Skip to content
Pro IT NW

Blog · 6 min read ·

Share

NIST SP 800-82 Rev. 4 draft: what changes for OT security

NIST's CSRC publication page lists the initial public draft of SP 800-82 Rev. 4 as published September 21, 2026, with the public comment period open through November 30, 2026. Nothing in it is final until NIST closes that comment period and issues a final revision.

NIST SP 800-82 Rev. 4, the draft update to NIST's Guide to Operational Technology (OT) Security, is not a finished standard — it's an initial public draft. NIST published it on September 21, 2026, and is taking public comments on Rev. 4 through November 30, 2026, before deciding what a final version looks like. If you run IT or OT for a mid-market manufacturer, including as an OEM machine supplier building automated equipment for other plants, this draft is worth reading now, not after it's finalized — some of what it emphasizes maps directly onto decisions you're probably already making about asset inventory and network monitoring.

The one-sentence version: NIST SP 800-82 Rev. 4 is a draft, not the new standard — it was published September 21, 2026, comments close November 30, 2026, and everything in it could still change before NIST finalizes it.

NIST SP 800-82 Rev. 4 is a draft — here's what that means

NIST's CSRC publication page titles this document NIST SP 800-82 Rev. 4 (Initial Public Draft) — Guide to Operational Technology (OT) Security — with a Date Published of September 21, 2026, and a Comments Due date of November 30, 2026. NIST's separate news feed for 2026 corroborates that publication date under an entry titled "Draft Guide to OT Security," dated September 21, 2026: NIST has released the initial public draft of Special Publication (SP) 800-82r4 (Revision 4), Guide to Operational Technology (OT) Security, which provides guidelines for improving the security of operational technology (OT) systems while addressing their unique performance, reliability, and safety requirements.

NIST didn't start this work in September, either. An earlier entry on the same news page, dated January 22, 2026, shows NIST announcing the project months before the draft text appeared: NIST has initiated the process of revising NIST SP 800-82, Guide to Operational Technology (OT) Security, to incorporate lessons learned, align with relevant NIST guidance and OT cybersecurity standards and practices, and address changes in the OT threat landscape. The publication page's own document history lists both dates — 01/22/26 and 09/21/26 — against SP 800-82 Rev. 4 (Draft).

NIST's materials don't say whether Rev. 4 replaces the current edition of SP 800-82 the moment it finalizes, and we're not going to characterize that ourselves. What the draft page does say is that this is a reorganization of "the previous risk management section" — confirming an earlier edition exists, without stating its status. Until NIST closes the comment period and publishes a final version, we wouldn't rebuild an OT security program around a document that's still a draft.

What NIST says changed in the draft

NIST's announcement lists the changes under a single heading: Updates in this revision include: — followed by six bullet points. Here's what each one means in practice for a manufacturer's IT/OT lead.

  • More sectors are explicitly in scope. NIST's bullet: Expanded introduction to operational technology (OT) sectors to include Building Automation and Control Systems (BACS), Water and Wastewater Systems (WWS), food and agriculture, freight rail, maritime vessels, and Industrial Internet of Things (IIoT) and cloud convergence. If your plant runs building automation for HVAC, physical access, or environmental monitoring alongside a production line, Rev. 4 treats that as part of the same OT conversation as your SCADA or ICS environment, not a separate topic.
  • The risk management section is restructured around CSF 2.0's Govern Function. NIST's bullet: Restructured around the NIST Cybersecurity Framework (CSF) 2.0, including a reorganization of the previous risk management section to focus on the CSF Govern Function. NIST's announcement doesn't go further than that in describing what changes — read that as directional (the risk management material now centers on Govern) until the draft itself or a final version says more about what the reorganization looks like in practice.
  • OT risk gets tied to enterprise risk management. NIST's bullet: Expanded discussion of how OT risk management aligns with broader enterprise risk management, as described in NIST IR 8286r1. That points toward plant-floor risk decisions being connected to the same enterprise risk register leadership already uses, instead of living in an OT-only silo that never reaches the board conversation.
  • A new appendix discusses adopting the Risk Management Framework. NIST's bullet: Discussion of the adoption of the NIST Risk Management Framework (RMF) in Appendix F. NIST's announcement doesn't summarize what that discussion says beyond noting it exists — Appendix F itself, once you're reading the draft, is where the detail on applying RMF to OT would live.
  • Guidelines for asset management and network monitoring are expanded. NIST's bullet: Expanded guidelines for implementing OT security controls, including asset management and network monitoring and detection. NIST names these two as examples of the OT security controls getting more detailed guidance — knowing what's connected to your OT network, and actually watching it, are the two the announcement calls out specifically.
  • System management functions and zero trust get their own architecture guidance. NIST's bullet: Security architecture guidelines focused on protecting system management functions and applying zero trust principles. The accounts, jump boxes, and engineering workstations used to manage OT and ICS systems — the management plane — get specific attention, alongside applying zero trust thinking to an environment historically built on implicit trust inside the plant network.

If you're already working through IT/OT network segmentation as part of a broader modernization project, our companion post on the manufacturing OT/IT split and server modernization covers the practical side of separating those networks — which is a natural pairing with Rev. 4's emphasis on asset management and monitoring.

Does the draft address IEC 62443?

Not that we found. Neither NIST's announcement text nor its list of updates on the CSRC publication page mentions IEC 62443 at all. If you're trying to map SP 800-82 Rev. 4 against IEC 62443's zones, conduits, or security levels, that comparison isn't something NIST's own published materials provide — the draft page simply doesn't address it.

What to do before November 30, 2026

A few concrete steps make sense while the comment period is still open, rather than waiting for a final version:

  • Read the draft itself. This post covers what NIST's publication page announces about the changes — it isn't a substitute for the full document, especially the new asset management, network monitoring, and system management function guidance most likely to affect day-to-day work.
  • Decide whether your organization should comment. NIST is explicitly requesting feedback through November 30, 2026, and points reviewers to a comment template for preparing formal responses. If Rev. 4's direction affects how you'll need to operate, that's a reason to weigh in before the draft becomes final rather than after.
  • Map your current asset inventory and network monitoring against the draft's emphasis. Rev. 4 expands its guidelines for asset management and network monitoring and detection, per NIST's list of updates. Knowing today what's actually connected to your OT network, and how much of it you're actively monitoring, puts you ahead of wherever the final version lands.

Rev. 4 isn't the only NIST draft moving through comment right now. We covered two others — including a multi-cloud architecture draft and a CSF-and-AI quick-start guide — in a separate roundup of current NIST drafts, if you're tracking more than one at a time.

Where we fit

We're not the author of NIST's guidance, and we won't tell you whether to submit a comment on the draft or how to word one. What we do help with is turning a framework's control list — asset inventory, network monitoring, RMF adoption, protecting system management functions — into an actual implementation plan for a Microsoft-centric IT/OT environment at a mid-market manufacturer, whether that's ahead of Rev. 4 finalizing or independent of it.

Sources

The 30-second version

NIST SP 800-82 Rev. 4 is an initial public draft, published September 21, 2026, with comments due November 30, 2026 — not a finished standard. NIST's own list of updates covers six changes: expanded sector coverage (including building automation, water/wastewater, food and agriculture, freight rail, maritime, and IIoT/cloud convergence), a restructuring around CSF 2.0 with a dedicated Govern focus, alignment with enterprise risk management under NIST IR 8286r1, a new RMF appendix, expanded asset management and network monitoring guidance, and security architecture guidance on system management functions and zero trust. NIST's publication page for the draft doesn't mention IEC 62443, and it doesn't state the previous revision's current status, so we haven't claimed either. Before November 30, 2026, read the draft itself, decide whether to comment, and check your current asset inventory and monitoring against where Rev. 4 is placing its emphasis.

If you want a senior engineer to help map your current OT asset inventory and monitoring against what Rev. 4 emphasizes, the project intake form takes about three minutes. We'll come back with scope and a fixed-fee range.


Pro IT NW helps regulated mid-market manufacturers plan and implement IT and OT security work, including asset inventory, network segmentation, and monitoring. Vendor-neutral, labor-only — we don't author NIST guidance or sell compliance certifications. This post reflects NIST's CSRC publication page for SP 800-82 Rev. 4 (Initial Public Draft) as read on September 27, 2026. Not legal or compliance advice.

Questions we get asked

Is NIST SP 800-82 Rev. 4 final?
No. As of this writing, NIST's CSRC publication page lists SP 800-82 Rev. 4 as an initial public draft, published September 21, 2026, with public comments open through November 30, 2026. NIST could revise the content in response to comments before publishing a final version, so nothing in the draft should be treated as settled guidance yet.
What's new in the NIST SP 800-82 Rev. 4 draft?
NIST's own announcement lists six updates: an expanded introduction to OT sectors including building automation and control systems, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and IIoT and cloud convergence; a restructuring around the NIST Cybersecurity Framework 2.0 that reorganizes the risk management section around the CSF Govern Function; an expanded discussion of how OT risk management aligns with enterprise risk management under NIST IR 8286r1; a new appendix on adopting the NIST Risk Management Framework; expanded guidelines for asset management and network monitoring and detection; and security architecture guidance focused on protecting system management functions and applying zero trust principles.
Does NIST SP 800-82 Rev. 4 compare to IEC 62443?
NIST's CSRC publication page for the draft doesn't mention IEC 62443 anywhere in its announcement or its list of updates, and neither does NIST's news entry for the release — those are the two pages we reviewed. If you need to map Rev. 4 against IEC 62443 zones, conduits, or security levels, that's work you'd have to do yourself; the pages we checked don't do it for you.
Is there a checklist for NIST SP 800-82 Rev. 4?
Not directly from NIST. The CSRC publication page for the draft offers a comment template for people preparing formal feedback during the public comment period, not a compliance or implementation checklist. If you want a working checklist, the closest source-backed starting point is the six-item list of updates NIST itself published, mapped against what you currently do for asset management, network monitoring, and OT risk governance.
Who wrote the NIST SP 800-82 Rev. 4 draft?
NIST's CSRC publication page credits nine authors: Keith Stouffer, Michael Pease, and CheeYee Tang from NIST, and Adam Hahn, Jim Gilsinn, Daniel Rebori-Carretero, Otis Alexander, Michael Fialk, and Zackary Louis Silva from MITRE.

Related service

Manufacturing IT

Written by the team at · Senior-led Microsoft project consultancy · Seattle and the Pacific Northwest, delivered USA-wide.

Have a project on the runway?

Tell us the workload, the seat count, and the deadline. We'll come back with scope and a fixed-fee range.