Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

NIST SP 800-82:

Cryptography and PKI for Operational Technology Security

Updated: August 24, 2026

Overview

Region United States (widely regarded as the global benchmark for OT/ICS security) 
Applicability Federal Agencies: operating or procuring OT/ICS under FISMA and the NIST Risk Management Framework Critical Infrastructure Operators: energy, water, manufacturing, and transportation organizations  OT/ICS Vendors and Integrators: companies supplying PLCs, DCS, SCADA components, and engineering workstations into environments that reference SP 800-82 
Relevant sections SP 800-82r3 Appendix F: System and Communications Protection (SC) control family SP 800-82r3 Appendix F: Identification and Authentication (IA) control family SP 800-82r3 Appendix F: OT overlay mapping SP 800-53 controls to ICS applicability 

NIST SP 800-82 Revision 3, “Guide to Operational Technology (OT) Security,” is NIST’s flagship guidance for securing industrial control systems, SCADA, distributed control systems, and the broader category of OT, including building automation and physical access control systems. Revision 3 expanded the scope beyond classic ICS to cover the full range of connected operational technology, reflecting the deeper integration between IT and OT networks. 

In practical terms, the guide applies NIST SP 800-53 control families to OT environments, with an OT-specific overlay in Appendix F that tells practitioners which controls apply as-is, which need modification for industrial constraints, and which do not apply. The System and Communications Protection (SC) and Identification and Authentication (IA) families carry the direct cryptographic obligations: encrypting data, authenticating devices and users, and establishing formal key management practices suited to environments that often run for 15 to 25 years. 

Why It Matters 

Why It Matters 

NIST SP 800-82 is the primary NIST guidance used by federal agencies securing OT environments and is widely referenced when implementing NIST RMF requirements. It is frequently used as a benchmark during cybersecurity assessments by critical infrastructure operators, sector regulators, and cyber insurers when evaluating OT security maturity, even outside the federal space. 

How This Maps to Cryptography 

NIST SP 800-82 addresses cryptography primarily through the System and Communications Protection and Identification and Authentication control families, tailored for OT’s legacy devices and availability constraints. The key control areas with direct cryptographic implications are: 

Section Function What it says Supporting Products
SC-8, SC-28 — Transmission Confidentiality, Protection of Information at Rest Data Confidentiality (At Rest and In Transit) Encryption of OT communications and historian or configuration data stores, with certificate-backed key material managed centrally rather than per-device Command 
IA-2, IA-3, IA-5 — Identification and Authentication (Organizational Users, Devices, Authenticator Management) Device and User Authentication Certificate-based authentication for OT devices, engineering workstations, and operators, replacing static or shared credentials common in brownfield ICS EJBCA 
SC-12, SC-13 — Cryptographic Key Establishment and Management, Use of Cryptography Cryptographic Key Establishment and Management Use of approved algorithms plus formal key generation, distribution, storage, and destruction procedures across the OT key lifecycle Command 
SI-7, CM-14 — System and Information Integrity, Signed Components Firmware and Software Integrity Cryptographic verification of firmware and software integrity before installation on OT devices SignServer 
SC-8(1), SC-23 — Transmission Confidentiality and Integrity, Session Authenticity Communications Integrity Message authentication and mutually authenticated sessions (TLS/DTLS) to protect OT protocol traffic against injection and replay EJBCA 
AC-17, IA-2(1) — Remote Access, Multi-Factor Authentication Remote Access Protection Certificate-based multi-factor authentication for remote engineering and vendor access sessions into OT environments Command 

Audit Readiness 

NIST SP 800-82 assessments, whether self-conducted, performed by a federal authorizing official, or reviewed by a customer or insurer, focus on evidence that OT-specific controls are implemented, not just documented. Key areas that examiners probe: 

  • OT Asset and Cryptographic Inventory: Has the organization inventoried every OT device, its cryptographic capability, and current certificate or key status? 
  • Control Overlay Mapping: Has the organization documented which NIST SP 800-53 SC and IA controls apply as-is, apply with modification, or are not applicable per the Appendix D overlay? 
  • Legacy Device Compensating Controls: For devices that cannot natively support PKI or strong authentication, are compensating controls identified and documented? 
  • Remote Access Certificate Management: Do remote engineering and vendor sessions use unique, revocable certificates rather than shared credentials? 
  • Firmware Signing Verification: Can the organization demonstrate that firmware updates are cryptographically signed and that verification is enforced before deployment? 
  • Key Lifecycle Documentation: Are key generation, rotation, and revocation procedures documented and applied consistently across ICS vendors and integrators?