RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Defense

Defense / From the archive · April 2025 event · prepared 16 September 2026

NIST rewrote incident response guidance around the Cybersecurity Framework

SP 800-61 Revision 3 replaces a 2012 standalone guide with recommendations mapped to the Framework's six functions.

Visual for this record: NIST rewrote incident response guidance around the Cybersecurity Framework
Visual published by nist.gov, shown for identification of the record. Credit: nist.gov · source page ↗ Rights: owner-review-pending.

What the document says

NIST published Special Publication 800-61 Revision 3 in April 2025 under the title Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile. The publication's own abstract says its purpose is to help organisations incorporate incident response recommendations throughout their cybersecurity risk management activities as described by the Cybersecurity Framework, whose six-function structure of Govern, Identify, Protect, Detect, Respond and Recover NIST published in February 2024. Revision 3 formally supersedes Revision 2, the 2012 Computer Security Incident Handling Guide, which NIST withdrew on 3 April 2025. Where Revision 2 was a standalone guide to detecting, analysing and handling incidents, Revision 3 is framed as a community profile: a set of recommendations mapped onto the Framework's functions, so that incident response sits inside an organisation's ongoing risk management rather than as a separate, emergency-only process.

Confidence and limits

Both revisions are official NIST publications retrieved directly from the agency's own repository, which is strong evidence for their scope, titles and supersession dates. The record is thinner on operational detail: the landing pages for both revisions describe purpose and structure rather than reproducing the internal lifecycle steps, so this account describes what the documents state about themselves rather than a line-by-line comparison of Revision 2 and Revision 3's full text.

Why it mattered

A thirteen-year gap between revisions meant many incident response plans were still written against a document that predated widespread cloud services, ransomware-as-a-service and routine third-party compromise. Rewriting the guidance around the Framework's functions mattered because it asked organisations to treat preparation, governance and recovery as continuous risk-management work, rather than a plan that only activates once an incident is declared. That reframing affects how a response plan is written, reviewed and funded, not only how it is executed during an incident.

Defensive takeaway

If your incident response plan cites Revision 2 by name, or was last revised before April 2025, treat that as a prompt to check it against the current guidance rather than an assumption that it still reflects best practice.

  • Does our incident response plan reference NIST SP 800-61, and if so, which revision?
  • Are our preparation and governance activities documented separately from our incident playbooks, or connected as this profile recommends?
  • When was our plan last reviewed against current guidance, rather than carried forward unchanged?

A superseded standard does not stop working the day a new one is published, but it stops being the reference a regulator, insurer or auditor expects to see cited. Confirming which revision a plan follows is a low-cost check with a clear answer.

Defensive takeaway

Check whether your incident response plan still cites Revision 2, and confirm it reflects the risk-management framing Revision 3 introduced.

NIST's own publication pages establish the titles, scope and supersession dates for both revisions. They do not, on the pages opened here, spell out every internal lifecycle change, so this account does not claim a complete section-by-section comparison.

Sources & reading trail

Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile (NIST SP 800-61r3) ↗

Establishes the April 2025 publication, title and CSF 2.0 community-profile framing that supersedes Revision 2.

government-primary · Source published: 1 April 2025 · Retrieved: 16 September 2026

Computer Security Incident Handling Guide (NIST SP 800-61 Rev. 2) ↗

Documents the August 2012 scope of the superseded guide and confirms its withdrawal on 3 April 2025.

government-primary · Source published: 6 August 2012 · Retrieved: 16 September 2026

NIST Cybersecurity Framework ↗

Confirms the February 2024 publication of CSF 2.0, the framework Revision 3 is built around.

government-primary · Source published: 1 February 2024 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.