Back to Frameworks
Frameworks

NIST SP 800-61r3

Framework Name

NIST SP 800-61, Revision 3 (Incident Response Recommendations and Considerations for Cybersecurity Risk Management)

Type

Voluntary

Region / Jurisdiction

United States (widely referenced globally as an incident response reference model)

Enforcing Body / Certifying Party

National Institute of Standards and Technology (NIST). There is no certifying body and no certification, organizations use it as guidance to build their own incident response programs

Penalty / Consequence of Non-Compliance

No direct penalty, and nothing to be certified against. The practical consequence is indirect: regulators, auditors, and cyber insurers increasingly expect a documented, defensible incident response process, and this is the standard most commonly used to build one

What It Is & Why It Matters

NIST SP 800-61 provides guidance on how to prepare for, detect, respond to, and recover from cybersecurity incidents. Revision 3, published in April 2025, is not a minor update, it's a full rewrite that replaced the document's previous title, the Computer Security Incident Handling Guide, which had stood unchanged since 2012. Rather than walking through incident response as its own separate playbook, Revision 3 rebuilt the entire guide around the six functions of NIST CSF 2.0, treating incident response as something woven through an organization's broader cybersecurity risk management, not a bolt-on process that only activates once something goes wrong.

It matters because incident response is one of the areas regulators and courts scrutinize most closely after a breach, and having no documented process, or an outdated one, looks bad in exactly the moment it matters most. This is the standard most auditors, insurers, and regulators implicitly compare an organization's incident response plan against, even without a formal requirement to use it. For any company already aligning with NIST CSF 2.0, this is the natural companion document for the "Respond" and "Recover" functions specifically.

Who Needs It

  • You want a documented, defensible incident response process, whether or not a specific law requires one
  • You already use or are building toward NIST CSF 2.0 and want detailed guidance for its Respond and Recover functions
  • You are preparing for cyber insurance underwriting, which increasingly asks about incident response maturity
  • Your incident response plan hasn't been reviewed since before 2025 and may still reflect the old 2012 structure
Book A Demo