and SLA Model guidance with source-linked decisions, owner checklists, evidence records, and implementation steps.
NIST SP 800-61 Rev. 3 vs CISA playbooks: practical side-by-side comparison
Compare NIST SP 800-61 Rev. 3 and CISA playbooks with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
NIST SP 800-61 Rev. 3 vs ISO 22301 business continuity: practical side-by-side comparison
Compare NIST SP 800-61 Rev. 3 and ISO 22301 business continuity with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
NIST SP 800-61 Rev. 3 vs ISO/IEC 27035: practical side-by-side comparison
Compare NIST SP 800-61 Rev. 3 and ISO/IEC 27035 with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
NIST SP 800-61 Rev. 3 vs NIS2 incident reporting: practical side-by-side comparison
Compare NIST SP 800-61 Rev. 3 and NIS2 incident reporting with side-by-side scope, owner, trigger, evidence, cadence, assurance, and decision-rule rows.
NIST SP 800-61 Rev. 3: escalation decision workflow for incident communications
A practical NIST SP 800-61 Rev. 3 Communications Escalation Workflow with steps, owners, evidence fields, decisions, and source-linked review triggers.
What should recovery include in a NIST SP 800-61 Rev. 3 incident response process?
Recovery should include restoring affected services, validating that the incident is contained, confirming monitoring is in place, communicating status, preserving evidence, and deciding when normal operations can safely resume.
Which CSIRT roles should teams define under NIST SP 800-61 Rev. 3?
Which CSIRT roles should teams define under NIST SP 800-61 Rev. 3? Clear, source-linked guidance with practical evidence checks, owner decisions, and implementation steps.