NIST SP 800-61 Rev. 3 – Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile

SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting. Framework text may require a separate license unless explicitly provided.
Overview
NIST SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management, is the April 2025 revision of NIST's incident handling guide. It replaces the 2012 Revision 2 and reframes incident response as an integral part of cybersecurity risk management rather than a separate activity run by a separate team, organizing its recommendations as a Community Profile of the NIST Cybersecurity Framework (CSF) 2.0.
The publication is produced by the National Institute of Standards and Technology (NIST) and written by Alexander Nelson, Sanjay Rekhi, and Murugiah Souppaya of NIST with Karen Scarfone. It is voluntary guidance: U.S. federal agencies use it to satisfy incident response expectations under FISMA and OMB policy, and organizations of every size and sector adopt it because the CSF 2.0 vocabulary already anchors their security programs, contracts, and regulatory reporting.
Organizations implement it by mapping their incident response policy, plan, playbooks, and roles to the Profile's Functions, Categories, and Subcategories, closing gaps in preparation (Govern, Identify, Protect) and in incident handling (Detect, Respond, Recover), and feeding lessons learned back through the Improvement Category. Technical detail that Rev. 2 carried in print now lives online, reached through the NIST Cybersecurity and Privacy Reference Tool (CPRT), so the document is paired with a living set of mappings and implementation resources.
Why it Matters
Incidents now occur frequently, cause far more damage than they did in 2012, and often take weeks or months to recover from. NIST SP 800-61 Rev. 3 responds by treating incident response as a continuous part of cybersecurity risk management and by giving every organization a common CSF 2.0 vocabulary for planning, running, and improving it.
Key benefits include:
- Integrate incident response with risk management
Preparation, detection, response, recovery, and lessons learned sit inside the same governance and risk activities the rest of the security program already uses.
- Speak a shared vocabulary
Every recommendation is tied to a CSF 2.0 Function, Category, and Subcategory, so incident response can be discussed with executives, auditors, insurers, and regulators in terms they already know.
- Reflect modern incidents
The life cycle model assumes long, complex incidents and continuous improvement instead of a closed loop that restarts after each event.
- Clarify roles and responsibilities
Section 2 sets out the internal teams, leadership, and third parties that carry incident response duties across all six Functions.
- Stay current without reissuing the document
Playbooks, technical guidance, and mappings to other standards are maintained online through the NIST Cybersecurity and Privacy Reference Tool.
How it Works
NIST SP 800-61 Rev. 3 is a 48-page publication in three parts. Section 1 introduces the document and its purpose, Section 2 explains incident response as part of cybersecurity risk management, including the new CSF 2.0-based life cycle model, roles and responsibilities, and incident response policies, processes, and procedures, and Section 3 presents the CSF 2.0 Community Profile itself in two tables: part 1, Preparation and Lessons Learned, and part 2, Incident Response. References, a glossary, and a change log from Revision 2 complete the document.
Implementation starts by comparing the organization's existing incident response plan and playbooks with the Profile's Subcategories and recording where each is met, partially met, or missing. Teams then assign owners for each Function, align detection sources, escalation paths, containment and eradication steps, and recovery criteria with the Detect, Respond, and Recover outcomes, define reporting and notification obligations, and schedule exercises and post-incident reviews so that lessons learned reach the Improvement Category and change the program.
Within SmartSuite, teams hold the Community Profile as a structured control library, link each Subcategory to the incident response plan sections, playbooks, and detection sources that satisfy it, and record incidents, timelines, decisions, and evidence in one place. Exercises, post-incident reviews, and remediation tasks run on assigned owners and due dates, and dashboards show the state of preparation and response outcomes for leadership and auditors.
Key Elements
- CSF 2.0-based life cycle model
Replaces the Rev. 2 cycle of preparation, detection and analysis, containment, eradication and recovery, and post-incident activity with a model built on the six CSF 2.0 Functions.
- Preparation through Govern, Identify, and Protect
Broader risk management activities that prevent some incidents, prepare the organization for those that occur, and reduce their impact.
- Incident response through Detect, Respond, and Recover
Outcomes for discovering, prioritizing, containing, eradicating, and recovering from incidents, and for reporting, notification, and other communications.
- Continuous improvement
The Improvement Category (ID.IM) receives lessons learned from every Function as they are identified, not only after recovery ends.
- Roles and responsibilities
Guidance on the individuals, teams, leadership, and third parties that hold incident response duties inside and outside the organization.
- Policies, processes, and procedures
Considerations for the incident response policy, plan, and procedures that set authority, scope, and workflow.
- Community Profile tables and online resources
Two tables list recommendations and considerations per Subcategory, and the CPRT links each to implementation guidance and mappings to other standards.
Framework Scope
NIST SP 800-61 Rev. 3 applies to any organization that must prepare for and handle cybersecurity incidents, from federal agencies, for which NIST guidance carries FISMA weight, to private companies, critical infrastructure operators, and small businesses. It covers incident response governance, preparation, detection, response, recovery, communication, and improvement, and it deliberately leaves detailed technical procedures and playbooks to the online resources it references.
Framework Objectives
The publication aims to help organizations prepare for incidents, reduce how many occur and how much harm they cause, and improve the efficiency and effectiveness of detection, response, and recovery.
Integrate incident response into cybersecurity risk management across the organization rather than isolating it in one team.
Organize incident response recommendations and considerations as a CSF 2.0 Community Profile with a shared taxonomy.
Provide a life cycle model that reflects long, complex modern incidents and the need for continuous improvement.
Clarify the roles and responsibilities of internal teams, leadership, and third parties in incident response.
Support incident reporting, notification, and communication obligations to regulators, partners, and the public.
Connect organizations to current online implementation resources and cross-standard mappings through the CPRT.
Framework in Context
NIST SP 800-61 Rev. 3 is the incident response companion to NIST CSF 2.0 and draws its structure from it. It supports the Incident Response (IR) control family in NIST SP 800-53 Rev. 5 and the authorization and monitoring steps of the Risk Management Framework in NIST SP 800-37 Rev. 2, and it uses the risk vocabulary of NIST SP 800-30 Rev. 1. Internationally it sits alongside ISO/IEC 27035 and the incident management controls 5.24 to 5.28 of ISO/IEC 27002:2022, while CIS Control 17 and the SOC 2 CC7 criteria are commonly mapped to it.
Common Framework Mappings
NIST SP 800-61 Rev. 3 is commonly mapped to other control frameworks and standards so that one incident response program can evidence several obligations at once, and the NIST CPRT publishes reference mappings for the Profile.
Mapped frameworks include:
NIST CSF 2.0
NIST 800-53 Rev.5
NIST 800-37 Rev.2
NIST SP 800-30 Rev. 1
ISO 27001:2022
ISO 27002:2022
ISO/IEC 27035
CIS Controls v8.1
SOC 2 (AICPA TSC 2017)
NIST CSF v1.1
- ClassificationCategoryCybersecurityDomainCybersecurityFramework FamilyNIST Special Publications
- Regulatory ContextTypeGuidanceLegal InstrumentGuidanceSectorCross-SectorIndustryCross-Industry
- Region / PublisherRegionNorth AmericaRegion DetailUnited StatesPublisherNational Institute of Standards and Technology (NIST)
- VersioningVersionRevision 3Effective DateApril 2025Issue DateApril 2025 (supersedes Revision 2 of August 2012)
- AdoptionAdoption ModelVoluntaryImplementation ComplexityMedium
- Official ReferenceOpen Link in New TabSource
License included / downloadable: Yes
NIST SP 800-61 Rev. 3 is a U.S. government publication available free of charge from NIST, and its CSF 2.0 Community Profile structure is included with the platform.
Framework text is licensed by its publisher and is included only where stated above.
How SmartSuite Supports NIST SP 800-61 Rev. 3
SmartSuite provides the system for managing controls, evidence, mappings, assessments, and reporting.
For NIST SP 800-61 Rev. 3, SmartSuite holds the CSF 2.0 Community Profile as a control library, links each Subcategory to the plan sections, playbooks, and detection sources that satisfy it, and records incidents, exercises, and lessons learned with their evidence in one place.
Incident Response Profile Library
Hold every Function, Category, and Subcategory of the Community Profile as a structured record with its recommendations and the organization's implementation status.
Ownership, Cadence, and Accountability
Assign owners for preparation and response outcomes, set review dates for plans and playbooks, and track exercise schedules.
Evidence Collection and Audit Trail
Capture incident tickets, timelines, decisions, notifications, and post-incident reports with timestamps and reviewers linked to the Subcategories they evidence.
Exercises and Post-Incident Reviews
Plan tabletop exercises and reviews, record findings, and route lessons learned to the Improvement Category as tracked actions.
Risk and Vendor Alignment
Connect incident scenarios, risk register entries, and third-party dependencies to the Profile outcomes they affect.
Leadership and Regulator Reporting
Generate status views of preparation and response outcomes, open incidents, and notification obligations for executives and auditors.
Related frameworks

NIST Cybersecurity Framework (CSF) v2.0 is a risk-based framework that helps organizations manage and reduce cybersecurity risks.

NIST SP 800-53 Rev. 5 provides a catalog of security and privacy controls to manage risks to information systems.

NIST RMF provides a structured process to select, implement, assess, authorize, and continuously monitor cybersecurity and privacy controls.

NIST SP 800-30 Rev. 1 is the NIST guide for conducting information security risk assessments: how to prepare, conduct, communicate, and maintain them at every tier of the organization.

NIST SP 800-39 guides organizations to identify, assess, and manage information security risk at all enterprise levels.

ISO/IEC 27001:2022 is an international ISMS standard that helps organizations manage information security risks and protect data.
Frequently Asked Questions For NIST SP 800-61 Rev. 3
NIST SP 800-61 Rev. 3 is NIST's April 2025 guide to incident response, titled Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. It explains how to build incident response into an organization's wider cybersecurity risk management and organizes its recommendations using the Functions, Categories, and Subcategories of NIST CSF 2.0.
Revision 2 (2012) described incident response as a separate cycle of preparation, detection and analysis, containment, eradication and recovery, and post-incident activity. Revision 3 replaces that model with one based on the six CSF 2.0 Functions, treats incident response as part of continuous cybersecurity risk management, and moves detailed technical guidance and playbooks to online resources that NIST keeps current through the Cybersecurity and Privacy Reference Tool.
A CSF 2.0 Community Profile is a set of CSF outcomes selected and annotated for a particular community or use case. In NIST SP 800-61 Rev. 3 the Profile lists, for each relevant Subcategory, the recommendations and considerations that support incident response, split into a preparation and lessons learned table and an incident response table.
It is voluntary guidance. U.S. federal agencies are expected to follow NIST guidelines when meeting their FISMA incident response obligations, and many regulators, insurers, and customers reference it, but there is no certification against it. Most organizations adopt it because it aligns with NIST CSF 2.0 and NIST SP 800-53 programs they already run.
Govern, Identify, and Protect are preparation activities that prevent some incidents, ready the organization for those that occur, and limit their impact. Detect, Respond, and Recover are the incident response activities themselves. The Improvement Category within Identify receives lessons learned from every Function as soon as they are identified, so improvement is continuous rather than a final phase.
NIST moved them online. Each Function, Category, and Subcategory in the Profile links through the NIST Cybersecurity and Privacy Reference Tool (CPRT) to implementation guidance, mappings to other incident response and risk management standards, and other resources that NIST can update without reissuing the publication.
It provides the how-to for the Incident Response (IR) control family in NIST SP 800-53 Rev. 5 and complements the risk management process in NIST SP 800-37 and NIST SP 800-30. Internationally, ISO/IEC 27035 and the incident management controls of ISO/IEC 27002:2022 cover the same ground, and the CPRT publishes mappings between them and the Profile.
Manage controls, risks, evidence, and audits in one platform designed for modern governance, risk, and compliance.
