NIST published the initial public draft of Special Publication 800-82 Revision 4, "Guide to Operational Technology (OT) Security," on September 21, 2026, with comments due November 30, 2026. The revision restructures the guide around the NIST Cybersecurity Framework (CSF) 2.0 and widens its coverage well past the factory floor — into building automation, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and the convergence of Industrial Internet of Things (IIoT) devices with cloud environments.
What Changed in Revision 4
SP 800-82 is the publication agencies and their contractors reach for when the system in question is not a laptop. Per NIST, the fourth revision makes six notable updates:
- A broader definition of "OT sectors," now expressly including building automation and control systems (BACS), water and wastewater systems (WWS), food and agriculture, freight rail, maritime vessels, and IIoT/cloud convergence.
- A restructure around CSF 2.0, with the prior risk management section reorganized to center on the CSF Govern function.
- Explicit alignment with enterprise risk management, following the approach in NIST IR 8286r1.
- A discussion of Risk Management Framework (RMF) adoption in Appendix F.
- Expanded control implementation guidance, particularly asset management and network monitoring and detection.
- Security architecture guidance focused on protecting system management functions and applying zero trust principles.
The draft was authored by Keith Stouffer, Michael Pease, and CheeYee Tang of NIST, with a MITRE team including Adam Hahn, Jim Gilsinn, Daniel Rebori-Carretero, Otis Alexander, Michael Fialk, and Zackary Louis Silva. An earlier Revision 4 draft circulated on January 22, 2026; this is the initial public draft and carries a call for patent claims.
Why This Reaches Contractors Who Don't Think They Have "OT"
A NIST special publication is guidance, not a regulation. It binds a contractor when an agency writes it — or requirements derived from it — into a specification, a statement of work, or a clause. Two things make that path likely here.
First, OT is the asset class most often dropped from scope. Programmable equipment that touches Controlled Unclassified Information, or that sits on a network with systems that do, is inside the assessment boundary whether or not it can run an agent. The practical question is categorization, not exclusion — the same analysis we walk through in CMMC Level 2 scoping. "It's a CNC machine" is a description, not a justification.
Second, the government is already moving OT into procurement language. The bulk-power and energy-procurement activity this year, covered in our Executive Order 14421 discussion, is the same trend from a different direction: physical-world systems acquired through contracts, with security expectations attached. SP 800-82 is the technical vocabulary those expectations will borrow from.
Contractors most exposed are defense manufacturers and depot operators, facility and base-operations contractors running building controls on government property, maritime and rail service providers, and utility or water-system contractors. See our defense industry overview for how these obligations stack.
What to Do During the Comment Window
Three steps that produce value whether or not you file a comment:
1. Inventory the programmable equipment you actually operate under contract. Include building controls, badge and physical access systems, environmental monitoring, and test equipment. Asset management is the first expanded area in the draft for a reason — it is where most OT programs stall. 2. Read the CSF 2.0 Govern material against your own decision rights. The restructure asks who owns OT risk. In many contractor organizations the honest answer is "facilities and IT each assume the other does," which is the gap the Govern function exists to close. 3. Comment where the draft misdescribes your reality. Safety and availability constraints that make a control infeasible are worth saying now, in writing, to NIST — not later, to an evaluator. Comments go to NIST at the address on the publication page through November 30, 2026.
If you are unsure which of these obligations already apply to your contracts, start with Find My Requirements and the frameworks reference, then use the checklists to organize the evidence.
OT security has spent a decade as a specialist concern. This draft is a reasonable signal that it is becoming a contract concern.
Key Takeaways
- NIST released the initial public draft of SP 800-82 Rev. 4 on September 21, 2026; comments are due November 30, 2026.
- The revision restructures OT security guidance around CSF 2.0 (centering the Govern function), aligns it with enterprise risk management per NIST IR 8286r1, adds RMF discussion in Appendix F, and expands coverage to building automation, water and wastewater, food and agriculture, freight rail, maritime vessels, and IIoT/cloud convergence.
- Guidance becomes binding through solicitations and clauses, so contractors with programmable equipment — including facility controls they may not classify as IT — should inventory those assets, settle who owns OT risk internally, and comment on infeasible controls before the standard hardens into a specification.