Date Published: December 2025
Supersedes:
IR 8286 (10/13/2020)
Planning Note (12/18/2025):
The NIST IR 8286 series enables risk practitioners to integrate CSRM activities more fully into the broader enterprise risk processes. Because information and technology comprise some of the enterprise’s most valuable resources, it is vital that directors and senior leaders always have a clear understanding of cybersecurity risk posture. It is similarly vital that those identifying, assessing, and treating cybersecurity risk understand enterprise strategic objectives when making risk decisions. In addition to this foundational document, the NIST Interagency Report (IR) 8286 Series includes:
None selected
Publication:
https://doi.org/10.6028/NIST.IR.8286r1
Download URL
Supplemental Material:
Risk Register Schema (JSON)
Risk Register Schema (xlsx)
Risk Detail Record Schema (JSON)
Risk Detail Record Schema (xlsx)
Risk Detail Record Example (JSON)
Risk Detail Record Example (xlsx)
OLIR Mapping NIST IR 8286 to CSF 1.1 (xlsx)
Playbook: ERM for the U.S. Federal Government (pdf)
Association for Federal Enterprise Risk Management (AFERM)
RMA - GCOR Conference
Prioritizing Cybersecurity Risk for ERM (2022 RMA GCOR Conference Session)
Publication Parts:
IR 8286A Rev. 1
IR 8286B
IR 8286C Rev. 1
IR 8286D
Related NIST Publications:
Document History:
02/26/25: IR 8286 Rev. 1 (Draft)
12/18/25: IR 8286 Rev. 1 (Final)