Framework Defense, Supply Chain & NIST Catalogue
NIST SP 800-61
NIST Special Publication 800-61 is the US federal guide to handling cybersecurity incidents. Revision 2 (2012), the "Computer Security Incident Handling Guide", gave the field its four-phase lifecycle (preparation; detection and analysis; containment, eradication, and recovery; post-incident activity) and is still the version most policies cite.
Revision 3, published April 2025 under the title "Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile", restructured the guidance around the Cybersecurity Framework 2.0 so that incident response is treated as part of ongoing risk management rather than a standalone process, with the Govern, Identify, and Protect functions covering preparation and Detect, Respond, and Recover covering the active phases.
It supersedes Revision 2. In writing, the guide expects an incident response policy, a plan with roles, escalation paths, and communication procedures, playbooks or procedures for common incident types, logging and detection capabilities that support analysis, reporting procedures that meet legal and contractual deadlines, and post-incident review records that feed improvements back into the program.
help
Who has to comply
Written for US federal agencies under FISMA; voluntary elsewhere but extremely widely adopted. The IR control family in NIST SP 800-53, the incident response requirements in NIST SP 800-171 and CMMC, and many state and sector rules point to it.
What the assessor asks to see
Incident response policy and plan; team roster and roles; escalation and communication procedures including regulatory and contractual reporting timelines; playbooks by incident type; logging and detection coverage; incident tickets and case records with timelines; evidence handling and forensics procedures; post-incident review reports and tracked improvements; exercise records.
Assessors
Who assesses NIST SP 800-61
None for the document itself; incident response capabilities built on it are examined within parent programs (FedRAMP 3PAOs, C3PAOs, agency assessors, ISO certification bodies).
No firm has claimed a NIST SP 800-61 assessor listing yet. Claim yours →
Consultants
Who helps with NIST SP 800-61
Incident response consultancies, managed detection and response providers, and retainer-based forensic firms build plans and playbooks and run tabletop exercises based on it. Plan development typically takes a few weeks; exercises are annual or more frequent.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a NIST SP 800-61 consultant listing yet. Claim yours →
Software
Tools for NIST SP 800-61
Tools that name this framework in their own material.
Need a hand implementing it?
Find a Consultant for NIST SP 800-61
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with NIST SP 800-61
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.