NIST Special Publication 800-82 is NIST's guide to securing operational technology. The current edition, Revision 3, published September 2023, is titled Guide to Operational Technology (OT) Security, broadening the scope from earlier editions that addressed only industrial control systems. It tells asset owners how to apply standard security controls without breaking the OT they are meant to protect.
What does NIST SP 800-82 cover?
The publication is the OT-specific companion to NIST SP 800-53 (the control catalog) and NIST SP 800-171 (CUI protection). It addresses the systems that run physical processes: SCADA, distributed control systems, programmable logic controllers, safety instrumented systems, building automation, and industrial IoT.
The structure follows the NIST 800-53 control families but reinterprets each one for OT operating conditions:
- Availability over confidentiality. Safety and uptime take precedence over the traditional confidentiality-first ordering.
- Deterministic behavior. Controls must not add latency or jitter that disrupts a control loop.
- Legacy compatibility. The guide explicitly addresses equipment with 20-year service lives and no firmware update path.
- Physical-cyber coupling. A cyber event in OT can cause a physical consequence: process upset, equipment damage, or a safety incident.
How does NIST SP 800-82 relate to other frameworks?
- NIST SP 800-53 supplies the full control catalog; 800-82 overlays OT-specific guidance on each family.
- NIST SP 800-171 defines CUI protection for non-federal systems; 800-82 addresses the OT portion of those systems.
- IEC 62443 is the international standard for industrial automation security; 800-82 and IEC 62443 map bidirectionally, and organizations often cite both.
- CMMC Level 2 draws its 110 controls from NIST 800-171. When CMMC scopes OT assets under the Specialized Asset category, 800-82 provides the implementation guidance.
Who should use NIST SP 800-82?
Asset owners and integrators in manufacturing, energy, water, and defense who run control systems and need a defensible security program. A compliance effort that leans only on 800-171 will leave gaps for OT, because the parent standard does not address control-system constraints. 800-82 fills those gaps with concrete guidance on segmentation, remote access, incident response, and logging in OT contexts.
Why does NIST SP 800-82 matter now?
Revision 3 added substantial material on zero-trust architecture applied to OT, software bill of materials expectations, and supply-chain risk for ICS vendors. Those additions align with DoD DTM 25-003 direction and reflect where OT security is heading: away from the assumption that a flat, trusted plant network is safe because it sits behind a firewall.
This is where Access Gate helps. It aligns with the 800-82 guidance on OT segmentation and identity-based access, providing a non-inline enforcement layer that suits control-system environments without re-architecting the physical network.

