NIST SP 800-61
NIST SP 800-61 is a guidance document from the National Institute of Standards and Technology (NIST) that helps organizations prepare for and respond to cybersecurity incidents. It offers recommendations for handling incidents, analyzing incident-related data, and deciding on appropriate responses. As a NIST guidance publication rather than a mandatory control set, it is generally advisory, though it may be referenced or incorporated by other requirements.
NIST SP 800-61 is a NIST Special Publication providing recommendations and considerations for cybersecurity incident response. Revision 2 (2012), titled the Computer Security Incident Handling Guide, presented an incident response life cycle model and guidance on analyzing incident-related data and determining appropriate response actions. Revision 3 (2025), titled Incident Response Recommendations and Considerations, reframes the guidance to align with the NIST Cybersecurity Framework (CSF) 2.0, and per the publication maps the prior life cycle model's phases to corresponding CSF 2.0 Functions. Practitioners should confirm which revision applies to their context, as the framing and structure differ between Rev. 2 and Rev. 3; the publication is guidance and is distinct from binding control baselines such as those in NIST SP 800-53 or SP 800-171. Readers should verify the current authoritative text at csrc.nist.gov.
Why it matters
Incident response is a foundational element of any cybersecurity program, and NIST SP 800-61 has long served as a widely referenced source of practical guidance on how organizations prepare for, detect, analyze, and respond to cybersecurity incidents. Because incidents are a matter of when rather than if, having a structured, repeatable approach to handling them helps organizations limit damage, preserve evidence, and recover in a coordinated way rather than improvising under pressure. For compliance-focused readers, the publication provides a common vocabulary and conceptual model that other requirements and frameworks can reference or build upon.
It is important to understand that NIST SP 800-61 is guidance rather than a binding control set. It is distinct from control baselines such as those in NIST SP 800-53 or SP 800-171, which may impose enforceable incident response requirements depending on the applicable regulatory or contractual context. In practice, an organization may be obligated to satisfy specific control requirements while turning to SP 800-61 for recommendations on how to design and operate the underlying incident response capability. Readers should not assume that following SP 800-61 alone demonstrates compliance with any given mandate.
The publication has evolved across revisions, and the framing differs significantly between versions. Revision 2 (2012) presented a life cycle model for incident handling, while Revision 3 (2025) reframes the guidance to align with the NIST Cybersecurity Framework (CSF) 2.0 and, per the publication, maps the earlier life cycle phases to corresponding CSF 2.0 Functions. Practitioners should confirm which revision applies to their context, because the structure and terminology are not identical between them, and should verify the current authoritative text at csrc.nist.gov.
Who it's relevant to
Inside SP 800-61
Common questions
Answers to the questions practitioners most commonly ask about SP 800-61.