# NIST Updates OT Security Guidance

NIST has released a draft update to Special Publication 800-82r4, expanding operational technology (OT) security guidance to incorporate zero trust architecture, Cybersecurity Framework 2.0 alignment, and consequence-driven risk management. This update targets federal agencies and contractors managing OT systems across critical infrastructure sectors, emphasizing enhanced risk management, asset management, and network monitoring tailored to OT environments. The public comment period is open until November 30, 2026, providing an opportunity for stakeholders to influence final guidance. Concurrently, CISA has added a critical vulnerability affecting Zyxel switches to its Known Exploited Vulnerabilities Catalog, urging immediate patching to protect infrastructure. The New York State Senate will hold a hearing on October 1, 2026, addressing cybersecurity threats to municipal water infrastructure, reflecting growing legislative focus on critical infrastructure protection. Additionally, legislation proposing strengthened healthcare cybersecurity standards with increased HHS oversight and funding has been reintroduced, signaling potential future procurement and compliance requirements.

- **Why this matters:** Federal and state agencies, as well as contractors, should prepare to align OT cybersecurity solutions with the forthcoming NIST guidance to meet evolving federal standards.
- The open public comment period until November 30, 2026, offers a direct channel for industry input on OT security requirements.
- Organizations managing critical infrastructure should prioritize patching Zyxel switch vulnerabilities as highlighted by CISA to mitigate exploitation risks.
- Healthcare contractors and providers should monitor legislative developments for enhanced cybersecurity mandates and funding opportunities tied to HHS oversight.
- New York State entities and contractors involved in water infrastructure cybersecurity may find emerging procurement opportunities following the October 1 Senate hearing.

**Jurisdictions:** federal
**Industries:** Information Technology, Defense & Military, Healthcare
**Topics:** Cybersecurity
**Published:** September 22, 2026

### Government Entities
- National Institute of Standards and Technology (NIST)
- Cybersecurity and Infrastructure Security Agency (CISA)
- New York State Senate
- United States Senate
- Department of Health and Human Services (HHS)

### Key Quotes
> The bill would require covered entities to perform security risk analyses, maintain incident-and-recovery plans, test recovery of essential functions, and undergo independent audits while proposing $1.3 billion in hospital cybersecurity funding and expanded HHS oversight and enforcement, including fines up to $5,000 per day for noncompliance.
> — Senator Mark R. Warner

> Establishing effective OT cybersecurity governance requires developing a process with clear responsibilities and accountability within the enterprise risk management function.
> — NIST SP 800-82r4 draft

### Sources
- [Daily OT Security News: September 22, 2026 - Security Boulevard](https://securityboulevard.com/2026/09/daily-ot-security-news-september-22-2026) - Security Boulevard
- [
		NIST SP 800-82r4 draft expands OT security guidance with zero trust, CSF 2.0, consequence-driven risk management - Industrial Cyber	](https://industrialcyber.co/nist/nist-sp-800-82r4-draft-expands-ot-security-guidance-with-zero-trust-csf-2-0-consequence-driven-risk-management) - Industrial Cyber