Standards

NIST SP 800-82 Rev. 4 Draft: What Is New in the Guide to OT Security

September 28, 20269 min readBy Beacon Security Team

On 21 September 2026, the National Institute of Standards and Technology (NIST) released the initial public draft of Special Publication (SP) 800-82 Revision 4, Guide to Operational Technology (OT) Security. It is the most significant restructuring of the guide since it was first published.

This article explains the draft in four parts: the key facts, what has changed, how the industry has responded, and what the draft means for organisations that operate industrial facilities.

NIST SP 800-82 Rev. 4 initial public draft: key dates and the headline changes

Key Facts About the Draft

Revision 4 is a draft, and its content may change before the final release. Until NIST publishes the final version, SP 800-82 Revision 3 remains the current official guide.

ItemDetail
DocumentNIST SP 800-82 Rev. 4, Guide to Operational Technology (OT) Security
StatusInitial public draft
Published21 September 2026
Comments due30 November 2026
AuthorsNIST, with co-authors from MITRE
Official pageNIST SP 800-82 Rev. 4 (Initial Public Draft)
DownloadNIST.SP.800-82r4.ipd.pdf (more than 300 pages)
How to commentUse the comment template (Excel) and email it to sp800-82rev4@nist.gov
Current final versionNIST SP 800-82 Rev. 3

What Is NIST SP 800-82?

NIST SP 800-82 provides guidelines for securing OT while respecting the performance, reliability and safety requirements that distinguish industrial systems from office IT. It covers supervisory control and data acquisition (SCADA) systems, distributed control systems (DCS), programmable logic controllers (PLCs), safety systems, building automation and transportation systems.

The guide is written for United States federal agencies, but asset owners, integrators and vendors around the world use it voluntarily. It complements the ISA/IEC 62443 series: IEC 62443 defines requirements that can be assessed and certified, while SP 800-82 provides broad practical guidance. Revision 3 is explained in our practical guide to NIST SP 800-82, and IEC 62443 in our article on IEC 62443.

The history of NIST SP 800-82, from the original guide to the Revision 4 draft

The original guide was published in June 2011, followed by revisions in May 2013, May 2015 and September 2023. NIST opened the Revision 4 process with a pre-draft call for comments in January 2026, with the aim of aligning the guide with the Cybersecurity Framework (CSF) 2.0 and reflecting changes in the OT threat landscape.

Revision 3 and Revision 4 at a Glance

AreaRevision 3 (current)Revision 4 (draft)
StructureCSF applied in one section near the endWhole guide organised around CSF 2.0
GovernancePart of risk management and programme sectionsDedicated section built on the CSF 2.0 Govern function
SectorsGeneral OT overviewNew profiles for buildings, water, food and agriculture, rail and maritime
ArchitectureSegmentation, DMZs and defence-in-depthAdds separate management networks and system management functions
Zero trustIntroduced as a conceptPractical, phased approach starting at the upper Purdue levels
ResilienceBackup and recovery guidanceAdds analogue backups and out-of-band management
CryptographyGeneral encryption guidanceAdds post-quantum cryptography planning
AppendicesIncluded in the documentAppendices C to F to move online in the final version

How the main sections of SP 800-82 Revision 3 map to the new Revision 4 structure

What Is New in Revision 4

1. A Structure Built on CSF 2.0

CSF 2.0 now organises the entire guide. Section 3 applies the Govern function, Section 4 applies Identify, Protect, Detect, Respond and Recover, and Section 5 covers architecture. Because CSF 2.0 places Govern at the centre of the framework, an organisation can describe its OT programme in the same language that it uses for enterprise cybersecurity.

The six CSF 2.0 functions and where each appears in SP 800-82 Revision 4

Practical implication: Organisations that already report against CSF 2.0 can extend that reporting to their plants without maintaining a separate framework for OT.

2. Governance and Enterprise Risk Management

The draft treats OT risk as part of enterprise risk management, aligned with NIST Interagency Report (IR) 8286 Revision 1. The Govern section covers four areas:

  • Shared governance: Leadership, OT, IT, safety, legal and operations share governance, and ultimate accountability for OT cybersecurity resides with executive leadership.
  • Risk management strategy: Organisations maintain an OT risk register and document each risk response (mitigate, transfer, accept or avoid).
  • Supply chain risk: Suppliers are vetted and managed across the product life cycle, including software and hardware bills of materials (SBOMs and HBOMs) and signed firmware. See our article on OT supply chain security.
  • Policy and oversight: Programme performance is measured and reviewed by leadership.

The draft also states that OT security objectives typically prioritise safety, followed by integrity, availability and confidentiality.

Practical implication: OT cybersecurity becomes an enterprise responsibility with executive accountability, rather than a matter delegated to a single plant.

3. A Consequence-Driven Defence Mindset

A new section defines defence-in-depth as independent barriers across people, processes, technology and the physical system, so that no single failure leads to an unacceptable consequence. Cyber controls should be evaluated alongside engineering safeguards. For a tank that could be over-pressurised through the control system, relief valves, hardwired interlocks and safety instrumented functions reduce the risk alongside monitoring. The draft refers to Cyber-Informed Engineering, associated with Idaho National Laboratory, for this approach.

Practical implication: The most reliable protection against a severe physical consequence is often an engineering safeguard that operates independently of the digital control system.

4. Expanded Sector and Cloud Coverage

The draft adds profiles for five sectors, each describing typical architectures and key security challenges:

  • Building automation and control systems
  • Food and agriculture
  • Freight rail
  • Maritime vessels
  • Water and wastewater systems

It also describes how OT connects to cloud and Industrial Internet of Things (IIoT) services through three patterns: cloud telemetry, edge gateways and cloud-hosted remote access. It emphasises defining shared responsibility with each provider.

Practical implication: A cloud connection to the plant requires the same governance as any other external connection.

5. Stronger Identify, Protect, Detect, Respond and Recover Guidance

  • Asset management: The draft favours passive monitoring for older or sensitive devices, because active scanning can affect availability, and advises testing tools offline first. See our article on OT asset discovery.
  • Vulnerability prioritisation: The draft points to the CISA Known Exploited Vulnerabilities catalogue as a more relevant basis than vulnerability scores alone.
  • Identity: IT and OT credentials should be kept separate, so that a compromised enterprise account cannot authorise access to OT.
  • Post-quantum cryptography: Because OT devices remain in service for decades, organisations should assess their cryptographic inventory and vendor roadmaps now.
  • Monitoring: The guidance adds network baselining, time synchronisation and threat intelligence, and discusses artificial intelligence and digital twins with appropriate caution. See our article on OT security monitoring.
  • Recovery: Recovery should prioritise human and environmental safety before a process is restarted.

Practical implication: Monitoring is only effective when it is built on an accurate inventory and a known baseline of normal behaviour.

6. Architecture and Zero Trust

The draft extends network separation inside the OT environment:

  • Operational networks carry process control traffic.
  • Management networks carry configuration, patching and access control traffic, and should be kept separate from operational networks.
  • External access by vendors should use separate paths with their own credentials and enforcement boundaries.

It also describes supporting controls, including a two-firewall demilitarised zone (DMZ), a USB scanning kiosk, privileged access management with session recording, and passive network monitoring.

On zero trust, the draft does not require a complete zero trust architecture. It explains that existing controls such as privileged access management and credential separation already apply zero trust principles. Because many PLCs and human machine interfaces (HMIs) cannot support the technology, it suggests starting at Purdue Levels 3, 4 and 5 and the OT DMZ. See our articles on the Purdue Model and zero trust in OT.

Practical implication: Zero trust in OT is a gradual extension of existing controls at the upper levels of the architecture, not a replacement for segmentation.

7. Designing for Resilience

A new section recognises that security controls do not, on their own, keep a process running. It sets out four design principles:

  1. Fault tolerance: The failure of a single component should not stop the process.
  2. Redundancy: Redundancy should be designed into the architecture.
  3. Analogue backups: Hardwired instruments and manual control stations provide a recovery path that a cyber incident cannot affect.
  4. Out-of-band management: A separate management path allows the environment to be administered and recovered if the main network is compromised.

Practical implication: Organisations should plan for a system that degrades gracefully and recovers predictably, not only for one that resists attack.

8. The Overlay, the RMF and the Appendices

  • Appendix E, OT overlay: This remains the OT tailoring of the NIST SP 800-53 Revision 5 security controls.
  • Appendix F, Risk Management Framework: This new appendix applies the seven steps of the NIST Risk Management Framework (RMF) to OT, with mappings to CSF 2.0 and IEC 62443.
  • Appendix D, resources: This appendix now includes MITRE ATT&CK for ICS, MITRE EMB3D and the OWASP OT Top 10.
  • Moving online: Appendices C to F will become online resources in the final version, so the core guide will be shorter.

How the Industry Has Responded

During the pre-draft consultation earlier in 2026, several OT security organisations shared their submissions publicly, as reported by Information Security Media Group. The table compares their requests with the draft.

Industry requestRaised byHow the draft responds
More specific, practical guidanceDragosLargely addressed through expanded sections, although much guidance remains descriptive
Risk-based vulnerability prioritisationClaroty, ArmisPartly addressed through the CISA catalogue reference, with no detailed method
Passive assessment as the safe baselineDragosPartly addressed, with passive methods favoured but no formal model for active scanning
Closer alignment with IEC 62443OT Cybersecurity CoalitionPartly addressed through references and RMF mappings, with no full crosswalk
Moving appendices onlineBroad supportAddressed, with Appendices C to F moving online

Independent analysis of the zero trust section has welcomed its realism, particularly its recognition that many PLCs and HMIs cannot participate directly.

Practical implication: The areas marked as partly addressed are the ones most likely to change before the final publication.

What This Means for Your Organisation

  • No new obligation: SP 800-82 remains voluntary guidance outside United States federal agencies, although regulators, insurers and auditors widely use it as a reference.
  • A complementary reference: For organisations that work to IEC 62443, the NCA OTCC or NERC CIP, Revision 4 helps describe one OT programme in the language of each stakeholder.
  • Keep Revision 3 references for now: Existing mappings and audit evidence should stay referenced to Revision 3 until the final version is published.
  • An opportunity to comment: Feedback from operating facilities, submitted by 30 November 2026, helps NIST reflect real plant conditions.

Common Findings

From Beacon Security's assessment work across oil and gas, power, chemical and manufacturing facilities, the areas that Revision 4 emphasises are also those where gaps are most often found:

  • Shared management and operational networks: Patching and remote access traffic frequently share infrastructure with process control traffic.
  • Shared trust between IT and OT identities: OT systems often accept enterprise domain credentials.
  • Asset inventories that are out of date: Inventories prepared for a project are often not maintained afterwards.
  • OT risk that is not visible to the enterprise: OT risks are often missing from the enterprise risk register.

How Beacon Security Can Help

Reading a 300-page draft is one task. Knowing what it means for a specific facility, and what to address first, is a considerably harder one. The draft itself notes that the most successful approach combines management, OT engineers and operators, the IT organisation and a trusted OT advisor. Beacon Security specialises exclusively in OT security, and this is the role we perform for our clients.

  1. Discover: We map your assets, connections and remote access paths, using methods designed for operating facilities.
  2. Assess: We assess your programme against the Revision 4 structure and identify the gaps.
  3. Prioritise: We rank the gaps by their consequence for your process and schedule the work around your outage calendar.
  4. Sustain: We support remediation, training and monitoring, and help you update your programme when the final version is published.

Our services include risk assessment, gap assessment, cybersecurity design, cybersecurity implementation, OT SOC deployment and tabletop exercises.

Next Steps

If you would like to understand how the Revision 4 draft applies to your facility, please use the Book a Free 15-Minute 1:1 Call button on this page. The call is free of charge and without obligation.


This article is based on the initial public draft of NIST SP 800-82 Revision 4, published on 21 September 2026. The content of the final publication may differ. Until the final version is released, NIST SP 800-82 Revision 3 remains the current publication.

Industrial infrastructure
OT Cybersecurity Experts

Your OT Environment Deserves
Expert Protection

IT security tools were not built for Modbus, OPC, or safety-rated controllers. Get a dedicated OT cybersecurity team that understands industrial protocols, control system architecture, and the operational constraints of your environment.

IEC/ISA 62443 Aligned
NIST 800-82 Compliant
OTCC Ready
ECC Aligned
Zero Operational Disruption