
What the document says
NIST published Special Publication 800-61 Revision 3 in April 2025 under the title Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. The publication's own abstract says its purpose is to help organisations incorporate incident response recommendations throughout their cybersecurity risk management activities as described by the Cybersecurity Framework, whose six-function structure of Govern, Identify, Protect, Detect, Respond and Recover NIST published in February 2024. Revision 3 formally supersedes Revision 2, the 2012 Computer Security Incident Handling Guide, which NIST withdrew on 3 April 2025. Where Revision 2 was a standalone guide to detecting, analysing and handling incidents, Revision 3 is framed as a community profile: a set of recommendations mapped onto the Framework's functions, so that incident response sits inside an organisation's ongoing risk management rather than as a separate, emergency-only process.
Confidence and limits
Both revisions are official NIST publications retrieved directly from the agency's own repository, which is strong evidence for their scope, titles and supersession dates. The record is thinner on operational detail: the landing pages for both revisions describe purpose and structure rather than reproducing the internal lifecycle steps, so this account describes what the documents state about themselves rather than a line-by-line comparison of Revision 2 and Revision 3's full text.
Why it mattered
A thirteen-year gap between revisions meant many incident response plans were still written against a document that predated widespread cloud services, ransomware-as-a-service and routine third-party compromise. Rewriting the guidance around the Framework's functions mattered because it asked organisations to treat preparation, governance and recovery as continuous risk-management work, rather than a plan that only activates once an incident is declared. That reframing affects how a response plan is written, reviewed and funded, not only how it is executed during an incident.
Defensive takeaway
If your incident response plan cites Revision 2 by name, or was last revised before April 2025, treat that as a prompt to check it against the current guidance rather than an assumption that it still reflects best practice.
- Does our incident response plan reference NIST SP 800-61, and if so, which revision?
- Are our preparation and governance activities documented separately from our incident playbooks, or connected as this profile recommends?
- When was our plan last reviewed against current guidance, rather than carried forward unchanged?
A superseded standard does not stop working the day a new one is published, but it stops being the reference a regulator, insurer or auditor expects to see cited. Confirming which revision a plan follows is a low-cost check with a clear answer.
Check whether your incident response plan still cites Revision 2, and confirm it reflects the risk-management framing Revision 3 introduced.
NIST's own publication pages establish the titles, scope and supersession dates for both revisions. They do not, on the pages opened here, spell out every internal lifecycle change, so this account does not claim a complete section-by-section comparison.
Sources & reading trail
Establishes the April 2025 publication, title and CSF 2.0 community-profile framing that supersedes Revision 2.
government-primary · Source published: 1 April 2025 · Retrieved: 16 September 2026
Documents the August 2012 scope of the superseded guide and confirms its withdrawal on 3 April 2025.
government-primary · Source published: 6 August 2012 · Retrieved: 16 September 2026
Confirms the February 2024 publication of CSF 2.0, the framework Revision 3 is built around.
government-primary · Source published: 1 February 2024 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.