NIST Special Publication 800-82 is the most widely cited guide to securing operational technology. Now in its third revision, it sets out how to apply cybersecurity to environments where reliability, safety and physical processes change the rules that IT security usually assumes.

This article explains what SP 800-82 is, why OT risk is different, the core of its recommendations, and how it fits alongside the NIST Cybersecurity Framework and IEC 62443. It is a practical orientation, not a substitute for the document itself.

01Key takeaways

  1. 01

    SP 800-82 is NIST's guide to securing operational technology, including ICS, SCADA and related systems.

  2. 02

    It stresses that OT risk differs from IT: availability and safety often outrank confidentiality.

  3. 03

    Its core themes include risk management, network architecture, segmentation and applying controls suited to OT.

  4. 04

    Recommended architecture leans on zones, conduits and controlled boundaries between OT and IT.

  5. 05

    It complements the NIST Cybersecurity Framework and aligns with IEC 62443 rather than competing with them.

02What SP 800-82 is

SP 800-82, the Guide to Operational Technology Security, is a NIST publication that helps organizations secure OT while accounting for its unique performance, reliability and safety requirements. Its latest revision broadened its scope from industrial control systems to operational technology more generally.

It is guidance, not a checklist or a certification. Its value is in helping teams reason about OT risk and select appropriate controls, which makes it a common foundation for OT security programs and a frequent reference in regulation and other standards.

SP 800-82 is the reference that translates general cybersecurity into the realities of operational technology.

03How OT risk differs from IT

A central theme is that OT cannot simply inherit IT security practices. The priorities are different, and applying IT assumptions blindly can cause harm in an operational environment.

Availability and safety first
In OT, keeping the process running safely usually outranks confidentiality, reversing the typical IT emphasis.
Real-time constraints
Control systems have timing requirements that some security measures can disrupt.
Long lifecycles
OT equipment can run for decades, limiting patching and requiring compensating controls.
Physical consequences
A security failure can affect physical processes, safety and the environment, not just data.

04The guidance's core themes

SP 800-82 covers a broad program, but several themes recur and capture much of its practical advice for OT teams.

  • Establish an OT-specific risk management approach rather than reusing IT risk decisions wholesale.
  • Build a defensible network architecture with segmentation between OT and IT.
  • Apply controls suited to OT constraints, using compensating controls where patching or hardening is limited.
  • Plan for incident response and recovery in an operational context.
  • Account for the full lifecycle of OT systems, including procurement and decommissioning.

05Recommended architecture

On network architecture, SP 800-82 reflects the broad consensus of OT security: separate OT from IT, control the boundary between them, and segment within OT so that a problem in one area does not spread freely.

It discusses boundary protection including the use of one-way and unidirectional approaches where appropriate, alongside firewalls and a DMZ between OT and enterprise networks. The recurring principle is to allow only the communication that is genuinely required, in the direction it is required.

For boundaries where the requirement is publication or only occasional access, an AIRGAPNET controlled connectivity pattern can implement the controlled, minimized communication SP 800-82 encourages, keeping a boundary one-way or offline by default.

06Applying controls in OT

SP 800-82 connects to the broader NIST control catalog, helping teams tailor general security controls to OT. The emphasis is on selecting and adapting controls so they fit operational reality rather than forcing OT to behave like IT.

Where a control such as frequent patching is impractical, the guidance points toward compensating controls, including reducing reachability and tightening boundaries, to manage the risk by other means. This is where exposure reduction and one-way transfer fit naturally into a compliant program.

07How it relates to the CSF and IEC 62443

SP 800-82 does not stand alone. It is designed to work with the NIST Cybersecurity Framework, helping apply the framework's outcomes to OT, and it aligns closely with IEC 62443, the international standard for industrial automation and control system security.

In practice, teams often use the Cybersecurity Framework to organize their program, SP 800-82 to apply it to OT, and IEC 62443 for detailed architecture and requirements. They are complementary layers, not competing choices.

08Closing thought

SP 800-82 endures because it takes OT seriously on its own terms. Instead of pretending operational technology is just unusual IT, it builds security advice around availability, safety and the physical world, which is why it remains the reference point for OT programs.

Use it as the bridge between general cybersecurity and your plant. Manage OT risk deliberately, architect defensible boundaries, and apply controls that respect operational constraints, with reachability reduction as a practical compensating control where patching cannot reach.

FAQFrequently asked questions

What is NIST SP 800-82?

NIST SP 800-82 is the Guide to Operational Technology Security, a publication that helps organizations secure OT, including ICS and SCADA, while respecting its performance, reliability and safety requirements. Its latest revision broadened the scope from ICS to OT generally.

How does SP 800-82 say OT risk differs from IT?

It stresses that in OT, availability and safety usually outrank confidentiality, real-time constraints limit some measures, equipment lifecycles are long, and security failures can have physical consequences. IT practices cannot simply be inherited.

What architecture does SP 800-82 recommend?

It recommends separating OT from IT, controlling the boundary with firewalls and a DMZ, segmenting within OT, and using one-way or unidirectional approaches where appropriate, allowing only the communication genuinely required in the direction required.

How does SP 800-82 relate to the NIST CSF and IEC 62443?

It is complementary. Teams often use the NIST Cybersecurity Framework to organize their program, SP 800-82 to apply it to OT, and IEC 62443 for detailed architecture and requirements. They are layers that work together, not competing standards.

What if you cannot patch OT systems under SP 800-82?

The guidance points toward compensating controls when measures like frequent patching are impractical. Reducing reachability and tightening boundaries are practical ways to manage the risk by other means while staying aligned with the guide.

SRCSources of record

Guidance into practice

Turn SP 800-82 principles into an enforced boundary.

Where the guide calls for minimized, controlled communication between OT and IT, keep the boundary one-way or offline by default and open it only when genuinely required.

Related article

Continue the thread IEC 62443 Zones and Conduits Explained: A Practical OT Segmentation Guide