Back to Frameworks

NIST SP 800-61 Rev. 3

United States (NIST, FISMA authority); voluntary for non-federal organizations
vRev. 3 (April 2025)
6 domains
72 controls

NIST's incident response guidance, rewritten in April 2025 as a CSF 2.0 Community Profile: every CSF 2.0 Function, Category and Subcategory given an incident-response priority, with recommendations, considerations and notes on the outcomes that matter for preparing for, detecting, responding to and recovering from cybersecurity incidents, and lessons learned fed back through the Improvement Category. Supersedes the 2012 Computer Security Incident Handling Guide (Rev. 2), withdrawn on 3 April 2025.

Verified

NIST SP 800-61 Rev. 3 is a compliance framework from United States (NIST, FISMA authority); voluntary for non-federal organizations with 6 domains and 72 controls that map to 132 other frameworks. The largest domains are Identify (ID): preparation and lessons learned – NIST SP 800-61 Rev. 3 (18 controls), Respond (RS): incident response – NIST SP 800-61 Rev. 3 (16 controls), Detect (DE): incident response – NIST SP 800-61 Rev. 3 (13 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

Detect (DE): incident response – NIST SP 800-61 Rev. 3

13 controls
Controls in the Detect (DE): incident response – NIST SP 800-61 Rev. 3 domain of NIST SP 800-61 Rev. 3 — 13 controls
CodeTitle
nist-sp-800-61-rev-3::DE.AEDE.AE Adverse event analysis filtered by technology and aimed at early detection
nist-sp-800-61-rev-3::DE.AE-02DE.AE-02 Log events analyzed with SIEM or SOAR tools, current CTI and manual review
nist-sp-800-61-rev-3::DE.AE-03DE.AE-03 Logs centralized and events correlated across sources
nist-sp-800-61-rev-3::DE.AE-04DE.AE-04 Impact and scope of adverse events estimated and refined
nist-sp-800-61-rev-3::DE.AE-06DE.AE-06 Alerts and findings delivered to the SOC and responders, with ticketing
nist-sp-800-61-rev-3::DE.AE-07DE.AE-07 CTI, context and vulnerability disclosures integrated into analysis
nist-sp-800-61-rev-3::DE.AE-08DE.AE-08 Incidents declared by applying incident criteria
nist-sp-800-61-rev-3::DE.CMDE.CM Continuous monitoring of all asset types at all times, tuned and informed by threat information
nist-sp-800-61-rev-3::DE.CM-01DE.CM-01 Networks and network services monitored, including rogue networks
nist-sp-800-61-rev-3::DE.CM-02DE.CM-02 Physical environment monitored for access attempts, movement and tampering
nist-sp-800-61-rev-3::DE.CM-03DE.CM-03 Personnel activity and technology usage monitored for anomalies
nist-sp-800-61-rev-3::DE.CM-06DE.CM-06 External service provider activity monitored, including remote administration
nist-sp-800-61-rev-3::DE.CM-09DE.CM-09 Computing environments monitored for malware, credential attacks, drift, tampering and endpoint health

Govern (GV): preparation – NIST SP 800-61 Rev. 3

13 controls
Controls in the Govern (GV): preparation – NIST SP 800-61 Rev. 3 domain of NIST SP 800-61 Rev. 3 — 13 controls
CodeTitle
nist-sp-800-61-rev-3::GV.OC-03GV.OC-03 Legal, regulatory and contractual requirements include incident response requirements
nist-sp-800-61-rev-3::GV.OC-04GV.OC-04 External dependencies on the organization inform response priorities
nist-sp-800-61-rev-3::GV.OC-05GV.OC-05 The organization's own dependencies on external resources inform response priorities
nist-sp-800-61-rev-3::GV.OV-01GV.OV-01 Past incidents inform adjustments to strategy and direction
nist-sp-800-61-rev-3::GV.OV-02GV.OV-02 Risks from past incidents considered when reviewing the strategy
nist-sp-800-61-rev-3::GV.POGV.PO Cybersecurity policies include an incident response policy
nist-sp-800-61-rev-3::GV.RM-03GV.RM-03 Incident decisions informed by enterprise risk, not cybersecurity risk alone
nist-sp-800-61-rev-3::GV.RM-06GV.RM-06 A standard risk method used to prioritize incidents and set escalation criteria
nist-sp-800-61-rev-3::GV.RRGV.RR Cybersecurity roles, responsibilities and authorities include incident response
nist-sp-800-61-rev-3::GV.RR-01GV.RR-01 Leadership accountable for cybersecurity risk, including incident response
nist-sp-800-61-rev-3::GV.RR-02GV.RR-02 Incident response roles documented in policy and given the authority they need
nist-sp-800-61-rev-3::GV.SC-05GV.SC-05 Supplier requirements include incident disclosure and information sharing
nist-sp-800-61-rev-3::GV.SC-08GV.SC-08 Relevant suppliers included in incident planning, response and recovery

Identify (ID): preparation and lessons learned – NIST SP 800-61 Rev. 3

18 controls
Controls in the Identify (ID): preparation and lessons learned – NIST SP 800-61 Rev. 3 domain of NIST SP 800-61 Rev. 3 — 18 controls
CodeTitle
nist-sp-800-61-rev-3::ID.AM-01ID.AM-01 Current, automatically updated hardware inventories available to responders
nist-sp-800-61-rev-3::ID.AM-02ID.AM-02 Current, automatically updated software, service and system inventories available to responders
nist-sp-800-61-rev-3::ID.AM-03ID.AM-03 Network data flow representations maintained to detect malicious flows
nist-sp-800-61-rev-3::ID.AM-04ID.AM-04 Current inventories of supplier-provided services available to responders
nist-sp-800-61-rev-3::ID.AM-05ID.AM-05 Asset priorities and dependencies direct protection, detection, response and recovery
nist-sp-800-61-rev-3::ID.AM-07ID.AM-07 Data inventories show what data an incident may have involved
nist-sp-800-61-rev-3::ID.AM-08ID.AM-08 Life cycle management accounts for cybersecurity and keeps inventories current
nist-sp-800-61-rev-3::ID.IM-01ID.IM-01 Incident response program periodically evaluated
nist-sp-800-61-rev-3::ID.IM-02ID.IM-02 Improvements identified from incident response tests and exercises
nist-sp-800-61-rev-3::ID.IM-03ID.IM-03 Lessons learned from incident response and recovery feed improvement
nist-sp-800-61-rev-3::ID.IM-04ID.IM-04 Incident response, vulnerability management and continuity plans maintained and synchronized
nist-sp-800-61-rev-3::ID.RA-01ID.RA-01 All types of known vulnerabilities understood for risk decisions
nist-sp-800-61-rev-3::ID.RA-02ID.RA-02 Cyber threat intelligence received and used for incident response
nist-sp-800-61-rev-3::ID.RA-03ID.RA-03 Internal and external threats identified in routine operations and from CTI
nist-sp-800-61-rev-3::ID.RA-04ID.RA-04 Impacts and likelihoods recorded to determine risk
nist-sp-800-61-rev-3::ID.RA-05ID.RA-05 Existing risk estimation mechanisms used for incident response
nist-sp-800-61-rev-3::ID.RA-06ID.RA-06 Criteria guide risk response decisions to prevent incidents and recurrence
nist-sp-800-61-rev-3::ID.RA-08ID.RA-08 Processes for receiving and acting on vulnerability disclosures

Protect (PR): preparation – NIST SP 800-61 Rev. 3

4 controls
Controls in the Protect (PR): preparation – NIST SP 800-61 Rev. 3 domain of NIST SP 800-61 Rev. 3 — 4 controls
CodeTitle
nist-sp-800-61-rev-3::PR.AT-02PR.AT-02 Role-based training includes incident-related responsibilities
nist-sp-800-61-rev-3::PR.DS-11PR.DS-11 Backups created, protected, maintained and tested for recovery
nist-sp-800-61-rev-3::PR.PS-04PR.PS-04 Log records generated and kept for detection, response and recovery
nist-sp-800-61-rev-3::PR.PS-06PR.PS-06 Secure development practices cover responding to vulnerabilities and incidents in released software

Recover (RC): incident response – NIST SP 800-61 Rev. 3

8 controls
Controls in the Recover (RC): incident response – NIST SP 800-61 Rev. 3 domain of NIST SP 800-61 Rev. 3 — 8 controls
CodeTitle
nist-sp-800-61-rev-3::RC.CO-03RC.CO-03 Recovery progress shared securely with leadership and suppliers under agreed protocols
nist-sp-800-61-rev-3::RC.CO-04RC.CO-04 Public recovery updates follow breach procedures and explain prevention steps
nist-sp-800-61-rev-3::RC.RP-01RC.RP-01 Recovery portion of the plan started and recovery staff briefed on plans and authorizations
nist-sp-800-61-rev-3::RC.RP-02RC.RP-02 Recovery actions selected by plan criteria and adjusted to reassessed needs
nist-sp-800-61-rev-3::RC.RP-03RC.RP-03 Backups and restoration assets checked for compromise and corruption before use
nist-sp-800-61-rev-3::RC.RP-04RC.RP-04 Essential services restored in order and restored systems confirmed with owners and monitored
nist-sp-800-61-rev-3::RC.RP-05RC.RP-05 Restored assets checked and root causes remediated before production
nist-sp-800-61-rev-3::RC.RP-06RC.RP-06 End of recovery declared and after-action report prepared

Respond (RS): incident response – NIST SP 800-61 Rev. 3

16 controls
Controls in the Respond (RS): incident response – NIST SP 800-61 Rev. 3 domain of NIST SP 800-61 Rev. 3 — 16 controls
CodeTitle
nist-sp-800-61-rev-3::RS.AN-03RS.AN-03 Sequence of events, actors and root causes of the incident established
nist-sp-800-61-rev-3::RS.AN-06RS.AN-06 Investigation actions recorded with confidentiality and integrity preserved
nist-sp-800-61-rev-3::RS.AN-07RS.AN-07 Incident data collected and retained as evidence under preservation procedures
nist-sp-800-61-rev-3::RS.AN-08RS.AN-08 Incident magnitude estimated by searching known and potential targets
nist-sp-800-61-rev-3::RS.CORS.CO Mechanisms in place in advance to coordinate with affected parties
nist-sp-800-61-rev-3::RS.CO-02RS.CO-02 Stakeholders, affected parties, regulators and law enforcement notified as required
nist-sp-800-61-rev-3::RS.CO-03RS.CO-03 Incident information shared securely with leadership, HR, media and sharing partners
nist-sp-800-61-rev-3::RS.MARS.MA Incident management by risk factors, not first come, with status tracked
nist-sp-800-61-rev-3::RS.MA-01RS.MA-01 Incident response plan executed with third parties once an incident is declared
nist-sp-800-61-rev-3::RS.MA-02RS.MA-02 Incident reports triaged and validated, including third-party reports
nist-sp-800-61-rev-3::RS.MA-03RS.MA-03 Incidents categorized by type, prioritized and given a response strategy
nist-sp-800-61-rev-3::RS.MA-04RS.MA-04 Incidents escalated or elevated through tracked status
nist-sp-800-61-rev-3::RS.MA-05RS.MA-05 Recovery initiation criteria applied, weighing operational disruption
nist-sp-800-61-rev-3::RS.MIRS.MI Containment and eradication criteria set, legal consulted before observing an attacker
nist-sp-800-61-rev-3::RS.MI-01RS.MI-01 Incidents contained, automatically where configured and manually by handlers
nist-sp-800-61-rev-3::RS.MI-02RS.MI-02 Incidents eradicated across all affected hosts and services

Your Compliance Coverage

If you comply with NIST SP 800-61 Rev. 3, you already cover:

+ 129 more: ISO 19650 - Organisation and Digitisation of Information about Buildings and Civil Engineering Works (BIM) (6%), ISO/IEC 27043:2015 (6%)

See all 132 mapped frameworks ↓

Maps to 132 other frameworks

80 total controls
NIST Cybersecurity Framework 2.0
67 source controls mapped|68 target controls covered
84%
OWASP MASVS
5 source controls mapped|7 target controls covered
6%
OWASP ASVS
5 source controls mapped|8 target controls covered
6%
ISO/IEC 27043:2015
5 source controls mapped|18 target controls covered
6%
ISO/SAE 21434
5 source controls mapped|17 target controls covered
6%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
5 source controls mapped|12 target controls covered
6%
OWASP Top 10:2025
4 source controls mapped|6 target controls covered
5%
NIST SP 800-190
4 source controls mapped|10 target controls covered
5%
South Korea ISMS-P
4 source controls mapped|9 target controls covered
5%
ISO/IEC 27010:2015
4 source controls mapped|7 target controls covered
5%
IEC 62351 - Power Systems Communication Security
4 source controls mapped|4 target controls covered
5%
Singapore Government Instruction Manual on ICT&SS Management (IM8)
4 source controls mapped|7 target controls covered
5%
ISO/IEC 27011:2024
4 source controls mapped|10 target controls covered
5%
FTC GLBA Safeguards Rule (16 CFR Part 314)
4 source controls mapped|3 target controls covered
5%
FFIEC IT Examination Handbook
4 source controls mapped|4 target controls covered
5%
UK Defence Standard 05-138 - Cyber Security for Defence Suppliers
4 source controls mapped|2 target controls covered
5%
Protective Security Policy Framework (PSPF) Release 2026
3 source controls mapped|3 target controls covered
4%
OWASP DevSecOps Maturity Model (DSOMM)
3 source controls mapped|4 target controls covered
4%
ASD Strategies to Mitigate Cyber Security Incidents
3 source controls mapped|12 target controls covered
4%
BSI IT-Grundschutz
3 source controls mapped|11 target controls covered
4%
ISO/IEC 29115:2013 - Entity Authentication Assurance Framework
3 source controls mapped|5 target controls covered
4%
ISO/IEC 23837:2023
3 source controls mapped|5 target controls covered
4%
ISO 27799:2025
3 source controls mapped|7 target controls covered
4%
ISO/IEC 27400:2022
3 source controls mapped|3 target controls covered
4%
Annex 11 to EU GMP - Computerised Systems
3 source controls mapped|5 target controls covered
4%
ISO 28001:2007 Supply Chain Security Management
3 source controls mapped|2 target controls covered
4%
Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023)
3 source controls mapped|3 target controls covered
4%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|5 target controls covered
4%
New Zealand Information Security Manual (NZISM)
3 source controls mapped|2 target controls covered
4%
OWASP API Security Top 10 - 2023
2 source controls mapped|4 target controls covered
3%
USMCA Chapter 19 - Digital Trade (United States-Mexico-Canada Agreement)
2 source controls mapped|2 target controls covered
3%
US EPA Safe Drinking Water Act (SDWA) - Cybersecurity Requirements
2 source controls mapped|1 target controls covered
3%
Turkey KVKK
2 source controls mapped|1 target controls covered
3%
TEFCA - Trusted Exchange Framework and Common Agreement
2 source controls mapped|1 target controls covered
3%
SWIFT CSCF
2 source controls mapped|2 target controls covered
3%
Regulation on the European Health Data Space (EHDS)
2 source controls mapped|2 target controls covered
3%
Privacy Act 1988 (Australia)
2 source controls mapped|1 target controls covered
3%
3%
FFIEC Cybersecurity Assessment Tool (CAT)
2 source controls mapped|5 target controls covered
3%
NIST Privacy Framework
2 source controls mapped|3 target controls covered
3%
Illinois Biometric Information Privacy Act (BIPA)
2 source controls mapped|2 target controls covered
3%
FIDO2 / WebAuthn
2 source controls mapped|1 target controls covered
3%
Florida Digital Bill of Rights (FDBR)
2 source controls mapped|3 target controls covered
3%
NIST SP 1800-32
2 source controls mapped|9 target controls covered
3%
DAMA-DMBOK2 - Data Management Body of Knowledge (2nd Edition)
2 source controls mapped|5 target controls covered
3%
API 1164
2 source controls mapped|9 target controls covered
3%
ISO/IEC 27019:2024
2 source controls mapped|9 target controls covered
3%
Bahrain PDPL
2 source controls mapped|2 target controls covered
3%
IEC 62443
2 source controls mapped|9 target controls covered
3%
APPI
2 source controls mapped|2 target controls covered
3%
US Consumer Product Safety Commission (CPSC) - Connected Product Safety
2 source controls mapped|2 target controls covered
3%
IATA Operational Safety Audit (IOSA) Standards Manual
2 source controls mapped|2 target controls covered
3%
New Jersey Data Privacy Act
2 source controls mapped|2 target controls covered
3%
South Korea PIPA
2 source controls mapped|2 target controls covered
3%
ISO/IEC 27031:2011
2 source controls mapped|4 target controls covered
3%
ASIS SPC.1-2009 - Organizational Resilience Standard
2 source controls mapped|2 target controls covered
3%
ISO 22320:2018
2 source controls mapped|4 target controls covered
3%
FBI CJIS Security Policy
2 source controls mapped|3 target controls covered
3%
Kuwait National Cybersecurity Framework
2 source controls mapped|2 target controls covered
3%
ISO/IEC 30111:2019
2 source controls mapped|4 target controls covered
3%
ISO/IEC 29134:2023
2 source controls mapped|2 target controls covered
3%
ISO/IEC 29147:2018
2 source controls mapped|4 target controls covered
3%
IEC 60601-1 - Medical Electrical Equipment Safety
2 source controls mapped|3 target controls covered
3%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
2 source controls mapped|2 target controls covered
3%
ISO/IEC 25012:2008 - Data Quality Model
2 source controls mapped|3 target controls covered
3%
Vermont Artificial Intelligence and Consumer Data Act (AICDA)
1 source controls mapped|1 target controls covered
1%
US Gramm-Leach-Bliley Act (GLBA) - Higher Education Safeguards Rule
1 source controls mapped|1 target controls covered
1%
UN Guiding Principles on Business and Human Rights (UNGPs)
1 source controls mapped|1 target controls covered
1%
Russia Federal Law on Personal Data (152-FZ)
1 source controls mapped|1 target controls covered
1%
OWASP Top 10 for LLM Applications 2025
1 source controls mapped|4 target controls covered
1%
US Automated Commercial Environment (ACE) - CBP Trade Data Requirements
1 source controls mapped|1 target controls covered
1%
Armenia Law on Protection of Personal Data (2015)
1 source controls mapped|1 target controls covered
1%
AML/CTF Act 2006 (Australia)
1 source controls mapped|1 target controls covered
1%
Bank Secrecy Act / Anti-Money Laundering (BSA/AML)
1 source controls mapped|1 target controls covered
1%
ITU-T X.805 - Security Architecture for End-to-End Communications
1 source controls mapped|2 target controls covered
1%
ISO/IEC 20000-1:2018
1 source controls mapped|1 target controls covered
1%
ITIL 4
1 source controls mapped|1 target controls covered
1%
Canada ITSG-33 - IT Security Risk Management
1 source controls mapped|1 target controls covered
1%
ICAO Annex 17 - Aviation Security (AVSEC)
1 source controls mapped|1 target controls covered
1%
ISO 22316
1 source controls mapped|2 target controls covered
1%
ISO/TS 22317:2021
1 source controls mapped|2 target controls covered
1%
NFPA 1600 - Standard on Continuity, Emergency, and Crisis Management
1 source controls mapped|2 target controls covered
1%
ISO/TS 22318:2021
1 source controls mapped|2 target controls covered
1%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|3 target controls covered
1%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
1%
W3C Verifiable Credentials (VC) Data Model 2.0
1 source controls mapped|1 target controls covered
1%
Vietnam Law on Cybersecurity (No. 24/2018/QH14)
1 source controls mapped|1 target controls covered
1%
PCAOB AS 2201 - Audit of Internal Control Over Financial Reporting (ICFR)
1 source controls mapped|2 target controls covered
1%
Pakistan Personal Data Protection Bill 2023
1 source controls mapped|2 target controls covered
1%
OCC Heightened Standards (12 CFR Part 30, Appendix D)
1 source controls mapped|1 target controls covered
1%
Notifiable Data Breaches Scheme (Australia)
1 source controls mapped|1 target controls covered
1%
1%
ISO/IEC 29100:2024
1 source controls mapped|3 target controls covered
1%
ISO 56002
1 source controls mapped|2 target controls covered
1%
Science Based Targets Initiative (SBTi) - Net-Zero Standard
1 source controls mapped|2 target controls covered
1%
ISO/IEC 17025:2017 - General Requirements for Testing and Calibration
1 source controls mapped|2 target controls covered
1%
IEC 62304:2015 Medical Device Software Lifecycle Processes
1 source controls mapped|3 target controls covered
1%
ISO 20400:2017 - Sustainable Procurement
1 source controls mapped|2 target controls covered
1%
Automotive SPICE (ASPICE) v4.1 - Process Assessment Model
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
1 source controls mapped|3 target controls covered
1%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
1%
COBIT 2019
1 source controls mapped|1 target controls covered
1%
Nebraska Data Privacy Act
1 source controls mapped|2 target controls covered
1%
Connecticut Data Privacy Act (CTDPA)
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27004:2016
1 source controls mapped|3 target controls covered
1%
ISO 41001:2018 - Facility Management Systems
1 source controls mapped|2 target controls covered
1%
ISO/IEC 23894:2023
1 source controls mapped|3 target controls covered
1%
Austria Data Protection Act (Datenschutzgesetz, DSG, amended 2018)
1 source controls mapped|2 target controls covered
1%
ISO/IEC 27014:2020
1 source controls mapped|2 target controls covered
1%
ISO 8000 - Data Quality
1 source controls mapped|2 target controls covered
1%
FedRAMP High
1 source controls mapped|1 target controls covered
1%
FedRAMP Moderate
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27007:2020
1 source controls mapped|1 target controls covered
1%
US Foreign Corrupt Practices Act (FCPA)
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27003:2017
1 source controls mapped|1 target controls covered
1%
Barbados Data Protection Act 2019
1 source controls mapped|1 target controls covered
1%
DFARS 252.204-7012 - Safeguarding Covered Defense Information
1 source controls mapped|1 target controls covered
1%
ISO 26262:2018 - Functional Safety for Road Vehicles
1 source controls mapped|1 target controls covered
1%
ICH Q10 - Pharmaceutical Quality System
1 source controls mapped|2 target controls covered
1%
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
1%
Azerbaijan Law on Personal Data (2010)
1 source controls mapped|1 target controls covered
1%
ISO/IEC 27050-1:2019
1 source controls mapped|1 target controls covered
1%
PCI DSS 4.0
1 source controls mapped|1 target controls covered
1%
Nigeria Open Banking Regulatory Framework (CBN, 2023)
1 source controls mapped|1 target controls covered
1%

Coverage is not the same as your position

This page shows what NIST SP 800-61 Rev. 3 overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is NIST SP 800-61 Rev. 3 and who does it apply to?

NIST SP 800-61 Rev. 3 is a compliance framework from United States (NIST, FISMA authority); voluntary for non-federal organizations with 6 domains and 72 controls. NIST's incident response guidance, rewritten in April 2025 as a CSF 2.0 Community Profile: every CSF 2.0 Function, Category and Subcategory given an incident-response priority, with recommendations, considerations and notes on the outcomes that matter for preparing for, detecting, responding to and recovering from cybersecurity incidents, and lessons learned fed back through the Improvement Category. Supersedes the 2012 Computer Security Incident Handling Guide (Rev. 2), withdrawn on 3 April 2025. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does NIST SP 800-61 Rev. 3 actually require?

NIST SP 800-61 Rev. 3 has 72 controls organised across 6 domains. The largest domains are Identify (ID): preparation and lessons learned – NIST SP 800-61 Rev. 3 (18 controls), Respond (RS): incident response – NIST SP 800-61 Rev. 3 (16 controls), Detect (DE): incident response – NIST SP 800-61 Rev. 3 (13 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of NIST SP 800-61 Rev. 3 do I already cover?

NIST SP 800-61 Rev. 3 maps to 132 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (84% coverage), OWASP MASVS (6% coverage), OWASP ASVS (6% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement NIST SP 800-61 Rev. 3?

Start your NIST SP 800-61 Rev. 3 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-61 Rev. 3 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 72 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 704 frameworks.

Get Started Free →

Free forever — no credit card required