.png)
.png)

NIST SP 800-61r3
Framework Name
NIST SP 800-61, Revision 3 (Incident Response Recommendations and Considerations for Cybersecurity Risk Management)
Type
Voluntary
Region / Jurisdiction
United States (widely referenced globally as an incident response reference model)
Enforcing Body / Certifying Party
National Institute of Standards and Technology (NIST). There is no certifying body and no certification, organizations use it as guidance to build their own incident response programs
Penalty / Consequence of Non-Compliance
No direct penalty, and nothing to be certified against. The practical consequence is indirect: regulators, auditors, and cyber insurers increasingly expect a documented, defensible incident response process, and this is the standard most commonly used to build one
What It Is & Why It Matters
NIST SP 800-61 provides guidance on how to prepare for, detect, respond to, and recover from cybersecurity incidents. Revision 3, published in April 2025, is not a minor update, it's a full rewrite that replaced the document's previous title, the Computer Security Incident Handling Guide, which had stood unchanged since 2012. Rather than walking through incident response as its own separate playbook, Revision 3 rebuilt the entire guide around the six functions of NIST CSF 2.0, treating incident response as something woven through an organization's broader cybersecurity risk management, not a bolt-on process that only activates once something goes wrong.
It matters because incident response is one of the areas regulators and courts scrutinize most closely after a breach, and having no documented process, or an outdated one, looks bad in exactly the moment it matters most. This is the standard most auditors, insurers, and regulators implicitly compare an organization's incident response plan against, even without a formal requirement to use it. For any company already aligning with NIST CSF 2.0, this is the natural companion document for the "Respond" and "Recover" functions specifically.
Who Needs It
- You want a documented, defensible incident response process, whether or not a specific law requires one
- You already use or are building toward NIST CSF 2.0 and want detailed guidance for its Respond and Recover functions
- You are preparing for cyber insurance underwriting, which increasingly asks about incident response maturity
- Your incident response plan hasn't been reviewed since before 2025 and may still reflect the old 2012 structure