U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.


Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

NISTIR 8183 Rev. 1 (Draft)

Cybersecurity Framework Version 1.1 Manufacturing Profile

Date Published: March 2020
Comments Due: May 4, 2020 (public comment period is CLOSED)
Email Questions to: CSF_Manufacturing_Profile@nist.gov


Keith Stouffer (NIST), Timothy Zimmerman (NIST), CheeYee Tang (NIST), Michael Pease (NIST), Joshua Lubell (NIST), Jeffrey Cichonski (NIST), John McCarthy (Dakota Consulting)


A draft revision to the Cybersecurity Framework (CSF) Manufacturing Profile, NISTIR 8183, has been developed that includes the subcategory enhancements established in NIST's Framework for Improving Critical Infrastructure Cybersecurity, Version 1.1. These updates include managing cybersecurity within the supply chain, self-assessing cybersecurity risk, vulnerability disclosure, system integrity, and more comprehensive controls for identity management. Additional changes include updating language to change references from "security levels" to "impact levels."

The Manufacturing Profile was developed for manufacturers managing cybersecurity risk and is aligned with manufacturing sector goals and industry best practices. The Manufacturing Profile provides a voluntary, risk-based approach for managing cybersecurity activities and reducing cyber risk to manufacturing systems. The Manufacturing Profile is meant to enhance but not replace current cybersecurity standards and industry guidelines that the manufacturer is embracing.

We encourage you to use our comment template when preparing your comments for submission.


NOTE: A call for patent claims is included on page iv of this draft. For additional information, see the Information Technology Laboratory (ITL) Patent Policy--Inclusion of Patents in ITL Publications.



computer security; Cybersecurity Framework (CSF); distributed control systems (DCS); industrial control systems (ICS); information security; manufacturing; network security; programmable logic controllers (PLC); risk management; security controls; supervisory control and data acquisition (SCADA) systems
Control Families

None selected


NISTIR 8183 Rev. 1 (Draft) (DOI)
Local Download

Supplemental Material:
Comment template (xls)
NIST Cybersecurity Framework (other)

Document History:
03/04/20: NISTIR 8183 Rev. 1 (Draft)
10/07/20: NISTIR 8183 Rev. 1 (Final)


Security and Privacy
security controls


cybersecurity framework; industrial control systems