✳ US · NIST SP 800-82

SP 800-82: OT security guidance (not an IT twin, not a plant certificate)

An educational overview of NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security: guidance for securing OT while addressing performance, reliability, and safety. Not a plant certification, and not an IT twin.

US · NIST SP 800-82Publication explainerLast reviewed

What this publication is for

NIST Special Publication 800-82 Revision 3 is the Guide to Operational Technology (OT) Security. The CSRC final page says it provides guidance on how to secure OT while addressing unique performance, reliability, and safety requirements. NIST announced the Final on 28 September 2023.

That is a publication of guidance. It is not a plant certificate, and it is not a badge that says a site implements NIST.

Edition pin

SP 800-82 Rev. 3, Final, 28 September 2023. CSRC lists Date Published as September 2023. Document history stamps the Final as 09/28/23. DOI 10.6028/NIST.SP.800-82r3. The PDF is NIST.SP.800-82r3 on nvlpubs. The same CSRC page says this Final supersedes SP 800-82 Rev. 2 (3 June 2015).

Use that string when you name the publication. A slide that says only 800-82 does not say which revision.

What OT means on this page

The CSRC abstract describes OT as programmable systems and devices that interact with the physical environment, or that manage devices that do. They detect or cause a direct change through monitoring and/or control of devices, processes, and events.

Examples named there include industrial control systems, building automation systems, transportation systems, physical access control systems, and physical environment monitoring and measurement systems. This page teaches that category. It is not a vendor catalog of control products.

Why Revision 3 says OT

Earlier revisions centered on industrial control systems. The 28 September 2023 news page says Revision 3 expands the scope from ICS to OT. The same note lists updates to threats, vulnerabilities, risk management, architectures, and alignment with the Cybersecurity Framework.

The news page also says Revision 3 adds tailoring guidance for SP 800-53 Revision 5, including an OT overlay for low-impact, moderate-impact, and high-impact OT systems. Literacy only: the overlay exists. This page does not copy those baselines, and it is not homework to implement them.

OT is not IT with different logos

Plant and OT environments care about safety, reliability, and performance alongside information security. A change that looks like a routine IT patch can be a process-safety event if it breaks timing, availability, or approved operational procedures.

Atlas industry notes already say to adapt this guidance to the actual system and to approved operational procedures. Ask the OT or operations owner which change window applies before you propose a network or host change that touches process control. Do that privately. Do not paste plant diagrams into Atlas.

An air-gap is not the program

Isolation habits matter. "We air-gapped it once," or one VLAN, is not a security program, and it is not what SP 800-82 replaces.

Segmentation literacy for a small manufacturing environment lives in a different NIST publication, CSWP 28. That guide is related. It is not a subchapter of this explainer, and this page does not turn it into a weekend checklist.

What SP 800-82 is not

It is not a plant certification. It is not FedRAMP, the federal cloud Authorization program. It is not CMMC, the contractor assessment program. It is not a do-it-yourself list for hardening every controller this weekend.

It also does not automatically cover every sector mandate. EPA water-sector resources, and the Transportation Systems Sector Cybersecurity Framework Implementation Guidance, stay related outbound links. They are not the body of this page.

Revision 4 is a draft

Re-opened on CSRC 25 September 2026: the Rev. 3 final page still carries a Planning Note dated 21 September 2026. The note points to an SP 800-82 Rev. 4 initial public draft. Public comments are due 30 November 2026. Rev. 3 remains the current Final until NIST publishes a new Final.

A Rev. 4 Final publication date is UNKNOWN. If that Planning Note changes, treat the draft status as UNKNOWN until you re-open the CSRC page. A draft does not make Rev. 3 obsolete today.

Rewrite the one-line claim

Replace "we are 800-82 certified" with this sentence: we use SP 800-82 Rev. 3 as OT security guidance and adapt changes through approved ops.

The Utilities, Manufacturing, and Transport paths already cite this Final. Read the explainer, then return to the path that matches the system. Sector resources on those paths stay related. They are not extra certificates.

Phrases people collapse

Teaching table only. It does not assign a plant Authorization, and it does not find that a publication has been met.

Claims people fold into one OT badge. Not a certification.
Phrase people sayLiteracy correction
OT is just IT with industrial logos.OT interacts with the physical environment. Safety, reliability, and performance sit beside information security.
An air-gap or one VLAN means SP 800-82 is done.Isolation is a habit, not the publication. CSWP 28 is related manufacturing segmentation guidance, not a chapter of this page.
Our plant is 800-82 certified.Rev. 3 is guidance. Atlas does not issue plant Authorizations or OT seals. Adapt changes through approved ops.
The Rev. 4 draft retired Rev. 3.Rev. 3 remains the current Final. Comments are due 30 November 2026. A Rev. 4 Final date is UNKNOWN.
800-82 means FedRAMP or CMMC.FedRAMP is federal cloud Authorization. CMMC is a contractor assessment program. Neither one is this publication.

Claims to retire

OT is just IT with industrial logos.

OT systems interact with the physical environment. Safety, reliability, and performance sit beside confidentiality, integrity, and availability. Copying an enterprise patch into a control network without approved ops can be a process-safety event.

We air-gapped it once, so OT security is done.

Isolation habits matter. One air-gap, or one VLAN, is not a security program and is not what SP 800-82 replaces. Manufacturing segmentation literacy is CSWP 28, a separate guide.

NIST published 800-82, so our plant is certified.

SP 800-82 Rev. 3 is guidance. It is not a plant certification, and this lesson is not an Authorization or an OT seal.

The Rev. 4 draft means Rev. 3 is obsolete.

As of the 25 September 2026 CSRC check, Rev. 3 is still the current Final. Comments on the Rev. 4 initial public draft are due 30 November 2026. A Rev. 4 Final date is UNKNOWN.

800-82 is the same thing as FedRAMP or CMMC.

FedRAMP is a cloud Authorization program. CMMC is a contractor assessment program. This page is OT security guidance. Those are different lanes.

Sort the one-line claim

Teaching sort only. It does not certify a plant, and it does not approve a control-network change.

Three sentences people fold into one badge. Not a determination.
SentenceLaneWhat this page is teaching
We use SP 800-82 Rev. 3 as OT security guidance and adapt changes through approved ops.Guidance, adaptedThe publication is the Guide to OT Security. Changes that touch process control still go through the OT or operations owner.
We are 800-82 certified.Not a plant certificateNIST did not certify the plant by publishing the guide. Completing this lesson is not an Authorization or an OT seal.
FedRAMP Authorization, or CMMC Status.Different laneFedRAMP is the cloud Authorization program. CMMC is the contractor assessment program. Neither one is SP 800-82.

CHECK THE CATEGORY

Which sentence matches this page?

Glossary and nearby pages

Use the agency page in the sources for the authoritative text. This page has no figure.

Find your next idea.

Tip: press / to open search. Escape closes this window.