NIST SP 800-82:
Cryptography and PKI for Operational Technology Security
Overview
| Region | United States (widely regarded as the global benchmark for OT/ICS security) |
| Applicability | Federal Agencies: operating or procuring OT/ICS under FISMA and the NIST Risk Management Framework Critical Infrastructure Operators: energy, water, manufacturing, and transportation organizations OT/ICS Vendors and Integrators: companies supplying PLCs, DCS, SCADA components, and engineering workstations into environments that reference SP 800-82 |
| Relevant sections | SP 800-82r3 Appendix F: System and Communications Protection (SC) control family SP 800-82r3 Appendix F: Identification and Authentication (IA) control family SP 800-82r3 Appendix F: OT overlay mapping SP 800-53 controls to ICS applicability |
NIST SP 800-82 Revision 3, “Guide to Operational Technology (OT) Security,” is NIST’s flagship guidance for securing industrial control systems, SCADA, distributed control systems, and the broader category of OT, including building automation and physical access control systems. Revision 3 expanded the scope beyond classic ICS to cover the full range of connected operational technology, reflecting the deeper integration between IT and OT networks.
In practical terms, the guide applies NIST SP 800-53 control families to OT environments, with an OT-specific overlay in Appendix F that tells practitioners which controls apply as-is, which need modification for industrial constraints, and which do not apply. The System and Communications Protection (SC) and Identification and Authentication (IA) families carry the direct cryptographic obligations: encrypting data, authenticating devices and users, and establishing formal key management practices suited to environments that often run for 15 to 25 years.
Why It Matters
Why It Matters
NIST SP 800-82 is the primary NIST guidance used by federal agencies securing OT environments and is widely referenced when implementing NIST RMF requirements. It is frequently used as a benchmark during cybersecurity assessments by critical infrastructure operators, sector regulators, and cyber insurers when evaluating OT security maturity, even outside the federal space.
How This Maps to Cryptography
NIST SP 800-82 addresses cryptography primarily through the System and Communications Protection and Identification and Authentication control families, tailored for OT’s legacy devices and availability constraints. The key control areas with direct cryptographic implications are:
| Section | Function | What it says | Supporting Products |
|---|---|---|---|
| SC-8, SC-28 — Transmission Confidentiality, Protection of Information at Rest | Data Confidentiality (At Rest and In Transit) | Encryption of OT communications and historian or configuration data stores, with certificate-backed key material managed centrally rather than per-device | Command |
| IA-2, IA-3, IA-5 — Identification and Authentication (Organizational Users, Devices, Authenticator Management) | Device and User Authentication | Certificate-based authentication for OT devices, engineering workstations, and operators, replacing static or shared credentials common in brownfield ICS | EJBCA |
| SC-12, SC-13 — Cryptographic Key Establishment and Management, Use of Cryptography | Cryptographic Key Establishment and Management | Use of approved algorithms plus formal key generation, distribution, storage, and destruction procedures across the OT key lifecycle | Command |
| SI-7, CM-14 — System and Information Integrity, Signed Components | Firmware and Software Integrity | Cryptographic verification of firmware and software integrity before installation on OT devices | SignServer |
| SC-8(1), SC-23 — Transmission Confidentiality and Integrity, Session Authenticity | Communications Integrity | Message authentication and mutually authenticated sessions (TLS/DTLS) to protect OT protocol traffic against injection and replay | EJBCA |
| AC-17, IA-2(1) — Remote Access, Multi-Factor Authentication | Remote Access Protection | Certificate-based multi-factor authentication for remote engineering and vendor access sessions into OT environments | Command |
Audit Readiness
NIST SP 800-82 assessments, whether self-conducted, performed by a federal authorizing official, or reviewed by a customer or insurer, focus on evidence that OT-specific controls are implemented, not just documented. Key areas that examiners probe:
- OT Asset and Cryptographic Inventory: Has the organization inventoried every OT device, its cryptographic capability, and current certificate or key status?
- Control Overlay Mapping: Has the organization documented which NIST SP 800-53 SC and IA controls apply as-is, apply with modification, or are not applicable per the Appendix D overlay?
- Legacy Device Compensating Controls: For devices that cannot natively support PKI or strong authentication, are compensating controls identified and documented?
- Remote Access Certificate Management: Do remote engineering and vendor sessions use unique, revocable certificates rather than shared credentials?
- Firmware Signing Verification: Can the organization demonstrate that firmware updates are cryptographically signed and that verification is enforced before deployment?
- Key Lifecycle Documentation: Are key generation, rotation, and revocation procedures documented and applied consistently across ICS vendors and integrators?
TAKE THIS TO MANAGEMENT
NIST SP 800-82 is the reference federal auditors, critical infrastructure regulators, and cyber insurers now use to judge our OT security program. Most of our equipment was never built to prove who they are or verify who sent them a command, and closing that gap is exactly what NIST SP 800-82 asks us to do.
If we can’t show that engineering workstations, remote vendors, and PLCs authenticate with real, revocable credentials instead of shared passwords, we’re the least defensible target in the sector. A documented, auditable program is what keeps federal customers, sector regulators, and insurers satisfied after the next incident, not a policy binder that has never been tested.


