TL;DR:
NIST has opened a public comment period for SP 800-82, Guide to Operational Technology (OT) Security, Rev. 4. The draft aims to update guidance for securing industrial control systems and related OT, aligning with Cybersecurity Framework 2.0 and other modern guidance. The comment window runs through February 23, 2026, with submissions invited to sp800-82rev4@nist.gov. This development matters for engineers responsible for OT security, system integration, and compliance planning across energy, manufacturing, and transportation sectors. The move complements established SP 800-82 Rev 3 guidance, issued in 2023, and signals a structured progression toward tighter OT security controls in the face of evolving threats. Understanding the scope, timelines, and how to participate will help engineers anticipate upcoming changes to risk assessments, procurement criteria, and exam topics that touch OT cybersecurity.
Background and current guidance
NIST Special Publication 800-82 provides foundational guidance for OT security, focusing on the unique performance, reliability, and safety requirements of industrial control environments. The current iteration, SP 800-82 Rev. 3, was published in September 2023 and remains the baseline for many OT security programs across energy, manufacturing, and transportation sectors. This Rev 3 document covers a broad range of OT devices and architectures, including SCADA, PLCs, DCS, and related networks, and it emphasizes risk-based security countermeasures appropriate for OT without compromising safety and availability. The Rev 3 publication is available through the NIST CSRC portal and remains a central reference for practitioners today. (csrc.nist.gov)
The Rev 4 draft: what is changing
In January 2026, NIST announced a formal call for comments on SP 800-82, OT Security Rev. 4, to incorporate lessons learned and align with newer CSF guidance, OT standards, and the shifting threat landscape. The update explicitly ties proposed revisions to Cybersecurity Framework (CSF) 2.0, NIST Interagency Report (IR) 8286 Rev. 1, and SP 800-53 Rev. 5.2.0, signaling a tighter integration between OT security practices and broader federal cybersecurity policy. The objective is to refine, augment, and harmonize OT security guidance so practitioners can address modern risks while maintaining process reliability and safety. (nist.gov)
Key themes likely to appear in Rev. 4 include guidance on governance, asset inventory for OT networks, enhanced risk assessment methodologies tailored to OT, and clearer mapping between OT security controls and existing industrial protocols. While the exact text awaits public input, the emphasis on alignment with CSF 2.0 and the OT threat environment indicates a push toward more prescriptive, risk-informed controls that balance safety with defense-in-depth. The update is framed as a means to better help OT professionals understand and manage cybersecurity risk in evolving industrial environments. (nist.gov)
Timetable and how to participate
The public comment period for SP 800-82 Rev. 4 runs through February 23, 2026. Comments can be submitted to sp800-82rev4 at nist.gov, with the subject line “Comments on SP 800-82.” NIST also points readers to the full official announcement for additional details about scope and submission procedures. This creates an immediate opportunity for engineers, OT security leads, and vendor teams to shape upcoming guidance before it is finalized. Released January 22, 2026, the call for comments invites broad participation from practitioners to ensure practical relevance across industries. (nist.gov)
Practical implications for practicing engineers
- OT security programs will be increasingly guided by a CSF-aligned framework: Expect more explicit alignment between OT controls and the NIST CSF 2.0 structure, which can influence risk governance, control selection, and assessment reporting. This alignment helps correlate OT security activities with enterprise risk management processes. (nist.gov)
- Asset visibility and risk prioritization gain emphasis: With Rev 4, engineers may see stronger calls for clear asset inventories, network segmentation, and prioritized remediation plans that reflect OT safety and availability requirements. This can affect system design choices, procurement criteria, and maintenance planning for plants and facilities. (nist.gov)
- Industrial control systems design and procurement: Updates typically translate into more detailed expectations for secure configuration, change management, and supply chain considerations for OT devices, software, and services. Practitioners should anticipate revised security baseline expectations as Rev 4 takes shape, and plan vendor evaluations accordingly. (csrc.nist.gov)
- Exam and professional development relevance: OT cybersecurity topics are increasingly part of the broader engineering cybersecurity landscape. PE exam candidates may encounter more questions that test understanding of OT risk management concepts, defense-in-depth strategies, and the role of standards like SP 800-82 within integrated design and operations. Staying current with SP 800-82 Rev 3 and the Rev 4 draft will help with both practice and exam readiness. (csrc.nist.gov)
Implications for PE exam candidates
- Build a strong foundation in OT security concepts: Even without Rev 4 final text, Rev 3 provides a comprehensive baseline for OT architecture, threat models, and compensating controls. Review the Rev 3 structure and typical control families while preparing for systems that blend IT and OT environments. (csrc.nist.gov)
- Watch for crosswalks to CSF 2.0: Expect exam questions or scenario-based problems that require mapping OT controls to CSF categories such as Identify, Protect, Detect, Respond, and Recover. Understanding how OT assets interact with broader enterprise cyber controls will be advantageous. (nist.gov)
- Plan for updates in security governance and risk management: Rev 4 is likely to emphasize governance, risk assessment, and supply chain security in OT contexts. Candidates should be ready to apply risk-based decision making to OT system design and lifecycle management. (nist.gov)
How practitioners can prepare now
- Read Rev 3 as a baseline: Familiarize with the existing SP 800-82 Rev. 3 framework to understand the current approach to OT security, including the treatment of OT networks, access controls, and incident response in industrial environments. (csrc.nist.gov)
- Track the Rev 4 draft and submit input: Mark February 23, 2026, on calendars and prepare comments focusing on practical implementation, interoperability with existing controls, and alignment with CSF 2.0. Use the official channels and maintain a record of suggested improvements for internal policy updates. (nist.gov)
- Align OT security with project lifecycles: For engineers involved in EPCs, integrations, or retrofits, map Rev 4 concepts to procurement specs, vendor assessments, and commissioning checklists to ensure security is embedded from design through operation. (nist.gov)
Key takeaways for 2026
- NIST SP 800-82 Rev 4 (Draft) represents a structured update to OT security guidance, with explicit intent to synchronize OT controls with CSF 2.0 and related guidance. The public comment period through February 23, 2026, offers a direct opportunity for practitioners to influence the final content. (nist.gov)
- The Rev 3 baseline remains the authoritative reference for current OT security practice, while Rev 4 signals a tighter, more formal alignment with enterprise cybersecurity policy and modern OT threat considerations. Practitioners should begin aligning programs with the anticipated direction by enhancing asset inventories, governance, and risk-based control selection. (csrc.nist.gov)
Sources:
- Call for Comments on NIST SP 800-82, Guide to Operational Technology (OT) Security, NIST, January 22, 2026. https://www.nist.gov/news-events/news/2026/01/call-comments-nist-sp-800-82-guide-operational-technology-ot-security (nist.gov)
- SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security, CSRC/NIST, Final publication date September 2023. https://csrc.nist.gov/pubs/sp/800-82/rev-3/final (csrc.nist.gov)
- NIST CSRC public summary and context for OT security guidance, including alignment with CSF 2.0 and related guidance. https://csrc.nist.gov/ (Public announcements and SP 800-82 Rev. 4 context) (nist.gov)
This timely development provides engineers with a structured path to strengthen OT cybersecurity programs, informs procurement and design decisions for facilities with critical control systems, and offers PE exam candidates a concrete area to study as OT risk management and cyber-physical system security gain prominence in licensure assessments.